Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A global pharmaceutical company is migrating its research and development (R&D) data to Azure. This data includes highly sensitive intellectual property (IP) and patient trial results. The company requires that data remains encrypted even while being processed in memory to prevent unauthorized access from privileged administrators or malicious insiders, known as 'in-use' encryption. Which Azure technology should the architect recommend to meet this stringent requirement?
- AAzure SQL Always Encrypted
- BAzure Disk Encryption
- CAzure Confidential Computing
- DAzure Key Vault
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Confidential Computing
Azure Confidential Computing addresses the need for 'in-use' encryption, protecting data even when it's being processed in memory. It uses hardware-based trusted execution environments (TEEs) to isolate data and code from the underlying cloud infrastructure, including privileged administrators.
Why the other options are wrong
- A. Azure SQL Always Encrypted protects data at rest and in transit, and client-side processing, but not data actively being processed in server memory from the host OS.
- B. Azure Disk Encryption protects data at rest on disks, not data in memory during processing.
- D. Azure Key Vault securely stores cryptographic keys and secrets but does not directly encrypt data during processing or at rest itself.
Azure Confidential Computing
A cloud computing technology that protects data while it's being processed (in-use) by running computations in hardware-based Trusted Execution Environments (TEEs), isolating it from the host OS and cloud administrators.
- Protects data 'in-use' (in memory)
- Uses hardware-based Trusted Execution Environments (TEEs)
- Provides strong isolation from cloud operators and privileged insiders
- Supports various workloads (VMs, containers, SQL)
Memory trick: R.I.T. = Rest, In-use, Transit.