Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planEasy

A DevOps team is deploying a new web application to Azure App Service. The application will store sensitive customer data in an Azure SQL Database. The security team mandates that all data in transit between the App Service and the SQL Database must be encrypted using a robust, industry-standard protocol. Which of the following configurations should the DevOps team prioritize to meet this requirement?

  1. AEnsure the Azure SQL Database connection string specifies 'Encrypt=True' and 'TrustServerCertificate=False'.
  2. BImplement Azure Front Door with SSL offloading enabled for the App Service.
  3. CEnable Azure SQL Database Auditing to track all data access attempts.
  4. DConfigure the Azure App Service to use HTTP/2 for all incoming requests.
Show answer & explanation

Correct answer: A. Ensure the Azure SQL Database connection string specifies 'Encrypt=True' and 'TrustServerCertificate=False'.

To ensure data in transit between Azure App Service and Azure SQL Database is encrypted, the connection string must explicitly require encryption and validate the server certificate. This forces the use of TLS/SSL for the connection.

Why the other options are wrong

  • B. Azure Front Door manages traffic to the App Service and handles client-side SSL, not the backend connection between App Service and SQL Database.
  • C. Auditing tracks access but does not encrypt data in transit.
  • D. HTTP/2 is for client-to-App Service communication and doesn't directly secure App Service to SQL Database traffic.

Azure SQL In-Transit Encryption

Ensuring data moving between client applications (like App Service) and Azure SQL Database is protected using Transport Layer Security (TLS).

  • Uses TLS/SSL protocols.
  • Configured via connection string parameters.
  • Mandatory for sensitive data protection.

Memory trick: Encrypt your SQL journey, verify the server's identity.

More Develop a security and compliance plan questions