{"id":14800,"date":"2020-08-01T10:54:34","date_gmt":"2020-08-01T10:54:34","guid":{"rendered":"https:\/\/www.testpreptraining.com\/tutorial\/?page_id=14800"},"modified":"2022-03-16T10:22:33","modified_gmt":"2022-03-16T10:22:33","slug":"encryption-for-data-at-rest-data-in-transmission-and-data-in-use","status":"publish","type":"page","link":"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/","title":{"rendered":"Encryption for data at rest, data in transmission, and data in use"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-304-microsoft-azure-architect-design\/\" target=\"_blank\" rel=\"noreferrer noopener\">Go back to AZ-304 Tutorials<\/a><\/p>\n\n\n\n<p>In this, we will learn and understand about encryption processes in transmission, at rest and in use. Moreover, we will know about the concepts of security management.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Information protection and encryption<\/strong><\/h3>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Transport Layer Security (Encryption-in-transit)<\/strong><\/h5>\n\n\n\n<p>By encrypting data in motion with Transport Layer Security, SQL Database and SQL Managed Instance protect client data (TLS). SQL Database and SQL Managed Instance, on the other hand, need all connections to be encrypted (SSL\/TLS) at all times. Furthermore, regardless of whether Encrypt or TrustServerCertificate is set in the connection string, all data is encrypted &#8220;in transit&#8221; between the client and server.<\/p>\n\n\n\n<p>As a recommended practice, you should specify an encrypted connection in the connection string utilized by the programme. Your application will be forced to check the server certificate as a result of this. As a result, man-in-the-middle attacks against your application will be prevented.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Transparent Data Encryption (Encryption-at-rest)<\/strong><\/h5>\n\n\n\n<p>Transparent Data Encryption (TDE) is a security feature for Azure SQL Database and SQL Managed Instance that helps safeguard data at rest from unauthorised or offline access to raw files or backups. However, data centre theft or insecure disposal of hardware or media such as disc drives and backup tapes are regular instances. TDE encrypts the whole database using the AES encryption technique, requiring no modifications to current applications from application developers.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"https:\/\/www.testpreptraining.ai\/microsoft-azure-architect-design-az-304-free-practice-test\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"961\" height=\"150\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-304-practice-tests-5.png\" alt=\"AZ-304 practice tests\" class=\"wp-image-18213\" srcset=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-304-practice-tests-5.png 961w, https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-304-practice-tests-5-750x117.png 750w\" sizes=\"auto, (max-width: 961px) 100vw, 961px\" \/><\/a><\/figure><\/div>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Always Encrypted (Encryption-in-use)<\/strong><\/h5>\n\n\n\n<p>Always Encrypted is a feature that prevents unauthorised access to sensitive data stored in certain database columns. Credit card numbers, national identity numbers, and data with a need-to-know basis are examples of this. Database administrators or other privileged users who are permitted to access the database to undertake administration activities are also included. The data is always encrypted in this case, which means it is only decrypted for processing by client apps that have access to the encryption key. The encryption key, on the other hand, is never exposed to SQL Database or SQL Managed Instance, and it may be kept in the Windows Certificate Store or Azure Key Vault.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Dynamic data masking<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/encryption.png\" alt=\"Dynamic data masking in Encryption\" class=\"wp-image-14807\" width=\"579\" height=\"351\" srcset=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/encryption.png 671w, https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/encryption-659x400.png 659w\" sizes=\"auto, (max-width: 579px) 100vw, 579px\" \/><figcaption>Image Source: Microsoft<\/figcaption><\/figure><\/div>\n\n\n\n<p>Dynamic data masking (DDM) is a technique for minimising sensitive data exposure to non-privileged users by disguising it. DDM, on the other hand, detects potentially sensitive data in Azure SQL Database and SQL Managed Instance automatically. It also offers practical advice for hiding certain variables with minimum impact on the application layer. It operates by obscuring sensitive data in the return set of a query over database fields while no data in the database changes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Security management<\/strong><\/h3>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Vulnerability assessment<\/strong><\/h4>\n\n\n\n<p>Vulnerability assessment is a way for configuring services that can discover, track, and help remediate potential database vulnerabilities with the motive to improve overall database security. However, VA is part of the advanced data security offering, which is a unified package for advanced SQL security capabilities. Further, the VA can be accessed and managed via the central SQL Advanced Data Security portal.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Data discovery and classification<\/strong><\/h4>\n\n\n\n<p>Data discovery and classification provides advanced capabilities built into Azure SQL Database and SQL Managed Instance. This is for discovering, classifying, labeling, and protecting the sensitive data in your databases. However, discovering and classifying sensitive data can play a crucial role in your organizational Information protection stature. It can serve as infrastructure for:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, various security scenarios, such as monitoring and alerting on anomalous access to sensitive data.<\/li><li>Secondly, controlling access to, and hardening the security of, databases containing highly sensitive data.<\/li><li>Lastly, helping in meeting data privacy standards and regulatory compliance requirements.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.testpreptraining.ai\/microsoft-azure-architect-design-az-304-practice-exam\" target=\"_blank\" rel=\"noopener noreferrer\"><img decoding=\"async\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/Az-304-online-course-4.png\" alt=\"AZ-304 Online course\"\/><\/a><\/figure>\n\n\n\n<p class=\"has-text-align-right\"><strong>Reference: <\/strong><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-sql\/database\/security-overview#information-protection-and-encryption\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Documentation<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-304-microsoft-azure-architect-design\/\" target=\"_blank\" rel=\"noreferrer noopener\"><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-304-microsoft-azure-architect-design\/\" target=\"_blank\" rel=\"noreferrer noopener\">Go back to AZ-304 Tutorials<\/a><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Go back to AZ-304 Tutorials In this, we will learn and understand about encryption processes in transmission, at rest and in use. Moreover, we will know about the concepts of security management. Information protection and encryption Transport Layer Security (Encryption-in-transit) By encrypting data in motion with Transport Layer Security, SQL Database and SQL Managed Instance&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-14800","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Encryption for data at rest, data in transmission, and data in use | AZ-304<\/title>\n<meta name=\"description\" content=\"Enhance your knowledge by learning about concepts of Encryption in Azure Portal using Microsoft Azure AZ-304 online course and practice exam Now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Encryption for data at rest, data in transmission, and data in use | AZ-304\" \/>\n<meta property=\"og:description\" content=\"Enhance your knowledge by learning about concepts of Encryption in Azure Portal using Microsoft Azure AZ-304 online course and practice exam Now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/\" \/>\n<meta property=\"og:site_name\" content=\"Testprep Training Tutorials\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-16T10:22:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-304-practice-tests-5.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/\",\"name\":\"Encryption for data at rest, data in transmission, and data in use | AZ-304\",\"isPartOf\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\"},\"datePublished\":\"2020-08-01T10:54:34+00:00\",\"dateModified\":\"2022-03-16T10:22:33+00:00\",\"description\":\"Enhance your knowledge by learning about concepts of Encryption in Azure Portal using Microsoft Azure AZ-304 online course and practice exam Now!\",\"breadcrumb\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Encryption for data at rest, data in transmission, and data in use\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"name\":\"Testprep Training Tutorials\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\",\"name\":\"Testprep Training\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"contentUrl\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"width\":583,\"height\":153,\"caption\":\"Testprep Training\"},\"image\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Encryption for data at rest, data in transmission, and data in use | AZ-304","description":"Enhance your knowledge by learning about concepts of Encryption in Azure Portal using Microsoft Azure AZ-304 online course and practice exam Now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/","og_locale":"en_US","og_type":"article","og_title":"Encryption for data at rest, data in transmission, and data in use | AZ-304","og_description":"Enhance your knowledge by learning about concepts of Encryption in Azure Portal using Microsoft Azure AZ-304 online course and practice exam Now!","og_url":"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/","og_site_name":"Testprep Training Tutorials","article_modified_time":"2022-03-16T10:22:33+00:00","og_image":[{"url":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-304-practice-tests-5.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/","url":"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/","name":"Encryption for data at rest, data in transmission, and data in use | AZ-304","isPartOf":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website"},"datePublished":"2020-08-01T10:54:34+00:00","dateModified":"2022-03-16T10:22:33+00:00","description":"Enhance your knowledge by learning about concepts of Encryption in Azure Portal using Microsoft Azure AZ-304 online course and practice exam Now!","breadcrumb":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/encryption-for-data-at-rest-data-in-transmission-and-data-in-use\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.testpreptraining.ai\/tutorial\/"},{"@type":"ListItem","position":2,"name":"Encryption for data at rest, data in transmission, and data in use"}]},{"@type":"WebSite","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","name":"Testprep Training Tutorials","description":"","publisher":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization","name":"Testprep Training","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/","url":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","contentUrl":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","width":583,"height":153,"caption":"Testprep Training"},"image":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/14800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/comments?post=14800"}],"version-history":[{"count":6,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/14800\/revisions"}],"predecessor-version":[{"id":52971,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/14800\/revisions\/52971"}],"wp:attachment":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/media?parent=14800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/categories?post=14800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/tags?post=14800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}