AZ-305 Design infrastructure solutions Practice Question
Exhibit
{
"properties": {
"provisioningState": "Succeeded",
"encryption": {
"keySource": "Microsoft.Keyvault",
"keyVaultProperties": {
"keyUri": "https://mykeyvault.vault.azure.net/keys/mykey/abc123",
"currentVersionedKeyIdentifier": "https://mykeyvault.vault.azure.net/keys/mykey/abc123",
"lastKeyRotationTimestamp": "2025-03-15T10:00:00Z"
},
"infrastructureEncryption": "Enabled"
},
"supportsHttpsTrafficOnly": true,
"minimumTlsVersion": "1.2"
}
}Refer to the exhibit. You are reviewing the properties of an Azure Storage account. The encryption section shows keySource as Microsoft.Keyvault and infrastructureEncryption enabled. What does infrastructureEncryption mean in this context?
⚠ Common exam trap
Many candidates confuse infrastructure encryption with enforcing HTTPS (data in transit) or with key rotation, but the question specifically tests the understanding that 'infrastructureEncryption' means double encryption of data at rest, not a transport or key management feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enables double encryption of data at rest
Infrastructure encryption in Azure Storage provides double encryption of data at rest. When enabled, data is encrypted twice: once at the service level using a Microsoft-managed key or a customer-managed key from Azure Key Vault (as indicated by keySource: Microsoft.Keyvault), and a second layer at the infrastructure level using a separate platform-managed key. This ensures that even if one encryption layer is compromised, the second layer protects the data, meeting compliance requirements for highly sensitive workloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It enforces HTTPS for all data in transit
Why it's wrong here
HTTPS enforcement is governed by the storage account's 'Secure transfer required' property (supportsHttpsTrafficOnly), not by infrastructure encryption. Infrastructure encryption is an at-rest protection that adds a second cipher layer on storage media; it never alters the network protocol, so requests can still arrive over HTTP if that toggle is disabled. Even with infrastructure encryption enabled, a client could use plain HTTP unless the separate secure-transport flag is set.
- ✗
It automatically rotates the encryption key daily
Why it's wrong here
Infrastructure encryption does not include any automatic rotation behavior, let alone a daily cycle. Keys used for this layer are platform-managed and Microsoft rotates them for internal compliance reasons, but that is not part of the feature contract nor visible to the tenant. Key rotation for customer-managed keys, if used for service-side encryption, is configured separately via Key Vault policies and is an entirely independent mechanism.
- ✗
It encrypts the encryption key stored in Key Vault
Why it's wrong here
Customer-managed keys stored in Key Vault are already encrypted at rest by Key Vault itself using HSM-backed and depending on the vault's own encryption protections; the storage account's infrastructure encryption does not target those keys. The Key Vault key is a control-plane artifact used to wrap a service encryption key, not the data itself. Infrastructure encryption instead protects the raw data on the physical storage cluster by applying a platform-managed key underneath the service-level encryption, a distinct layer.
- ✓
It enables double encryption of data at rest
Why this is correct
When infrastructure encryption is enabled on an Azure Storage account, data is encrypted at rest twice: first by the standard Azure Storage service-side encryption, then by a second layer using platform-managed keys at the storage infrastructure level. This double-encryption model means a compromise of one key layer still leaves the data protected by the other. It is specifically an at-rest capability; it does not apply to network traffic, and it cannot be turned off after the account is created.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.