Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium
A financial services company is designing a new application in Azure that will process highly sensitive customer financial data. The application will use an Azure SQL Database. Regulatory compliance requires that the data always remains encrypted, even during query processing, to prevent unauthorized access from database administrators or underlying infrastructure. Which Azure SQL Database feature should the architect recommend to meet this requirement?
- AAzure Disk Encryption
- BTransparent Data Encryption (TDE)
- CAlways Encrypted with Secure Enclaves
- DCustomer-Managed Keys (CMK) for Azure SQL Database
Show answer & explanationAnswer & explanation
Correct answer: C. Always Encrypted with Secure Enclaves
Always Encrypted with Secure Enclaves provides the highest level of data confidentiality by allowing computations on encrypted data within a secure enclave, ensuring data remains encrypted even during processing in the database engine.
Why the other options are wrong
- A. Azure Disk Encryption encrypts the underlying disks of the virtual machine, but not the data within the SQL database itself, nor does it protect data during processing.
- B. TDE encrypts data at rest and backup files, but data is decrypted in memory for processing, making it vulnerable to privileged users.
- D. CMK for Azure SQL Database allows customer control over encryption keys for TDE, but TDE still decrypts data in memory for processing.
Always Encrypted with Secure Enclaves
A feature in Azure SQL Database that enables data to remain encrypted while being processed in the database engine, using secure enclaves to protect sensitive data from unauthorized access.
- Data is always encrypted, at rest, in transit, and during processing.
- Protects data from database administrators and cloud operators.
- Requires client-side encryption and a secure enclave for computations.
Memory trick: Always Encrypt, even when SQL is doing its sum work!