Courseiva

AZ-305 Design data storage solutions Practice Question

A company needs to store sensitive customer data in Azure Blob Storage with encryption at rest using customer-managed keys (CMK) stored in a hardware security module (HSM). Which Azure service should they use to manage the keys?

⚠ Common exam trap

A common mix-up: candidates confuse the Azure Key Vault Premium tier (which supports HSM keys but in a shared multi-tenant HSM) with the dedicated HSM requirement, leading them to select Option A instead of the more appropriate Managed HSM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Key Vault Managed HSM

Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant HSM that is FIPS 140-2 Level 3 validated. It allows you to store customer-managed encryption keys (CMKs) in a hardware security module (HSM) for Azure Storage encryption at rest, meeting the requirement for HSM-backed key storage. The Premium tier of Azure Key Vault also supports HSM-backed keys, but the question specifies 'stored in a hardware security module (HSM)', and Managed HSM provides dedicated HSM partitions with stronger isolation and compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Key Vault (Premium tier)

    Why it's wrong here

    Azure Key Vault (Premium tier) is not the correct service name; while it does support HSM-backed keys, it is simply a pricing tier within the shared, multi-tenant Azure Key Vault service. Microsoft's current offering for a fully dedicated, single-tenant HSM is Azure Managed HSM, which provides isolated HSM partitions, FIPS 140-2 Level 3 validated hardware, and more granular administrative controls. Choosing 'Premium tier' misidentifies the service and overlooks the higher security boundary that Managed HSM provides for customer-managed keys.

  • ✗

    Azure Information Protection

    Why it's wrong here

    Azure Information Protection (now part of Microsoft Purview Information Protection) is a classification and labeling solution, not a key storage service. It tags and optionally encrypts documents and emails using Azure Rights Management (RMS), which relies on underlying key management, but it does not directly store customer data keys in an HSM. It is therefore incorrect for a requirement that asks where to store sensitive customer data encryption keys, as it lacks the dedicated key storage and lifecycle management capabilities of a key vault or HSM.

  • ✗

    Azure Key Vault (Standard tier)

    Why it's wrong here

    Azure Key Vault (Standard tier) is incorrect because it uses software-backed keys, not hardware security module (HSM) protected keys. Standard tier operates in a multi-tenant environment and lacks the FIPS 140-2 Level 3 validation and hardware-level tamper resistance that Managed HSM offers. For a scenario demanding HSM-backed customer-managed keys for sensitive customer data, Standard tier does not meet the higher assurance and compliance requirements.

  • ✓

    Azure Key Vault Managed HSM

    Why this is correct

    Azure Key Vault Managed HSM is the correct service for storing sensitive customer data encryption keys because it is a fully managed, single-tenant, FIPS 140-2 Level 3 validated hardware security module. It provides HSM-backed keys suitable for customer-managed keys (CMK) used in Azure encryption at rest, ensuring keys are protected in dedicated hardware partitions inaccessible to other tenants. Managed HSM also supports more granular access control, powerful Rbac for key management, and full key lifecycle management, making it the appropriate choice for high-security and compliance-driven environments.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.