Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium

A DevOps team is deploying a new web application to Azure App Service. The application will store sensitive user data in an Azure SQL Database. The security requirement states that all communication between the web application and the database must be encrypted in transit using FIPS 140-2 validated cryptography. Which of the following is the MOST appropriate method to ensure this requirement is met?

  1. ADeploy a Web Application Firewall (WAF) in front of the Azure App Service to inspect all traffic.
  2. BEnsure the connection string used by the App Service specifies 'Encrypt=True;TrustServerCertificate=False'.
  3. CEnable the 'Always Encrypted' feature on the Azure SQL Database columns storing sensitive data.
  4. DConfigure the Azure SQL Database firewall to only allow connections from the App Service's outbound IP addresses.
Show answer & explanation

Correct answer: B. Ensure the connection string used by the App Service specifies 'Encrypt=True;TrustServerCertificate=False'.

To ensure in-transit encryption with FIPS 140-2 validated cryptography between Azure App Service and Azure SQL Database, the connection string must explicitly enforce encryption and server certificate validation. This forces the use of TLS/SSL, which in Azure SQL Database, leverages FIPS 140-2 validated modules.

Why the other options are wrong

  • A. A WAF protects the web application from common web vulnerabilities but does not directly enforce encryption between the web application and the backend database.
  • C. Always Encrypted encrypts data at rest and in use, but the question specifically asks for encryption in transit between the application and the database.
  • D. Firewall rules control network access but do not enforce encryption of the data in transit.

Azure SQL In-Transit Encryption

Ensuring data is encrypted while it travels between the client application and the Azure SQL Database, typically via TLS/SSL, often with FIPS 140-2 validated modules.

  • Azure SQL Database uses TLS/SSL for in-transit encryption by default for most client drivers.
  • Explicitly configuring 'Encrypt=True' in the connection string is a best practice.
  • FIPS 140-2 validation applies to the cryptographic modules used by Azure services, including TLS/SSL.

Memory trick: Securely Transporting SQL Data: Always Encrypt the Journey!

More Develop a security and compliance plan questions