Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy

A company is deploying an Azure SQL Database and needs to ensure that sensitive customer data, such as credit card numbers, is automatically encrypted at rest and in transit without application-level changes. The solution must provide high performance and be transparent to the application. Which Azure SQL Database security feature should be implemented?

  1. ATransparent Data Encryption (TDE)
  2. BDynamic Data Masking (DDM)
  3. CAlways Encrypted with secure enclaves
  4. DAzure Private Link for Azure SQL Database
Show answer & explanation

Correct answer: A. Transparent Data Encryption (TDE)

Transparent Data Encryption (TDE) encrypts the entire database, including data at rest and backups, as well as data in transit over trusted connections, without requiring changes to the application. It operates at the database file level.

Why the other options are wrong

  • B. Dynamic Data Masking obfuscates sensitive data to non-privileged users but does not encrypt the data at rest or in transit.
  • C. Always Encrypted encrypts specific columns and requires client-side changes or secure enclaves for richer computations, which is not transparent to the application without some configuration.
  • D. Azure Private Link provides private connectivity to Azure SQL Database, enhancing network security but not encrypting data within the database itself.

Transparent Data Encryption (TDE)

A feature in Azure SQL Database that encrypts the entire database, including data files and transaction log files, at rest and in backups.

  • Encrypts data at rest and backups.
  • Transparent to applications; no code changes required.
  • Uses a database encryption key (DEK) protected by a master key.

Memory trick: TDE protects the whole database like a transparent shield.

More Secure data and applications questions