Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A startup is building a new mobile application that stores user profiles and preferences in Azure Table Storage. They are concerned about data breaches and want to ensure that even if the storage account is compromised, the sensitive user data (e.g., email addresses) remains unreadable to unauthorized parties. The security architect needs to implement encryption for specific sensitive columns within the Azure Table Storage, without requiring a full client-side encryption solution for the entire table. Which approach should be taken?

  1. AImplement application-level encryption for specific properties before storing them in Azure Table Storage.
  2. BRely on Azure Storage Service Encryption (SSE) for data at rest.
  3. CUse Azure Key Vault to encrypt the entire Azure Table Storage account.
  4. DConfigure Azure Disk Encryption for the underlying storage disks of Azure Table Storage.
Show answer & explanation

Correct answer: A. Implement application-level encryption for specific properties before storing them in Azure Table Storage.

Azure Table Storage encrypts data at rest (SSE), but to protect specific columns from being read even if the storage account is compromised, application-level encryption must be implemented. This means the application encrypts the sensitive data before sending it to Table Storage.

Why the other options are wrong

  • B. SSE encrypts data at rest at the service level, but the data is decrypted by the storage service before being returned. If the storage account's access keys are compromised, the data is readable.
  • C. Azure Key Vault manages encryption keys, but it does not directly encrypt entire Azure Table Storage accounts. SSE is the built-in encryption, and for column-level encryption, the application must handle it.
  • D. Azure Table Storage is a PaaS service; customers do not manage its underlying disks, so Azure Disk Encryption is not applicable.

Application-Level Encryption

Encryption performed by the application itself before data is stored in a database or storage service, allowing granular control over which data is encrypted and who holds the keys.

  • Protects data even if the underlying storage service is compromised.
  • Enables column-level or field-level encryption.
  • Requires the application to manage encryption/decryption keys and processes.

Memory trick: App-Level Encryption for Column-Level Secrets.

More Design security for applications and data questions