Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A financial institution is migrating a legacy application to Azure. This application processes highly sensitive customer financial data that must remain encrypted at rest and in transit. Additionally, the institution requires a solution that enables cryptographic operations to be performed on the encrypted data without decrypting it in memory, even by the cloud provider. Which Azure compute technology should be recommended to meet these stringent security requirements?

  1. AAzure Virtual Machines with Azure Disk Encryption
  2. BAzure App Service with Customer-Managed Keys
  3. CAzure Confidential Computing with confidential VMs
  4. DAzure Container Instances with network isolation
Show answer & explanation

Correct answer: C. Azure Confidential Computing with confidential VMs

Azure Confidential Computing, specifically confidential VMs, provides hardware-based Trusted Execution Environments (TEEs) that protect data in use. This allows cryptographic operations to be performed on encrypted data without exposing it in plaintext to the cloud provider or other unauthorized entities, directly addressing the requirement for in-memory protection.

Why the other options are wrong

  • A. Azure Disk Encryption protects data at rest but not data in use (in memory) from the cloud provider.
  • B. Customer-Managed Keys protect data at rest but do not provide protection for data being processed in memory.
  • D. Network isolation protects data in transit and restricts access, but doesn't protect data in use from memory exposure.

Azure Confidential Computing

A set of cloud computing technologies that protect data while it's in use by processing it inside a hardware-based Trusted Execution Environment (TEE).

  • Protects data in memory from the cloud operator and other tenants.
  • Uses hardware-backed enclaves for isolation.
  • Critical for highly sensitive data workloads like financial or healthcare.

Memory trick: Confidential Computing keeps secrets even when they're 'thinking'.

More Design security for infrastructure questions