Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A global manufacturing company uses Azure Synapse Analytics dedicated SQL pools for large-scale data warehousing. They need to ensure that data in transit to and from the dedicated SQL pools is encrypted, even for client applications that might not explicitly enforce encryption. Which network security measure should be implemented to guarantee this encryption?
- AImplement Network Security Groups (NSGs) for the Synapse workspace subnet.
- BEnforce 'Force TLS' at the Azure Synapse workspace level.
- CConfigure client applications to use 'Encrypt=True' in their connection strings.
- DEnable Always Encrypted on the dedicated SQL pools.
Show answer & explanationAnswer & explanation
Correct answer: B. Enforce 'Force TLS' at the Azure Synapse workspace level.
Enforcing 'Force TLS' at the Azure Synapse workspace level ensures that all connections to dedicated SQL pools within that workspace will use TLS 1.2 encryption, regardless of client application settings.
Why the other options are wrong
- A. NSGs control network traffic flow (allow/deny) but do not enforce encryption for the allowed traffic.
- C. Relying on client applications is error-prone and doesn't guarantee encryption for all connections.
- D. Always Encrypted encrypts data at rest and during processing, but it's for data confidentiality, not for enforcing TLS for data in transit.
Force TLS for Azure Synapse Analytics
A security setting within an Azure Synapse Analytics workspace that mandates all incoming connections to dedicated SQL pools and serverless SQL pools to use Transport Layer Security (TLS) version 1.2 or higher.
- Guarantees data in transit encryption for all connections.
- Enforced at the workspace level, overriding client settings.
- Protects against eavesdropping and tampering during data transfer.
Memory trick: Force TLS to make every Synapse connection secure.