Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium

A financial institution uses Azure SQL Database to store highly sensitive customer transaction data. Regulatory compliance requires that all data at rest and in transit be encrypted, and that cryptographic keys are managed by the customer. Additionally, the solution must support a mechanism for transparent key rotation without service interruption. Which encryption method and key management strategy should be implemented?

  1. AAlways Encrypted with secure enclaves and service-managed keys.
  2. BCell-level encryption with T-SQL functions and application-managed keys.
  3. CTransparent Data Encryption (TDE) with service-managed keys and manual key rotation.
  4. DTransparent Data Encryption (TDE) with customer-managed keys (CMK) in Azure Key Vault and auto-rotation.
Show answer & explanation

Correct answer: D. Transparent Data Encryption (TDE) with customer-managed keys (CMK) in Azure Key Vault and auto-rotation.

Transparent Data Encryption (TDE) encrypts the entire database, including data at rest and backups, which meets the requirement for data at rest. Using customer-managed keys (CMK) stored in Azure Key Vault provides customer control over cryptographic keys, satisfying the key management requirement. Azure Key Vault's auto-rotation feature allows for key rotation without service interruption, fulfilling the final requirement.

Why the other options are wrong

  • A. Always Encrypted is for data in use and protects sensitive data from database administrators, but the question emphasizes data at rest encryption and customer key management with transparent rotation, which TDE with CMK handles more comprehensively for the entire database.
  • B. Cell-level encryption is more granular and complex to manage for an entire database, and application-managed keys lack the robust security and rotation features of Azure Key Vault.
  • C. Service-managed keys do not meet the customer-managed key requirement. Manual rotation would cause service interruption.

TDE with CMK and Auto-rotation

Transparent Data Encryption (TDE) with Customer-Managed Keys (CMK) stored in Azure Key Vault, configured for automatic key rotation, provides comprehensive encryption for data at rest with enhanced security and compliance.

  • Encrypts entire database at rest and backups.
  • Customer retains full control over encryption keys via Azure Key Vault.
  • Automated key rotation minimizes operational overhead and enhances security posture.
  • Supports various Azure SQL offerings.

Memory trick: Secure your SQL data with customer control and seamless key updates.

More Secure data and applications questions