Courseiva

AZ-305 Design data storage solutions Practice Question

You are the Azure architect for a healthcare organization that needs to store patient medical records (unstructured data) and provide secure access to doctors and nurses via a web application. The data must be encrypted at rest and in transit. Access must be authorized based on the requester's role (doctor, nurse, admin). The solution must be cost-effective and support high concurrency. You decide to use Azure Blob Storage. You need to design the access control mechanism. What should you recommend?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure RBAC with Microsoft Entra ID authentication.

Use Azure RBAC with Microsoft Entra ID authentication. Azure RBAC (Role-Based Access Control) integrated with Microsoft Entra ID (formerly Azure AD) allows you to assign permissions to users based on their roles (e.g., doctor, nurse, admin) for fine-grained access to Blob Storage. This meets the requirement for role-based authorization without managing separate keys or tokens. Option A is incorrect because encryption at rest and HTTPS only address data protection, not access control. Option B is incorrect because shared access signatures (SAS) grant time-limited access to specific resources but are not tied to user roles. Option D is incorrect because storage account access keys provide full administrative access to the entire storage account, not role-based permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable storage service encryption and use HTTPS.

    Why it's wrong here

    Storage service encryption and HTTPS satisfy the encryption requirements but provide no authorisation mechanism at all, leaving role-based access unaddressed. These controls suit baseline data-protection compliance, not controlling which user may read or write a given blob.

  • ✗

    Use shared access signatures (SAS) with stored access policies.

    Why it's wrong here

    SAS tokens delegate access to specific resources but cannot express role-based authorisation for doctors, nurses and admins without custom issuance logic. SAS suits time-limited delegated access to individual blobs or containers, not identity-driven role enforcement.

  • ✓

    Use Azure RBAC with Microsoft Entra ID authentication.

    Why this is correct

    Azure RBAC with Microsoft Entra ID authentication assigns built-in or custom roles scoped to the storage account or container, so doctors, nurses and admins receive permissions matching their role. This satisfies the stem's role-based authorisation requirement while remaining cost-effective and supporting high concurrency.

  • ✗

    Use storage account access keys and distribute them to users.

    Why it's wrong here

    Storage account access keys grant full administrative control over the entire account, so every doctor and nurse would hold unrestricted rights, defeating role-based authorisation. Keys suit trusted service-to-service access, not per-user role separation in a web application.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.