Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy

A global manufacturing company uses Azure Synapse Analytics dedicated SQL pools for large-scale data warehousing. Due to strict industry regulations, all connections to the Synapse SQL pools must enforce Transport Layer Security (TLS) 1.2 or higher. How can you ensure this requirement is met for all client connections?

  1. AUse Azure Active Directory (AAD) authentication for Synapse SQL pools.
  2. BConfigure firewall rules to block non-TLS 1.2 connections.
  3. CEnable 'Force TLS 1.2' setting on the Azure Synapse Analytics workspace.
  4. DImplement Azure Private Link for secure connectivity.
Show answer & explanation

Correct answer: C. Enable 'Force TLS 1.2' setting on the Azure Synapse Analytics workspace.

Azure Synapse Analytics workspaces provide a setting to 'Force TLS 1.2' for all connections. This ensures that any client attempting to connect to the SQL pools within that workspace must use TLS 1.2 or a higher version, directly addressing the regulatory requirement.

Why the other options are wrong

  • A. AAD authentication controls user identity, but not the TLS version used for the connection itself.
  • B. Firewall rules control network access based on IP, not the TLS version used for connections.
  • D. Azure Private Link secures connections by keeping them on the Azure backbone, but it doesn't enforce a specific TLS version.

Force TLS for Azure Synapse Analytics

A security setting within Azure Synapse Analytics workspaces that mandates all incoming client connections to use a minimum specified Transport Layer Security (TLS) version, typically TLS 1.2, for enhanced security.

  • Ensures secure communication protocol.
  • Mandates TLS 1.2 or higher for all connections.
  • Configured at the Synapse workspace level.

Memory trick: Forcing TLS 1.2 is like a 'bouncer' at the Synapse door, only letting in secure connections.

More Secure data and applications questions