Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy
A global e-commerce company uses Azure Cosmos DB to store customer profiles, order history, and payment information. Due to stringent regulatory compliance requirements (e.g., GDPR, PCI DSS), the company must ensure that highly sensitive data, such as credit card numbers and personal identification numbers (PINs), is encrypted at the client application layer before being sent to Cosmos DB. The encryption keys must be managed by the application owners and never exposed to Azure Cosmos DB or Microsoft. Which Azure Cosmos DB feature should the architect recommend to achieve this client-side encryption requirement?
- AClient-side encryption for Azure Cosmos DB
- BTransparent Data Encryption (TDE)
- CAzure Cosmos DB built-in encryption at rest
- DAzure Key Vault integration for data encryption
Show answer & explanationAnswer & explanation
Correct answer: A. Client-side encryption for Azure Cosmos DB
Client-side encryption for Azure Cosmos DB allows the application to encrypt sensitive data fields before transmitting them to Cosmos DB. This ensures that Cosmos DB only receives encrypted data, and the encryption keys remain under the control of the client application, meeting the specific requirement.
Why the other options are wrong
- B. Transparent Data Encryption (TDE) is typically associated with relational databases like SQL Server and encrypts data at the database file level, not at the client application layer for Cosmos DB.
- C. Azure Cosmos DB built-in encryption at rest encrypts data at the storage layer within Azure, but it is Microsoft-managed encryption and does not meet the requirement for client-side encryption with keys managed by application owners.
- D. Azure Key Vault integration can be used to store the keys, but it's the 'Client-side encryption for Azure Cosmos DB' feature that orchestrates the encryption logic at the application layer using these keys.
Client-side encryption for Azure Cosmos DB
A feature that enables applications to encrypt sensitive data before sending it to Azure Cosmos DB, ensuring that the data is never exposed in plaintext to the database service.
- Encryption occurs at the application layer.
- Encryption keys are managed by the client application owners.
- Data remains encrypted throughout its lifecycle in Cosmos DB.
Memory trick: Client-side encryption keeps Cosmos DB data a secret, even from the cloud, by encrypting before it leaves your app.