AZ-305 Design data storage solutions Practice Question
A company wants to store application configuration settings and secrets (e.g., database connection strings, API keys) securely with automatic rotation. Access must be controlled and audited. Which Azure service should they use?
⚠ Common exam trap
Many candidates confuse Azure App Configuration with Key Vault because both deal with configuration, but App Configuration is for non-sensitive settings and feature flags, while Key Vault is the only service that provides secure secret storage with rotation and auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Key Vault
Azure Key Vault is the correct choice because it is designed specifically for securely storing and managing secrets, keys, and certificates. It supports automatic rotation of secrets via integration with Azure managed identities and event grid notifications, and provides fine-grained access control through Azure RBAC and access policies, with full auditing via Azure Monitor and diagnostic logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Key Vault
Why this is correct
Azure Key Vault is a specialized cloud service for securely storing and controlling access to secrets, encryption keys, and certificates. It uses Microsoft Entra ID authentication and fine-grained access policies to govern who can read or modify secret versions, and it natively integrates with Azure services (e.g., App Service) via Key Vault references for automatic secret rotation with zero downtime. It also provides audit logging, soft-delete, and purge protection, making it the only option here designed specifically for secrets management.
- ✗
Azure App Configuration
Why it's wrong here
Azure App Configuration is a service for centrally managing application configuration settings, feature flags, and key-value pairs, but it is not a secrets store. Values stored in App Configuration are in plaintext (encrypted at rest, but not designed for secret-level sensitivity), and it lacks native secret rotation capabilities or versioned secret lifecycle management. Best practice is to store secrets in Key Vault and reference them from App Configuration, so App Configuration itself is the wrong layer for secret storage.
- ✗
Azure Storage Queues
Why it's wrong here
Azure Storage Queues is a messaging service that enables asynchronous communication between application components by storing messages (up to 64 KiB) in a queue. It has no concept of secret algorithms, rotation schedules, or per-secret permissions, and its access control (storage account keys/SAS tokens) is not designed for granular secret-level auditing or management. Its sole purpose is temporary message passing, making it completely unsuitable for storing configuration or secrets.
- ✗
Azure Service Bus
Why it's wrong here
Azure Service Bus is a fully managed enterprise message broker for integrating applications via queues and topics, providing reliable message delivery, sessions, and transactions. It is a messaging infrastructure product, not a configuration or secret vault, and its security model (Shared Access Signatures or managed identities) is scoped to messaging entities, not to secret object versions or rotation policies. While it supports encryption in transit/at rest, it offers no secret lifecycle management, so it is the wrong choice for this requirement.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.