Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A financial institution is migrating its on-premises data warehouse to Azure Synapse Analytics. Due to strict regulatory compliance requirements, all data in Azure Synapse Analytics must be encrypted using customer-managed keys (CMK) stored in Azure Key Vault. The solution must ensure that encryption keys never leave the FIPS 140-2 Level 2 validated hardware security modules (HSMs). Which specific encryption configuration must be implemented for Azure Synapse Analytics?
- AAlways Encrypted with secure enclaves for dedicated SQL pools
- BTransparent Data Encryption (TDE) with service-managed keys
- CColumn-level encryption for sensitive data using built-in Synapse functions
- DCustomer-managed keys (CMK) for data encryption, using Key Vault with HSM protection
Show answer & explanationAnswer & explanation
Correct answer: D. Customer-managed keys (CMK) for data encryption, using Key Vault with HSM protection
Customer-managed keys (CMK) for data encryption, integrated with Azure Key Vault that supports HSM (Hardware Security Module) protection, is the correct solution. This allows the financial institution to control the encryption keys and ensures that the keys are stored in FIPS 140-2 Level 2 validated HSMs, meeting the stringent regulatory compliance requirements.
Why the other options are wrong
- A. Always Encrypted is for client-side encryption of specific columns and is not the primary method for encrypting the entire Synapse workspace or dedicated SQL pool data at rest with CMK.
- B. TDE with service-managed keys does not meet the requirement for customer-managed keys or HSM protection.
- C. Column-level encryption with built-in functions is not a comprehensive solution for encrypting all data at rest using CMK and HSMs.
Customer-Managed Keys (CMK) in Azure Synapse Analytics
Allows customers to use their own encryption keys, stored in Azure Key Vault (often with HSMs), to encrypt data at rest within Azure Synapse Analytics.
- Provides full control over encryption keys.
- Keys can be stored in Azure Key Vault with HSMs for FIPS 140-2 Level 2 compliance.
- Enhances regulatory compliance and data governance.
Memory trick: CMK in Key Vault with HSM is the golden key for ultimate data control.