Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A company is designing a new cloud-native application that will process highly sensitive customer data. The application will leverage Azure Kubernetes Service (AKS) for container orchestration and Azure SQL Database for data storage. The security architect needs to ensure that data at rest in the Azure SQL Database is protected against unauthorized access, even if the underlying storage is compromised. Which encryption strategy should be recommended?

  1. ATransparent Data Encryption (TDE) managed by Azure SQL Database.
  2. BClient-side encryption using Always Encrypted with secure enclaves.
  3. CApplication-layer encryption implemented within the AKS pods.
  4. DDisk encryption on the virtual machines hosting Azure SQL Database.
Show answer & explanation

Correct answer: B. Client-side encryption using Always Encrypted with secure enclaves.

For highly sensitive data requiring protection even from cloud administrators, client-side encryption using Always Encrypted with secure enclaves provides the strongest assurance as the data remains encrypted in the database, in memory on the server side, and during computation.

Why the other options are wrong

  • A. TDE encrypts data at rest and backup files, but the encryption keys are managed by Azure or a customer-managed key in Azure Key Vault, meaning the data is decrypted for processing by the SQL service.
  • C. While application-layer encryption is possible, Always Encrypted with secure enclaves provides a more robust and integrated solution for SQL data, ensuring encryption throughout the data lifecycle within the database system without complex custom application development.
  • D. Azure SQL Database is a PaaS offering; direct disk encryption on the underlying VMs is not an option available to customers and wouldn't protect data at the database level if the SQL service itself was compromised.

Always Encrypted with Secure Enclaves

A feature in Azure SQL Database that protects sensitive data, allowing clients to encrypt data before sending it to the database. The data remains encrypted during processing within a secure enclave, preventing unauthorized access by database administrators or cloud providers.

  • Data encrypted on the client side.
  • Data remains encrypted in SQL Database, even in memory.
  • Secure enclaves enable computations on encrypted data without decrypting it fully.
  • Protects against high-privileged unauthorized users (e.g., DBAs, cloud admins).

Memory trick: Always Encrypt Your Sensitive Data Everywhere.

More Design security for infrastructure questions