Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global financial institution is migrating its core banking applications to Azure. These applications use highly sensitive customer account data, which must be encrypted at rest, in transit, and during processing. The institution requires a solution that provides cryptographic separation between the application and the database owner, ensuring that the database administrator cannot view decrypted sensitive data. Which encryption technology should be used for the Azure SQL Database?

  1. AAlways Encrypted with secure enclaves
  2. BTransparent Data Encryption (TDE)
  3. CCell-level encryption
  4. DAzure Disk Encryption
Show answer & explanation

Correct answer: A. Always Encrypted with secure enclaves

Always Encrypted with secure enclaves allows sensitive data to remain encrypted during computation within a secure enclave, even on the database server. This provides cryptographic separation, meaning the database administrator has no access to the encryption keys and cannot see the decrypted data, fulfilling the strict security requirement.

Why the other options are wrong

  • B. Transparent Data Encryption (TDE) encrypts data at rest (database files) but decrypts it in memory for processing; database administrators with access to the database can still view the decrypted data.
  • C. Cell-level encryption encrypts individual columns but requires the application to manage keys and decryption, and the data is still decrypted on the server for processing, potentially exposing it to the DBA.
  • D. Azure Disk Encryption encrypts the underlying disks of the VM hosting the SQL database but does not protect data once it's loaded into the SQL Server process memory.

Azure SQL Always Encrypted with Secure Enclaves

An Azure SQL Database feature that allows sensitive data to remain encrypted throughout its lifecycle (at rest, in transit, and in use) by performing computations on encrypted data inside a secure enclave, ensuring cryptographic separation from database administrators and other privileged users.

  • Protects data in use within a secure enclave.
  • Cryptographic separation between application and DBA.
  • Supports rich computations on encrypted data.
  • Enhances confidentiality for highly sensitive data.

Memory trick: Always Encrypted + Enclaves: Even DBAs can't peek.

More Design security for applications and data questions