Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A manufacturing company uses Azure Synapse Analytics dedicated SQL pools to store sensitive intellectual property data. The security team mandates that all data at rest within these SQL pools must be encrypted using a customer-managed key stored in Azure Key Vault. Furthermore, the solution must support automatic key rotation. Which encryption solution should the company implement?
- ATransparent Data Encryption (TDE) with customer-managed keys (CMK) and auto-rotation
- BAlways Encrypted with secure enclaves
- CTransparent Data Encryption (TDE) with service-managed keys
- DColumn-level encryption within the SQL database
Show answer & explanationAnswer & explanation
Correct answer: A. Transparent Data Encryption (TDE) with customer-managed keys (CMK) and auto-rotation
Transparent Data Encryption (TDE) with customer-managed keys (CMK) stored in Azure Key Vault directly addresses the requirement for data at rest encryption using CMK. Azure Key Vault provides the capability for automatic key rotation, fulfilling all specified criteria.
Why the other options are wrong
- B. Always Encrypted focuses on data in use and in transit, not primarily data at rest encryption for the entire database.
- C. TDE with service-managed keys does not meet the 'customer-managed key' requirement.
- D. Column-level encryption is granular but doesn't provide the comprehensive data at rest encryption for the entire SQL pool using CMK and auto-rotation.
TDE with CMK and Auto-rotation
Transparent Data Encryption (TDE) for Azure Synapse Analytics dedicated SQL pools using customer-managed keys (CMK) stored in Azure Key Vault, with automated key rotation.
- Encrypts data at rest (database files, backups, transaction logs).
- Keys are managed by the customer in Azure Key Vault.
- Azure Key Vault supports automatic key rotation for enhanced security.
Memory trick: TDE CMK: Your data's vault, your key, always fresh.