Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A multinational corporation is designing a new customer relationship management (CRM) application on Azure. The application will handle highly sensitive customer data, including personally identifiable information (PII) and financial details. The company requires that data classification and protection policies are consistently applied across all data stored in Azure, on-premises, and in SaaS applications. Furthermore, these policies must allow for automated encryption, access restrictions, and visual marking based on the sensitivity of the data. Which Microsoft solution should the architect recommend?
- AAzure SQL Always Encrypted
- BMicrosoft Defender for Cloud Apps
- CAzure Information Protection (AIP) Sensitivity Labels
- DAzure Confidential Ledger
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Information Protection (AIP) Sensitivity Labels
Azure Information Protection (AIP) Sensitivity Labels, now integrated into Microsoft Purview Information Protection, allows organizations to classify and protect sensitive data across various environments (Azure, on-premises, SaaS). It provides capabilities for automated encryption, visual marking, and access restrictions based on data sensitivity.
Why the other options are wrong
- A. Azure SQL Always Encrypted provides column-level encryption for data in SQL databases, but it does not offer a comprehensive data classification and protection solution across diverse environments like AIP.
- B. Microsoft Defender for Cloud Apps (MCAS) is a Cloud Access Security Broker (CASB) that provides visibility and control over SaaS applications; it does not directly manage data classification and protection policies across all specified environments.
- D. Azure Confidential Ledger provides an immutable and verifiable ledger for data, ensuring data integrity, but it is not a solution for data classification, automated encryption, or access restrictions based on sensitivity.
Microsoft Purview Information Protection (Sensitivity Labels)
A unified data governance and protection solution that allows organizations to classify, label, and protect sensitive data across clouds, on-premises, and endpoints using sensitivity labels, providing encryption, visual marking, and access controls.
- Classifies and labels data based on sensitivity
- Applies automated encryption and access restrictions
- Includes visual markings (headers, footers, watermarks)
- Works across Microsoft 365, Azure, on-premises, and third-party apps
Memory trick: Purview's labels protect data everywhere.