Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium

A global manufacturing company uses Azure Synapse Analytics dedicated SQL pools for large-scale data warehousing. They need to ensure that all client connections to the dedicated SQL pools are secured using Transport Layer Security (TLS) with a minimum version of 1.2. This must be enforced at the server level. Which setting should be configured?

  1. AImplement Azure Firewall to filter non-TLS 1.2 traffic.
  2. BApply Azure Policy to audit non-compliant TLS connections.
  3. CEnable 'Force TLS 1.2' setting on the Azure Synapse Workspace.
  4. DConfigure client applications to use TLS 1.2 for database connections.
Show answer & explanation

Correct answer: C. Enable 'Force TLS 1.2' setting on the Azure Synapse Workspace.

Azure Synapse Analytics workspaces (which host dedicated SQL pools) have a 'Minimum TLS version' setting. By configuring this setting to '1.2', all client connections to the dedicated SQL pools will be forced to use TLS 1.2 or higher, ensuring secure communication at the server level.

Why the other options are wrong

  • A. Azure Firewall can filter traffic, but it's not the native or most efficient way to enforce a minimum TLS version for internal Azure service communication like Synapse SQL pools.
  • B. Azure Policy can audit, but it does not *enforce* the minimum TLS version; it only reports on non-compliance. The requirement is for enforcement.
  • D. While client applications *should* be configured, the requirement is to 'enforce' at the 'server level', which client-side configuration alone does not guarantee.

Force TLS for Azure Synapse Analytics

A setting within Azure Synapse Analytics workspaces that enforces a minimum Transport Layer Security (TLS) version for all client connections to dedicated SQL pools, ensuring secure communication.

  • Configured at the Synapse Workspace level.
  • Enforces TLS 1.2 (or higher) for all inbound client connections.
  • Enhances data in transit security for dedicated SQL pools.
  • Helps meet compliance requirements for secure communication protocols.

Memory trick: Ensure your Synapse connections are always securely encrypted with the right lock.

More Secure data and applications questions