A startup is building a new mobile application that stores user profiles and preferences in Azure Cosmos DB. To protect user privacy, the company wants to ensure that all sensitive user data is encrypted within the application before being sent to Cosmos DB, and that the encryption keys are never exposed to Azure Cosmos DB itself. Which encryption approach should the startup use?
- AAzure Disk Encryption for the Cosmos DB infrastructure
- BAzure Cosmos DB server-side encryption with service-managed keys
- CAzure Cosmos DB client-side encryption
- DTransparent Data Encryption (TDE) for Cosmos DB
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Cosmos DB client-side encryption
Azure Cosmos DB client-side encryption is the appropriate approach. It allows the mobile application to encrypt sensitive data fields before transmitting them to Cosmos DB. This ensures that the data is encrypted 'in transit' and 'at rest' from the perspective of Cosmos DB, and crucially, the encryption keys remain with the client application, never exposed to the database service.
Why the other options are wrong
- A. Azure Disk Encryption encrypts the underlying physical storage where Cosmos DB data resides but doesn't prevent the Cosmos DB service itself from accessing unencrypted data if not combined with other methods.
- B. Server-side encryption with service-managed keys encrypts data at rest within Cosmos DB, but the data is decrypted by the Cosmos DB service. The keys are managed by Azure, not the client.
- D. Transparent Data Encryption (TDE) is a feature for relational databases like Azure SQL Database, not applicable to Azure Cosmos DB.
Client-Side Encryption for NoSQL (Cosmos DB)
An encryption method for NoSQL databases like Azure Cosmos DB where the client application encrypts specific data fields before sending them to the database. This ensures that sensitive data is encrypted before it leaves the client and that the encryption keys are managed by the client, not the database service.
- Encryption performed by the client application.
- Keys are managed by the client, often in a secure key store.
- Data is encrypted in transit and at rest from the database's perspective.
- Provides strong data confidentiality and control for sensitive data.
Memory trick: Client-side keys: My app holds the key, not the cloud.