Courseiva

AZ-305 Design data storage solutions Practice Question

A company wants to store application configuration settings and secrets (e.g., database connection strings, API keys) securely with automatic rotation. Access must be controlled and audited. Which Azure service should they use?

⚠ Common exam trap

Many candidates confuse Azure App Configuration with Key Vault because both deal with configuration, but App Configuration is for non-sensitive settings and feature flags, while Key Vault is the only service that provides secure secret storage with rotation and auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Key Vault

Azure Key Vault is the correct choice because it is designed specifically for securely storing and managing secrets, keys, and certificates. It supports automatic rotation of secrets via integration with Azure managed identities and event grid notifications, and provides fine-grained access control through Azure RBAC and access policies, with full auditing via Azure Monitor and diagnostic logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Key Vault

    Why this is correct

    Azure Key Vault is a specialized cloud service for securely storing and controlling access to secrets, encryption keys, and certificates. It uses Microsoft Entra ID authentication and fine-grained access policies to govern who can read or modify secret versions, and it natively integrates with Azure services (e.g., App Service) via Key Vault references for automatic secret rotation with zero downtime. It also provides audit logging, soft-delete, and purge protection, making it the only option here designed specifically for secrets management.

  • ✗

    Azure App Configuration

    Why it's wrong here

    Azure App Configuration is a service for centrally managing application configuration settings, feature flags, and key-value pairs, but it is not a secrets store. Values stored in App Configuration are in plaintext (encrypted at rest, but not designed for secret-level sensitivity), and it lacks native secret rotation capabilities or versioned secret lifecycle management. Best practice is to store secrets in Key Vault and reference them from App Configuration, so App Configuration itself is the wrong layer for secret storage.

  • ✗

    Azure Storage Queues

    Why it's wrong here

    Azure Storage Queues is a messaging service that enables asynchronous communication between application components by storing messages (up to 64 KiB) in a queue. It has no concept of secret algorithms, rotation schedules, or per-secret permissions, and its access control (storage account keys/SAS tokens) is not designed for granular secret-level auditing or management. Its sole purpose is temporary message passing, making it completely unsuitable for storing configuration or secrets.

  • ✗

    Azure Service Bus

    Why it's wrong here

    Azure Service Bus is a fully managed enterprise message broker for integrating applications via queues and topics, providing reliable message delivery, sessions, and transactions. It is a messaging infrastructure product, not a configuration or secret vault, and its security model (Shared Access Signatures or managed identities) is scoped to messaging entities, not to secret object versions or rotation policies. While it supports encryption in transit/at rest, it offers no secret lifecycle management, so it is the wrong choice for this requirement.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.