Question 1
Your company wants to setup an Azure SQL data warehouse. Data would be loaded weekly from an Azure SQL database instance.
You have to advise on recommendations based on the following security requirements for the data warehouse:
You have to ensure data engineers can only connect from their on-premise workstations
You have to ensure the right authentication and authorization measures are put in place
You have to ensure the data is encrypted at rest
Which of the following would you recommend for the requirement?
“You have to ensure the data is encrypted at rest”
Answer and explanation
Correct answer: B
Explanation:
You can use Transparent Data Encryption to encrypt the data at rest The Microsoft documentation mentions the following:
Encryption
Azure SQL Data Warehouse Transparent Data Encryption (TDE) helps protect against the threat of malicious activity by encrypting and decrypting your data at rest. When you encrypt your database, associated backups and transaction log files are encrypted without requiring any changes to your applications. TDE encrypts the storage of an entire database by using a symmetric key called the database encryption key.
In SQL Database, the database encryption key is protected by a built-in server certificate. The built-in server certificate is unique for each SQL Database server. Microsoft automatically rotates these certificates at least every 90 days. The encryption algorithm used by SQL Data Warehouse is AES-256. For a general description of TDE, see Transparent Data Encryption.
You can encrypt your database using the Azure portal or T-SQL.
Since this is clearly mentioned in the Microsoft documentation, all other options are incorrect -- Reference:
https://docs.microsoft.com/en-us/azure/sql-data-warehouse/sql-data-warehouse-overview- manage-security
