Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A financial services company uses Azure SQL Database to store highly sensitive customer transaction data. The company needs to enforce strict access controls, ensuring that database administrators (DBAs) can manage the database but cannot view the actual sensitive data in plain text, even if they have elevated permissions. Which Azure SQL Database security feature should be implemented to meet this requirement?
- AAlways Encrypted with secure enclaves
- BAzure Active Directory authentication
- CDynamic Data Masking (DDM)
- DTransparent Data Encryption (TDE)
Show answer & explanationAnswer & explanation
Correct answer: A. Always Encrypted with secure enclaves
Always Encrypted with secure enclaves allows computations on encrypted data without decrypting it in the database engine, preventing DBAs from viewing sensitive data. TDE encrypts data at rest but decrypts it for DBAs, DDM only masks data visually, and AAD authentication controls access but not data visibility post-authentication.
Why the other options are wrong
- B. Azure Active Directory authentication manages who can access the database, but it does not control what data they can see once authenticated.
- C. DDM obscures sensitive data in query results for non-privileged users but does not prevent DBAs with sufficient permissions from seeing the raw data.
- D. TDE encrypts data at rest and in backups, but data is decrypted in memory during processing, making it visible to DBAs.
Always Encrypted with secure enclaves
A feature in Azure SQL Database that allows clients to encrypt sensitive data inside client applications and never reveal the encryption keys to the database engine. Secure enclaves enable in-place computations on encrypted data without decrypting it.
- Data remains encrypted in memory on the server side.
- Protects against highly privileged users (e.g., DBAs) from accessing sensitive data.
- Requires client-side encryption and specialized client drivers.
Memory trick: Always Encrypt, Never Expose.