Courseiva

AZ-305 Design data storage solutions Practice Question

Exhibit

Refer to the exhibit.

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "storageName": {
      "type": "string",
      "defaultValue": "mystorageaccount"
    },
    "location": {
      "type": "string",
      "defaultValue": "[resourceGroup().location]"
    }
  },
  "resources": [
    {
      "type": "Microsoft.Storage/storageAccounts",
      "apiVersion": "2023-01-01",
      "name": "[parameters('storageName')]",
      "location": "[parameters('location')]",
      "kind": "StorageV2",
      "sku": {
        "name": "Standard_GRS"
      },
      "properties": {
        "accessTier": "Hot",
        "minimumTlsVersion": "TLS1_2",
        "supportsHttpsTrafficOnly": true,
        "encryption": {
          "keySource": "Microsoft.Storage"
        },
        "networkAcls": {
          "defaultAction": "Deny",
          "virtualNetworkRules": [],
          "ipRules": []
        }
      }
    }
  ]
}

You deploy the above ARM template. The deployment succeeds. However, you cannot access the storage account from the Azure portal. What is the most likely reason?

⚠ Common exam trap

The trap here is that candidates often overlook network ACLs as a cause for portal access failure, mistakenly focusing on TLS versions or encryption settings, which do not affect basic connectivity from the Azure portal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The network ACLs deny all traffic by default, and no allow rules are configured.

The ARM template likely includes a network ACL configuration that, by default, denies all traffic. Without explicit allow rules for the Azure portal's IP ranges or the 'Allow trusted Microsoft services' exception, the portal cannot reach the storage account's management endpoints, resulting in an inability to access it from the portal despite a successful deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The storage account is configured to require HTTPS traffic only.

    Why it's wrong here

    Requiring HTTPS traffic only is the storage account's secure transfer setting, which is enabled by default in newer accounts. It forces all data plane requests to use TLS, but the Azure portal always communicates over HTTPS to storage endpoints, so this setting does not prevent portal access. Instead, portal access would be blocked by network rules, not by transport encryption.

  • ✓

    The network ACLs deny all traffic by default, and no allow rules are configured.

    Why this is correct

    The network ACLs are the key culprit. In the ARM template, the default action is explicitly set to 'Deny' and no IP rules or virtual network rules are included, so the public endpoint is effectively locked down. When you open the storage account in the Azure portal, the portal's management pane uses the control plane to show settings, but trying to view or edit containers, blobs, or data relies on a data plane request from your client's public IP address, which is not permitted by the ACLs. Thus, the deployment succeeds but data operation access from the portal is impossible.

  • ✗

    The minimum TLS version is set to TLS 1.2, which is not supported by the portal.

    Why it's wrong here

    Setting the minimum TLS version to TLS 1.2 is a supported, recommended configuration for storage accounts. The Azure portal and all current browsers support TLS 1.2 (and often 1.3), so this does not block portal access. This setting only enforces the security protocol for client-to-storage data plane traffic after network access has been granted; it cannot be the cause of a denial at the ACL layer.

  • ✗

    The encryption key source is set to Microsoft.Storage, which prevents portal access.

    Why it's wrong here

    Choosing Microsoft.Storage as the encryption key source means Azure-managed keys automatically encrypt the storage account at rest. This setting has no effect on network reachability or the ability of the portal to perform either control-plane or data-plane operations. Portal access is governed by network ACLs, public endpoint settings, and authentication, not by who holds the encryption key.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.