Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global pharmaceutical company is migrating its research and development (R&D) data to Azure. This data includes highly sensitive genetic sequences and drug compound formulas. The company requires a solution that protects data not only at rest and in transit but also *during processing* in memory, even from privileged administrators or malicious insiders with access to the underlying cloud infrastructure. The data must remain encrypted throughout its entire lifecycle, including computation. Which Azure computing technology should the architect recommend to meet these stringent confidentiality requirements?

  1. AAzure Security Center (Defender for Cloud)
  2. BAzure Confidential Computing
  3. CAzure Disk Encryption
  4. DAzure Key Vault
Show answer & explanation

Correct answer: B. Azure Confidential Computing

Azure Confidential Computing uses hardware-based trusted execution environments (TEEs) to protect data in use. This ensures that data remains encrypted during computation, isolating it from the operating system, hypervisor, and even cloud administrators, which is essential for the highest level of confidentiality required for R&D data.

Why the other options are wrong

  • A. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection, but it is a monitoring and protection service, not a technology for encrypting data during computation.
  • C. Azure Disk Encryption protects data at rest on the disk, but data is decrypted in memory during processing, making it vulnerable to attacks on the compute environment.
  • D. Azure Key Vault is used to securely store and manage encryption keys, but it does not perform data encryption during computation or protect data in memory from privileged access.

Azure Confidential Computing (ACC)

A set of technologies that protects data while it's being processed in memory, using hardware-based Trusted Execution Environments (TEEs) to isolate and encrypt data from the operating system, hypervisor, and cloud administrators.

  • Protects data 'in use' (during computation).
  • Uses hardware-based Trusted Execution Environments (TEEs).
  • Ensures data remains encrypted and isolated from cloud operators and privileged software.

Memory trick: Confidential Computing keeps your secrets safe from everyone, even while the computer is thinking about them.

More Design security for applications and data questions