AZ-305 Soft-delete Practice Question
A company is designing a solution for storing sensitive documents in Azure Blob Storage. They require that all data be encrypted at rest using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, they want to prevent any accidental deletion of the key vault and its keys. Which combination of actions should they take?
⚠ Common exam trap
Candidates might mistakenly choose RBAC roles (Option A) believing that restricting role assignments prevents deletion, but RBAC does not block deletion by users who are assigned the Contributor role. The actual protection against deletion comes from soft-delete and purge protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable soft-delete and purge protection on the key vault
Enabling soft-delete and purge protection on the Azure Key Vault prevents accidental or malicious deletion of the key vault and its keys, which is essential when using customer-managed keys for encryption at rest. Soft-delete allows recovery of deleted vaults and keys within a retention period, while purge protection prevents permanent deletion until the retention period expires. Option A is incorrect because Key Vault Contributor role allows management of the vault but does not prevent deletion; in fact, it could allow authorized users to delete the vault. Option B is incorrect because firewall rules restrict network access but do not prevent deletion of the vault itself. Option D is incorrect because diagnostic settings and logging only provide monitoring and auditing, not protection against deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the Key Vault Contributor role to only the security team
Why it's wrong here
Role assignment limits who can administer the vault but grants no encryption of blob data with a customer-managed key and does not stop an authorised contributor deleting the vault or keys. Least-privilege role scoping is correct when the requirement is controlling administrative access, not deletion protection.
- ✗
Configure firewall rules to restrict network access
Why it's wrong here
Firewall rules govern which networks may reach the vault; they do nothing to encrypt blob data with a customer-managed key or to stop key or vault deletion. Network restriction is correct when the requirement is limiting exposure of a vault to approved virtual networks or IP ranges.
- ✓
Enable soft-delete and purge protection on the key vault
Why this is correct
Soft-delete retains deleted vaults and keys for a recovery window, while purge protection blocks permanent deletion during that period. Together they satisfy the requirement to prevent accidental deletion of the key vault and its keys.
- ✗
Enable diagnostic settings and send logs to a Log Analytics workspace
Why it's wrong here
Diagnostic settings record control-plane and data-plane operations for auditing; they neither encrypt blobs with a customer-managed key nor block deletion of the vault or its keys. This is correct when the requirement is visibility into who accessed or modified vault objects.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.