Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global financial institution is migrating its core banking applications to Azure. These applications handle highly sensitive customer financial data and require the highest level of data confidentiality. The architect needs to ensure that sensitive columns in the Azure SQL Database, such as account numbers and credit card details, are encrypted at rest and in transit, and that the encryption keys are never exposed to the database engine. This encryption must also support complex operations like joins and aggregations on encrypted data without decrypting the entire dataset. Which Azure SQL Database feature should be implemented?

  1. AAzure Disk Encryption
  2. BAlways Encrypted with secure enclaves
  3. CDynamic Data Masking (DDM)
  4. DTransparent Data Encryption (TDE)
Show answer & explanation

Correct answer: B. Always Encrypted with secure enclaves

Always Encrypted with secure enclaves allows for rich computations (e.g., joins, aggregations) on encrypted data while ensuring the data remains encrypted in memory on the server side and is only decrypted within a secure enclave. This prevents the database engine itself from ever accessing the unencrypted data or encryption keys, meeting the stringent confidentiality and operational requirements.

Why the other options are wrong

  • A. Azure Disk Encryption encrypts the underlying disks of Azure VMs, not specific columns within an Azure SQL Database, and doesn't address encryption in use or computations on encrypted data.
  • C. Dynamic Data Masking (DDM) obscures sensitive data for non-privileged users but does not encrypt the data itself or protect it from privileged database users.
  • D. TDE encrypts the entire database data and log files at rest but decrypts data in memory for computations, exposing it to the database engine.

Azure SQL Always Encrypted with Secure Enclaves

Always Encrypted with secure enclaves enhances the original Always Encrypted feature by allowing rich confidential queries (e.g., pattern matching, range comparisons, joins) on encrypted data. It decrypts data only within a secure, isolated region of memory (enclave) on the server side, ensuring the database engine never sees plaintext data or keys.

  • Data remains encrypted in memory, only decrypted within the enclave.
  • Supports richer computations on encrypted data (joins, aggregations).
  • Protects data from privileged users (DBAs, cloud administrators).
  • Requires compatible client drivers and application changes.

Memory trick: Always Encrypted with Enclaves keeps data truly private, even during complex calculations.

More Design security for applications and data questions