Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard
A company uses Azure Data Factory to ingest and transform sensitive customer data from various sources into an Azure Data Lake Storage Gen2 account. The transformed data is then used by Azure Synapse Analytics for reporting. The security architect needs to ensure that data in Data Lake Storage Gen2 is always encrypted at rest and that access is strictly controlled based on the principle of least privilege, using Azure Active Directory (AAD) identities. Which encryption and access control mechanisms should be prioritized?
- AStorage Service Encryption (SSE) with service-managed keys and IP-based firewall rules.
- BCustomer-managed encryption keys (CMEK) via Azure Key Vault and Azure role-based access control (RBAC) with AAD identities.
- CClient-side encryption using custom keys and Shared Access Signatures (SAS) for access.
- DPlatform-managed encryption keys (PMEK) and Access Control Lists (ACLs) with AAD users/groups.
Show answer & explanationAnswer & explanation
Correct answer: B. Customer-managed encryption keys (CMEK) via Azure Key Vault and Azure role-based access control (RBAC) with AAD identities.
CMEK provides customer control over encryption keys, often a compliance requirement. RBAC with AAD identities allows for granular, identity-based access control based on the principle of least privilege, which is superior to ACLs or SAS tokens for enterprise data lakes.
Why the other options are wrong
- A. SSE with service-managed keys is default encryption but doesn't offer customer control. IP-based firewall rules are network-level controls and don't provide identity-based, least-privilege access control at the data level.
- C. Client-side encryption is an option but managing custom keys can be complex. SAS tokens are for delegated access but less granular and manageable than RBAC for a data lake.
- D. PMEK is default encryption, but CMEK offers greater control. ACLs are granular but RBAC is generally preferred for broader permissions management across Azure resources and integrates seamlessly with AAD identities for least privilege.
Azure Data Lake Storage Gen2 Security
Securing Azure Data Lake Storage Gen2 involves a combination of encryption (PMEK/CMEK), access control (RBAC, ACLs), and network security (Private Endpoints, firewalls) to protect sensitive data at scale.
- Supports both RBAC and POSIX-like ACLs for granular access control.
- Integrates with Azure Active Directory for identity management.
- Offers both platform-managed and customer-managed encryption keys for data at rest.
Memory trick: CMEK & RBAC for Data Lake Protection.