Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A startup is building a new mobile application that stores user profiles and preferences in Azure Cosmos DB. The application is designed with a 'zero-trust' principle, meaning that even the application backend should not have direct access to unencrypted sensitive user data. The security architect needs to ensure that sensitive user attributes, such as email addresses and phone numbers, are encrypted by the client application before being sent to Cosmos DB and remain encrypted at rest and in transit, with decryption only possible by the client application. Which data protection approach should the architect recommend?

  1. AAzure Key Vault integration for Cosmos DB
  2. BClient-side encryption for Azure Cosmos DB
  3. CAzure Cosmos DB server-side encryption with customer-managed keys (CMK)
  4. DNetwork Security Groups (NSGs) for Cosmos DB
Show answer & explanation

Correct answer: B. Client-side encryption for Azure Cosmos DB

Client-side encryption for Azure Cosmos DB ensures that sensitive data is encrypted by the client application before it's sent to the database. This means the data is encrypted at rest, in transit, and even from the perspective of the Cosmos DB service itself, meeting the 'zero-trust' requirement where the backend should not see unencrypted data.

Why the other options are wrong

  • A. Azure Key Vault integration with Cosmos DB is primarily for managing encryption keys used by server-side encryption, not for client-side encryption where the client controls the encryption process and keys entirely.
  • C. Server-side encryption with CMK encrypts data at rest within Cosmos DB using keys managed by the customer, but the Cosmos DB service still has access to the unencrypted data during processing, which violates the 'zero-trust' principle of the backend not seeing unencrypted data.
  • D. Network Security Groups (NSGs) control network access to Cosmos DB but do not provide data encryption at any state (at rest, in transit, or in use).

Client-side encryption (Cosmos DB)

A method where the client application encrypts sensitive data before sending it to Azure Cosmos DB, ensuring the data remains encrypted from the database service's perspective, protecting it from privileged access within the cloud provider.

  • Encryption happens at the client application layer
  • Cosmos DB stores only encrypted data
  • Keys are managed by the client application
  • Provides 'zero-trust' data protection from the backend

Memory trick: Client-side encryption puts the key in YOUR hand.

More Design security for applications and data questions