AZ-305 Design data storage solutions Practice Question
A company stores sensitive customer data in Azure Blob Storage. They need to ensure that data at rest is encrypted using a customer-managed key stored in Azure Key Vault. Which of the following should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Disk Encryption (which encrypts VM disks) with Azure Storage Service Encryption (which encrypts Blob Storage data), leading them to select the wrong service for the given scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Storage Service Encryption with customer-managed keys in Azure Key Vault
Azure Storage Service Encryption (SSE) encrypts data at rest in Azure Blob Storage. When configured with customer-managed keys (CMK) stored in Azure Key Vault, the customer controls the encryption key lifecycle, including rotation and revocation, meeting the requirement for customer-managed key control. This is the only option that directly applies to Blob Storage data at rest with CMK support.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Storage Service Encryption with customer-managed keys in Azure Key Vault
Why this is correct
Azure Storage Service Encryption (SSE) is enabled by default for all Azure Storage accounts, including Blob Storage, encrypting data at rest before it is persisted to disk. By specifying customer-managed keys (CMK) in Azure Key Vault, you take ownership of the encryption key lifecycle — including rotation, versioning, and revocation — rather than relying on Microsoft-held keys. This also enables auditability of key usage via Key Vault logs, and can be integrated with Azure Policy to enforce CMK across subscriptions. For a scenario requiring customer-managed encryption for sensitive customer data in Blob Storage, SSE with CMK is the appropriate mechanism.
- ✗
Azure Disk Encryption
Why it's wrong here
Azure Disk Encryption (ADE) is designed for encrypting the OS and data disks attached to Azure virtual machines, using BitLocker on Windows and DM-Crypt on Linux. It operates at the hypervisor or VM guest level and is completely independent of Azure Blob Storage as a data service. While ADE protects VM disk content, it has no effect on data stored in Blob containers, blobs, or Azure Files. Therefore, it cannot satisfy the requirement to encrypt sensitive customer data residing in Blob Storage.
- ✗
Azure Storage Service Encryption with Microsoft-managed keys
Why it's wrong here
Azure Storage Service Encryption with Microsoft-managed keys also encrypts Blob Storage at rest transparently, and it is the default encryption mode for all storage accounts. However, the cryptographic keys are generated, managed, and rotated by Microsoft, giving the customer no ability to control, bring, or audit key usage. For a requirement that specifies customer-managed keys, this option fails because the key management authority remains with Microsoft. This is a common default that meets basic encryption needs but not compliance or governance policies that demand customer control.
- ✗
Azure Information Protection
Why it's wrong here
Azure Information Protection (AIP) is a classification, labeling, and protection platform that helps organizations identify and protect sensitive documents and emails by applying sensitivity labels. It can enforce visual markings and conditional access policies, and it can encrypt files via Azure Rights Management, but it does not encrypt data at rest in Azure Blob Storage itself. AIP operates on content items such as Office documents, not on the underlying storage infrastructure where blob data is written. Since the requirement is for encryption at rest of Blob Storage data, AIP is not a viable mechanism.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.