Courseiva

AZ-305 Design infrastructure solutions Practice Question

A government agency is designing a solution to store sensitive citizen data. The data must be encrypted at rest and in transit. The agency requires that the encryption keys be managed by the agency and stored in a hardware security module (HSM). Additionally, the solution must comply with regulatory requirements that mandate customer-managed keys. You need to recommend a key management solution. What should you recommend?

⚠ Common exam trap

Test-takers frequently confuse Azure Key Vault Standard (which offers software-protected keys) with Azure Key Vault Managed HSM (which offers dedicated HSM-backed keys), failing to recognize that only Managed HSM provides FIPS 140-2 Level 3 validation and full customer-managed key sovereignty.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure Key Vault Managed HSM with FIPS 140-2 Level 3 validated HSMs.

Azure Key Vault Managed HSM provides a fully managed, FIPS 140-2 Level 3 validated HSM that allows the agency to retain sole control of the encryption keys, meeting the requirement for customer-managed keys. It ensures data is encrypted at rest and in transit while keeping keys within the agency's own HSM boundary, which is essential for regulatory compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Azure Key Vault Standard with software-protected keys.

    Why it's wrong here

    Azure Key Vault Standard tier stores keys in software rather than in a hardware security module, so the key material is protected only by Azure's software encryption and not by FIPS 140-2 Level 3 validated HSMs. For a government agency that must demonstrate hardware-rooted key protection, Standard would fail strict compliance requirements. It also lacks Managed HSM's dedicated single-tenant HSM boundary, audit controls, and customer-controlled key sovereignty.

  • ✗

    Use Microsoft Purview to manage keys and compliance.

    Why it's wrong here

    Microsoft Purview is a unified data governance, cataloging, and policy platform; it can discover, classify, and map sensitive data and apply sensitivity labels, but it does not generate, store, rotate, or cryptographically safeguard encryption keys. Key management in Azure remains the job of Azure Key Vault or Azure Key Vault Managed HSM. Using Purview as a key management service conflates data governance with key custody and would not satisfy regulatory mandates for controlled key storage.

  • ✗

    Use Azure Information Protection with a custom protection template.

    Why it's wrong here

    Azure Information Protection (now part of Microsoft Purview Information Protection) applies classification labels and usage restrictions through rights management templates, which govern how files and emails can be used (e.g., view, edit, forward) rather than how encryption keys are stored or managed. A custom protection template defines user permissions and encryption policy for content, but the underlying keys are handled by the Azure Rights Management service, not the template. Therefore it cannot provide HSM-backed customer-managed keys or FIPS 140-2 Level 3 compliance for key storage.

  • ✓

    Use Azure Key Vault Managed HSM with FIPS 140-2 Level 3 validated HSMs.

    Why this is correct

    Azure Key Vault Managed HSM is a fully managed, single-tenant HSM service validated to FIPS 140-2 Level 3, meaning the cryptographic boundary is tamper-resistant and hardware-protected. It gives the agency customer-managed keys (CMK) stored in a dedicated HSM partition, preventing Microsoft from accessing key material and providing the auditability required by government mandates such as FedRAMP High and NIST controls. This makes it the correct choice for sensitive workloads requiring hardware-bound key protection.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.