Courseiva

AZ-305 Design infrastructure solutions Practice Question

You are designing a landing zone in Azure for a regulated financial services company. They require that all storage accounts be restricted to specific virtual networks and have encryption using customer-managed keys (CMK). Additionally, they want to ensure that any storage account creation outside of the approved network boundaries is prevented. Which combination of Azure Policy and Network Security controls should you recommend?

⚠ Common exam trap

Many candidates confuse network security groups (NSGs) or Azure Firewall with service endpoints or private endpoints, not realizing that NSGs cannot restrict PaaS service access and that private endpoints alone do not prevent resource creation outside approved networks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure Policy to enforce service endpoints on storage accounts and deny creation if not present, along with a policy requiring CMK encryption.

It combines Azure Policy to enforce service endpoints on storage accounts (denying creation if not present) with a policy requiring customer-managed keys (CMK) for encryption. Service endpoints restrict storage account access to specific virtual networks at the network layer, while the CMK policy ensures compliance with encryption requirements. This directly addresses the company's need to prevent storage account creation outside approved network boundaries and enforce encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Azure Policy to enforce service endpoints on storage accounts and deny creation if not present, along with a policy requiring CMK encryption.

    Why this is correct

    By combining a Deny policy that requires the Microsoft.Storage service endpoint on storage accounts with a policy mandating customer-managed keys (CMK), the landing zone ensures all storage resources are both network-isolated to approved virtual networks and encrypted with keys held by the organization. The Deny effect blocks any storage account creation that lacks the service endpoint, while the CMK policy enforces encryption at rest with a key the customer controls, addressing regulated-industry requirements for both network segmentation and cryptographic key sovereignty. This approach is declarative and prevents configuration drift, as any non-compliant creation is rejected at deployment time.

  • ✗

    Use Azure Policy to require storage account encryption with CMK, and use network security groups (NSGs) to restrict storage account access to specific subnets.

    Why it's wrong here

    NSGs are stateful filtering rules applied to virtual network subnets or network interfaces, and they cannot be directly attached to an Azure Storage account to govern its inbound traffic. While a policy requiring CMK encryption satisfies the encryption requirement, the NSG mechanism does nothing to restrict which clients can reach the storage account's public endpoint; that requires storage firewall rules or service endpoints. As a result, the combination leaves network isolation unenforced and is therefore inadequate for the regulated landing zone.

  • ✗

    Deploy Azure Firewall in the hub virtual network and configure application rules to allow only approved storage accounts.

    Why it's wrong here

    Azure Firewall deployed in the hub virtual network filters traffic routed through it, such as outbound connections from virtual machines to storage account FQDNs, but it has no control-plane authority over resource creation or configuration. Application rules can limit which storage account endpoints VMs can access, yet they cannot deny the deployment of storage accounts or enforce encryption and network settings on the storage service itself. Regulated landing zones require Azure Policy to govern the entire resource lifecycle, not just the posture of workload traffic.

  • ✗

    Use Azure Policy to require storage accounts to use private endpoints, and use Azure Private Link to restrict access from specific virtual networks.

    Why it's wrong here

    This approach uses Azure Policy to require a private endpoint on every storage account, which gives the resource a private IP from a virtual network and removes public exposure, satisfying network isolation. However, the option never addresses encryption at rest; a regulated workload typically requires customer-managed key (CMK) encryption, and without a corresponding policy the storage account could be created with service-managed keys. Additionally, while private endpoints are a strong choice, they are not strictly mandatory when service endpoints plus firewall rules can provide equivalent network restriction, so this incomplete policy set fails to meet the full compliance bar.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.