QuestionQ7

Implement a secure environment

You have an Azure SQL database that includes an Employees table with a Salary column.

You need to encrypt the Salary column. The solution must prevent database administrators from reading the Salary data and provide the most secure encryption.

Which three actions should you perform in sequence?

Drag & Drop
Explanation

Always Encrypted uses a column master key to protect a column encryption key, and the column encryption key encrypts column data. Randomized encryption produces different ciphertext for the same plaintext, providing stronger confidentiality than deterministic encryption. TDE protects database files at rest, and dynamic data masking only limits displayed values; neither prevents a privileged database administrator from accessing plaintext through the database.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!