AZ-305 Design data storage solutions Practice Question
You are designing a data storage solution for a multi-tenant SaaS application. Each tenant's data must be isolated and encrypted with a tenant-specific key. The solution must support automatic key rotation and the ability to revoke a tenant's access immediately by disabling their key. The data will be stored in Azure Blob Storage. Which two actions should you include in your design? (Choose two.)
⚠ Common exam trap
The trap here is assuming that a single key with access policies can provide per-tenant isolation; revoking one tenant's access would affect all tenants if they share a key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a separate Azure Key Vault for each tenant and store the tenant's customer-managed key in that vault.
The requirements are per-tenant encryption with tenant-specific keys, automatic key rotation, and immediate revocation by disabling a key. Creating a separate Key Vault per tenant and using encryption scopes in Blob Storage that reference those keys achieves this. Encryption scopes allow different containers or blobs to be encrypted with different keys, and disabling a key in Key Vault immediately blocks access to data encrypted with that key. This design provides strong isolation and meets all requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a separate Azure Key Vault for each tenant and store the tenant's customer-managed key in that vault.
Why this is correct
Using a separate Azure Key Vault per tenant provides strong isolation of keys. Each tenant's key is stored in its own vault, and you can disable the key in that vault to immediately revoke access to that tenant's data. This also simplifies key management and auditing per tenant. Azure Blob Storage supports customer-managed keys from a Key Vault, and you can configure each storage account or encryption scope to use a specific key.
- ✗
Use Azure Disk Encryption with BitLocker for each tenant's virtual machine disks.
Why it's wrong here
Azure Disk Encryption is for virtual machine disks, not for Azure Blob Storage. It does not apply to the scenario of storing data in Blob Storage. Additionally, managing per-tenant VMs and disk encryption would be inefficient and not provide the required isolation for blob data. This option is not relevant to the storage solution.
- ✓
Configure Azure Blob Storage encryption scopes, each using a tenant-specific customer-managed key from the tenant's Key Vault.
Why this is correct
Encryption scopes in Azure Blob Storage allow you to manage encryption with different keys at the container or blob level. By creating an encryption scope per tenant that references the tenant's customer-managed key in their Key Vault, you achieve per-tenant encryption. Disabling the key in the tenant's Key Vault immediately revokes access to that tenant's data. This design provides isolation and meets the revocation requirement.
- ✗
Store all tenant data in a single container and use a single customer-managed key stored in Azure Key Vault Managed HSM.
Why it's wrong here
A single key for all tenants does not provide tenant-specific encryption. If you disable the key to revoke one tenant's access, you would revoke access to all tenants. This violates the isolation and immediate revocation requirement for a specific tenant. While Managed HSM provides HSM-backed keys, it does not solve the multi-tenant key isolation problem.
- ✗
Enable Azure Storage Service Encryption with Microsoft-managed keys and use Azure Policy to enforce per-tenant encryption.
Why it's wrong here
Microsoft-managed keys do not allow you to control key rotation or revocation. Azure Policy can enforce configurations but cannot provide tenant-specific encryption keys or immediate revocation. This approach does not meet the requirement for customer-managed, tenant-specific keys with the ability to disable a key to revoke access.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.