Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureHard

A financial services company is designing a new application in Azure that will process highly sensitive customer financial data. Regulatory compliance dictates that all data, both at rest and in transit, must be encrypted with keys managed by the customer. Furthermore, the application must be able to perform computations on encrypted data without decrypting it in memory, even to the cloud provider. Which Azure security feature best meets these stringent requirements?

  1. AAzure Storage Service Encryption with customer-managed keys
  2. BAzure Disk Encryption with customer-managed keys
  3. CAzure Key Vault managed HSM with application-level encryption
  4. DConfidential Computing with Always Encrypted secure enclaves
Show answer & explanation

Correct answer: D. Confidential Computing with Always Encrypted secure enclaves

Confidential Computing with Always Encrypted secure enclaves allows computations on encrypted data without exposing it in plaintext, even to the host OS or hypervisor, directly addressing the requirement to perform computations on encrypted data without decrypting it in memory.

Why the other options are wrong

  • A. Azure Storage Service Encryption protects data at rest but does not provide protection for data in use or during computation.
  • B. Azure Disk Encryption encrypts data at rest on VMs but does not protect data during computation in memory.
  • C. Key Vault managed HSM protects encryption keys, and application-level encryption protects data at rest and in transit, but neither allows computations on encrypted data without in-memory decryption.

Confidential Computing

Confidential Computing protects data while it's in use by performing computations within a hardware-based Trusted Execution Environment (TEE), ensuring the data remains encrypted and inaccessible to the host operating system, hypervisor, or other unauthorized entities.

  • Protects data in-use (during computation).
  • Utilizes hardware-based Trusted Execution Environments (TEEs).
  • Prevents unauthorized access to sensitive data even from cloud administrators.
  • Examples include secure enclaves for SQL Server Always Encrypted.

Memory trick: Compute Confidentially, Encrypt Everything, Key Control is King.

More Design security for infrastructure questions