Courseiva

AZ-305 Design data storage solutions Practice Question

You are designing a data storage solution for a multi-tenant SaaS application. Each tenant's data must be isolated and encrypted with a tenant-specific key. The solution must support automatic key rotation and the ability to revoke a tenant's access immediately by disabling their key. The data will be stored in Azure Blob Storage. Which two actions should you include in your design? (Choose two.)

⚠ Common exam trap

The trap here is assuming that a single key with access policies can provide per-tenant isolation; revoking one tenant's access would affect all tenants if they share a key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a separate Azure Key Vault for each tenant and store the tenant's customer-managed key in that vault.

The requirements are per-tenant encryption with tenant-specific keys, automatic key rotation, and immediate revocation by disabling a key. Creating a separate Key Vault per tenant and using encryption scopes in Blob Storage that reference those keys achieves this. Encryption scopes allow different containers or blobs to be encrypted with different keys, and disabling a key in Key Vault immediately blocks access to data encrypted with that key. This design provides strong isolation and meets all requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a separate Azure Key Vault for each tenant and store the tenant's customer-managed key in that vault.

    Why this is correct

    Using a separate Azure Key Vault per tenant provides strong isolation of keys. Each tenant's key is stored in its own vault, and you can disable the key in that vault to immediately revoke access to that tenant's data. This also simplifies key management and auditing per tenant. Azure Blob Storage supports customer-managed keys from a Key Vault, and you can configure each storage account or encryption scope to use a specific key.

  • ✗

    Use Azure Disk Encryption with BitLocker for each tenant's virtual machine disks.

    Why it's wrong here

    Azure Disk Encryption is for virtual machine disks, not for Azure Blob Storage. It does not apply to the scenario of storing data in Blob Storage. Additionally, managing per-tenant VMs and disk encryption would be inefficient and not provide the required isolation for blob data. This option is not relevant to the storage solution.

  • ✓

    Configure Azure Blob Storage encryption scopes, each using a tenant-specific customer-managed key from the tenant's Key Vault.

    Why this is correct

    Encryption scopes in Azure Blob Storage allow you to manage encryption with different keys at the container or blob level. By creating an encryption scope per tenant that references the tenant's customer-managed key in their Key Vault, you achieve per-tenant encryption. Disabling the key in the tenant's Key Vault immediately revokes access to that tenant's data. This design provides isolation and meets the revocation requirement.

  • ✗

    Store all tenant data in a single container and use a single customer-managed key stored in Azure Key Vault Managed HSM.

    Why it's wrong here

    A single key for all tenants does not provide tenant-specific encryption. If you disable the key to revoke one tenant's access, you would revoke access to all tenants. This violates the isolation and immediate revocation requirement for a specific tenant. While Managed HSM provides HSM-backed keys, it does not solve the multi-tenant key isolation problem.

  • ✗

    Enable Azure Storage Service Encryption with Microsoft-managed keys and use Azure Policy to enforce per-tenant encryption.

    Why it's wrong here

    Microsoft-managed keys do not allow you to control key rotation or revocation. Azure Policy can enforce configurations but cannot provide tenant-specific encryption keys or immediate revocation. This approach does not meet the requirement for customer-managed, tenant-specific keys with the ability to disable a key to revoke access.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.