Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingHard
A financial institution is deploying a new application in Azure that will process highly sensitive customer data. They need to ensure that the data remains encrypted not only at rest and in transit, but also while actively being processed by the CPU and memory. Which Azure security concept addresses this requirement?
- AConfidential Computing
- BData Encryption at Rest
- CAzure DDoS Protection
- DThreat Intelligence
Show answer & explanationAnswer & explanation
Correct answer: A. Confidential Computing
Confidential Computing focuses on protecting data in use, meaning data is encrypted while being processed in memory and by the CPU. This is achieved through hardware-based trusted execution environments (TEEs), providing a higher level of isolation and protection for sensitive data.
Why the other options are wrong
- B. Data Encryption at Rest protects data stored on disks, not while it's actively being processed.
- C. Azure DDoS Protection defends against denial-of-service attacks, unrelated to data encryption during processing.
- D. Threat Intelligence provides information about known threats but doesn't directly encrypt data during processing.
Confidential Computing
A cloud security technology that protects data while it is in use by processing it in a hardware-based trusted execution environment (TEE).
- Encrypts data during processing (in memory and CPU)
- Uses hardware-based Trusted Execution Environments (TEEs)
- Protects against malicious insiders and compromised systems
- Adds a critical layer of data protection beyond at-rest and in-transit
Memory trick: Confidential Computing: Data secured even when thinking.