AZ-305 Design data storage solutions Practice Question
You are the Azure architect for a healthcare organization that needs to store patient medical records (unstructured data) and provide secure access to doctors and nurses via a web application. The data must be encrypted at rest and in transit. Access must be authorized based on the requester's role (doctor, nurse, admin). The solution must be cost-effective and support high concurrency. You decide to use Azure Blob Storage. You need to design the access control mechanism. What should you recommend?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure RBAC with Microsoft Entra ID authentication.
Use Azure RBAC with Microsoft Entra ID authentication. Azure RBAC (Role-Based Access Control) integrated with Microsoft Entra ID (formerly Azure AD) allows you to assign permissions to users based on their roles (e.g., doctor, nurse, admin) for fine-grained access to Blob Storage. This meets the requirement for role-based authorization without managing separate keys or tokens. Option A is incorrect because encryption at rest and HTTPS only address data protection, not access control. Option B is incorrect because shared access signatures (SAS) grant time-limited access to specific resources but are not tied to user roles. Option D is incorrect because storage account access keys provide full administrative access to the entire storage account, not role-based permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable storage service encryption and use HTTPS.
Why it's wrong here
Storage service encryption and HTTPS satisfy the encryption requirements but provide no authorisation mechanism at all, leaving role-based access unaddressed. These controls suit baseline data-protection compliance, not controlling which user may read or write a given blob.
- ✗
Use shared access signatures (SAS) with stored access policies.
Why it's wrong here
SAS tokens delegate access to specific resources but cannot express role-based authorisation for doctors, nurses and admins without custom issuance logic. SAS suits time-limited delegated access to individual blobs or containers, not identity-driven role enforcement.
- ✓
Use Azure RBAC with Microsoft Entra ID authentication.
Why this is correct
Azure RBAC with Microsoft Entra ID authentication assigns built-in or custom roles scoped to the storage account or container, so doctors, nurses and admins receive permissions matching their role. This satisfies the stem's role-based authorisation requirement while remaining cost-effective and supporting high concurrency.
- ✗
Use storage account access keys and distribute them to users.
Why it's wrong here
Storage account access keys grant full administrative control over the entire account, so every doctor and nurse would hold unrestricted rights, defeating role-based authorisation. Keys suit trusted service-to-service access, not per-user role separation in a web application.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.