Courseiva

AZ-305 Soft-delete Practice Question

A company is designing a solution for storing sensitive documents in Azure Blob Storage. They require that all data be encrypted at rest using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, they want to prevent any accidental deletion of the key vault and its keys. Which combination of actions should they take?

⚠ Common exam trap

Candidates might mistakenly choose RBAC roles (Option A) believing that restricting role assignments prevents deletion, but RBAC does not block deletion by users who are assigned the Contributor role. The actual protection against deletion comes from soft-delete and purge protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable soft-delete and purge protection on the key vault

Enabling soft-delete and purge protection on the Azure Key Vault prevents accidental or malicious deletion of the key vault and its keys, which is essential when using customer-managed keys for encryption at rest. Soft-delete allows recovery of deleted vaults and keys within a retention period, while purge protection prevents permanent deletion until the retention period expires. Option A is incorrect because Key Vault Contributor role allows management of the vault but does not prevent deletion; in fact, it could allow authorized users to delete the vault. Option B is incorrect because firewall rules restrict network access but do not prevent deletion of the vault itself. Option D is incorrect because diagnostic settings and logging only provide monitoring and auditing, not protection against deletion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign the Key Vault Contributor role to only the security team

    Why it's wrong here

    Role assignment limits who can administer the vault but grants no encryption of blob data with a customer-managed key and does not stop an authorised contributor deleting the vault or keys. Least-privilege role scoping is correct when the requirement is controlling administrative access, not deletion protection.

  • ✗

    Configure firewall rules to restrict network access

    Why it's wrong here

    Firewall rules govern which networks may reach the vault; they do nothing to encrypt blob data with a customer-managed key or to stop key or vault deletion. Network restriction is correct when the requirement is limiting exposure of a vault to approved virtual networks or IP ranges.

  • ✓

    Enable soft-delete and purge protection on the key vault

    Why this is correct

    Soft-delete retains deleted vaults and keys for a recovery window, while purge protection blocks permanent deletion during that period. Together they satisfy the requirement to prevent accidental deletion of the key vault and its keys.

  • ✗

    Enable diagnostic settings and send logs to a Log Analytics workspace

    Why it's wrong here

    Diagnostic settings record control-plane and data-plane operations for auditing; they neither encrypt blobs with a customer-managed key nor block deletion of the vault or its keys. This is correct when the requirement is visibility into who accessed or modified vault objects.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.