Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsHard

A global logistics company uses Azure Synapse Analytics for real-time analytics on supply chain data. To meet stringent data sovereignty requirements, they need to ensure that all data processing, including Spark pool computations, occurs exclusively within a specific Azure region and that data never leaves that region, even for management or monitoring traffic. What combination of Azure Synapse Analytics features should be used to achieve this strict data residency and network isolation for the Spark pools?

  1. APrivate Endpoints for the Synapse workspace and Workspace managed VNet.
  2. BAlways Encrypted with secure enclaves and Transparent Data Encryption (TDE).
  3. CAzure Firewall for outbound traffic filtering and Network Security Groups (NSGs).
  4. DCustomer-Managed Keys (CMK) for encryption and Azure Policy for region enforcement.
Show answer & explanation

Correct answer: A. Private Endpoints for the Synapse workspace and Workspace managed VNet.

Workspace managed VNet ensures that all Spark pool resources are deployed into a private network within the specified region, and Private Endpoints allow secure access to Synapse resources from this VNet without traversing the public internet, thereby enforcing strict data residency and isolation. CMK and Always Encrypted are for data at rest/in-use encryption, Azure Policy enforces configurations but not network isolation, and NSGs/Firewall control traffic but don't inherently provide the managed VNet isolation for Spark pools.

Why the other options are wrong

  • B. Always Encrypted and TDE are primarily for data encryption at rest and in use, not for enforcing network isolation or data residency for computational resources like Spark pools.
  • C. Azure Firewall and NSGs control network traffic, but a managed VNet and Private Endpoints are necessary to ensure the Spark pool's execution environment is fully isolated and data remains within the private network.
  • D. CMK and Azure Policy address data encryption and configuration compliance, respectively, but do not directly enforce network isolation or data residency for Spark pool processing.

Azure Synapse Workspace Managed VNet & Private Endpoints

A combination of features in Azure Synapse Analytics where the workspace is configured with a managed Virtual Network (VNet) for its compute resources (like Spark pools) and uses Private Endpoints to securely connect to other Azure services, ensuring all data processing and connectivity remain within a private, isolated network.

  • Ensures data residency by keeping all Spark pool traffic within the VNet.
  • Private Endpoints eliminate public internet exposure for data movement.
  • The managed VNet is created and managed by Synapse for its compute needs.

Memory trick: Managed VNet + Private Endpoint = Synapse's private island.

More Secure data and applications questions