Courseiva

AZ-305 Design data storage solutions Practice Question

A company stores sensitive customer data in Azure Blob Storage. They need to ensure that data at rest is encrypted using a customer-managed key stored in Azure Key Vault. Which of the following should they use?

⚠ Common exam trap

A common mix-up: candidates confuse Azure Disk Encryption (which encrypts VM disks) with Azure Storage Service Encryption (which encrypts Blob Storage data), leading them to select the wrong service for the given scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Storage Service Encryption with customer-managed keys in Azure Key Vault

Azure Storage Service Encryption (SSE) encrypts data at rest in Azure Blob Storage. When configured with customer-managed keys (CMK) stored in Azure Key Vault, the customer controls the encryption key lifecycle, including rotation and revocation, meeting the requirement for customer-managed key control. This is the only option that directly applies to Blob Storage data at rest with CMK support.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Storage Service Encryption with customer-managed keys in Azure Key Vault

    Why this is correct

    Azure Storage Service Encryption (SSE) is enabled by default for all Azure Storage accounts, including Blob Storage, encrypting data at rest before it is persisted to disk. By specifying customer-managed keys (CMK) in Azure Key Vault, you take ownership of the encryption key lifecycle — including rotation, versioning, and revocation — rather than relying on Microsoft-held keys. This also enables auditability of key usage via Key Vault logs, and can be integrated with Azure Policy to enforce CMK across subscriptions. For a scenario requiring customer-managed encryption for sensitive customer data in Blob Storage, SSE with CMK is the appropriate mechanism.

  • ✗

    Azure Disk Encryption

    Why it's wrong here

    Azure Disk Encryption (ADE) is designed for encrypting the OS and data disks attached to Azure virtual machines, using BitLocker on Windows and DM-Crypt on Linux. It operates at the hypervisor or VM guest level and is completely independent of Azure Blob Storage as a data service. While ADE protects VM disk content, it has no effect on data stored in Blob containers, blobs, or Azure Files. Therefore, it cannot satisfy the requirement to encrypt sensitive customer data residing in Blob Storage.

  • ✗

    Azure Storage Service Encryption with Microsoft-managed keys

    Why it's wrong here

    Azure Storage Service Encryption with Microsoft-managed keys also encrypts Blob Storage at rest transparently, and it is the default encryption mode for all storage accounts. However, the cryptographic keys are generated, managed, and rotated by Microsoft, giving the customer no ability to control, bring, or audit key usage. For a requirement that specifies customer-managed keys, this option fails because the key management authority remains with Microsoft. This is a common default that meets basic encryption needs but not compliance or governance policies that demand customer control.

  • ✗

    Azure Information Protection

    Why it's wrong here

    Azure Information Protection (AIP) is a classification, labeling, and protection platform that helps organizations identify and protect sensitive documents and emails by applying sensitivity labels. It can enforce visual markings and conditional access policies, and it can encrypt files via Azure Rights Management, but it does not encrypt data at rest in Azure Blob Storage itself. AIP operates on content items such as Office documents, not on the underlying storage infrastructure where blob data is written. Since the requirement is for encryption at rest of Blob Storage data, AIP is not a viable mechanism.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.