Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard
A global financial institution is migrating its core banking applications to Azure. These applications rely heavily on stored procedures and parameterized queries to interact with sensitive customer account data in Azure SQL Database. The institution requires that sensitive columns, such as account numbers and balances, are encrypted within the database and can only be decrypted by the client application, without exposing the encryption keys to the database engine. The solution must also support computations (e.g., comparisons, arithmetic operations) on the encrypted data directly within the database, without requiring decryption server-side. Which Azure SQL Database feature should the architect recommend?
- AAzure SQL Transparent Data Encryption (TDE)
- BAzure SQL Database firewall rules
- CAzure SQL Always Encrypted with Secure Enclaves
- DAzure Key Vault integration for SQL Database
Show answer & explanationAnswer & explanation
Correct answer: C. Azure SQL Always Encrypted with Secure Enclaves
Azure SQL Always Encrypted with Secure Enclaves allows computations on encrypted data directly within the database without exposing the data or encryption keys to the SQL Database engine. This extends the 'Always Encrypted' capability to support rich computations on encrypted columns, meeting the requirement for client-side decryption and server-side computation on encrypted data.
Why the other options are wrong
- A. Azure SQL Transparent Data Encryption (TDE) encrypts the entire database at rest (data files and log files) but does not encrypt individual columns, nor does it allow computations on encrypted data without server-side decryption, and keys are exposed to the database engine.
- B. Azure SQL Database firewall rules control network access to the database server but do not provide column-level encryption or enable computations on encrypted data.
- D. Azure Key Vault integration for SQL Database is used to manage the keys for TDE or Always Encrypted but does not inherently provide the ability to perform computations on encrypted data without server-side decryption or specific enclave technology.
Azure SQL Always Encrypted with Secure Enclaves
An Azure SQL Database feature that encrypts sensitive data client-side and allows computations on encrypted data within hardware-based secure enclaves, ensuring data and keys are never exposed to the SQL Database engine.
- Client-side encryption of specified columns
- SQL Database engine never sees plaintext data or keys
- Secure enclaves enable rich computations (comparisons, joins, arithmetic) on encrypted data
- Protects data from privileged database administrators
Memory trick: Always Encrypted Enclaves: compute secretly.