AZ-305 Design infrastructure solutions Practice Question
A healthcare organization is deploying a new application on Azure that will handle Protected Health Information (PHI). The application must be compliant with HIPAA. The security team requires encryption at rest and in transit, and the ability to audit access to the data. The solution should minimize administrative overhead. Which storage solution should you recommend?
⚠ Common exam trap
Candidates may choose Azure SQL Managed Instance with customer-managed keys (Option C) thinking it is more HIPAA-compliant, but customer-managed keys increase administrative overhead. Azure SQL Database with service-managed keys is equally HIPAA-compliant and simpler to manage, while still supporting TDE and Always Encrypted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure SQL Database with Transparent Data Encryption and Always Encrypted
Azure SQL Database provides encryption at rest via Transparent Data Encryption (TDE), which is enabled by default, and encryption in transit via TLS. It also supports Always Encrypted to protect sensitive data client-side, ensuring PHI is never exposed to database administrators. Built-in auditing tracks access, and as a PaaS service, it minimizes administrative overhead compared to SQL Managed Instance or IaaS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure SQL Database with Transparent Data Encryption and Always Encrypted
Why this is correct
Azure SQL Database is a managed PaaS offering that automatically handles high availability, backups, and patching while providing built-in Transparent Data Encryption (TDE) for at-rest encryption and Always Encrypted to protect sensitive columns in transit and client-side. Always Encrypted ensures encryption keys are never exposed to the database engine, adding a strong separation-of-duties layer, and the service natively supports auditing for compliance.
- ✗
Azure Cosmos DB with encryption at rest
Why it's wrong here
Azure Cosmos DB is a globally distributed NoSQL database, so it is not a natural fit for a healthcare organization's relational transaction data that requires SQL joins, stored procedures, and strict schema consistency. While its encryption-at-rest uses automatic Microsoft-managed keys to protect storage, it lacks a full audit capability and does not offer column-level client-side encryption like Always Encrypted, making it weaker for sensitive healthcare scenarios.
- ✗
Azure SQL Managed Instance with customer-managed keys
Why it's wrong here
Azure SQL Managed Instance delivers SQL Server-compatible TDE and auditing, yet it demands significantly more operational effort than Azure SQL Database because it runs inside your virtual network and requires instance-level configuration, maintenance, and patching. Adding customer-managed keys (CMK) through Azure Key Vault introduces extra responsibility for key rotation, revocation, and access policy management that is unnecessary when Azure SQL Database's platform-managed TDE and Always Encrypted already satisfy the requirements with less administration.
- ✗
SQL Server on Azure Virtual Machine with BitLocker
Why it's wrong here
Installing SQL Server on an Azure VM with BitLocker is an IaaS approach where you must manually enable BitLocker for disk encryption, configure SQL Server's own encryption (such as TDE), manage backups, and apply OS/SQL patches, resulting in high administrative overhead. Furthermore, BitLocker only protects data at rest at the disk level and does not protect sensitive columns from database-level compromise or provide integrated auditing, so it is the least aligned with a compliance-driven PaaS strategy.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.