AZ-305 Design data storage solutions Practice Question
Your company is designing a data lake solution using Azure Data Lake Storage Gen2. The solution must support hierarchical namespace for efficient directory operations, and must provide encryption at rest using customer-managed keys stored in Azure Key Vault. Which steps must you take to enable customer-managed key encryption for the storage account?
⚠ Common exam trap
Test-takers frequently assume customer-managed key encryption can be configured during storage account creation, but Azure requires it to be set post-creation after a managed identity is assigned, and hierarchical namespace must be enabled at creation time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create the storage account with hierarchical namespace enabled, then assign a system-assigned managed identity, and configure encryption with Azure Key Vault.
Azure Data Lake Storage Gen2 requires hierarchical namespace to be enabled at account creation time, and customer-managed key encryption with Azure Key Vault requires a system-assigned managed identity to be assigned to the storage account after creation. The system-assigned identity is used to authenticate to Key Vault for key access, and encryption with customer-managed keys can be configured post-creation via the Azure portal or PowerShell.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create the storage account with a user-assigned managed identity, then enable hierarchical namespace, and configure encryption.
Why it's wrong here
Using a user-assigned managed identity is unnecessary for configuring customer-managed keys in Azure Storage; a system-assigned managed identity is automatically available and is the recommended identity type for this integration. Moreover, the sequence is flawed because hierarchical namespace must be enabled at account creation time—it cannot be added afterward. To meet the requirements, create the account with the hierarchical namespace feature enabled, then rely on the system-assigned identity when configuring encryption with Key Vault.
- ✗
Create the storage account without hierarchical namespace, then enable it later, and configure encryption with Key Vault.
Why it's wrong here
Creating the storage account without hierarchical namespace is a permanent limitation because Azure Data Lake Storage Gen2's hierarchical namespace can only be enabled during initial account creation; there is no supported operation to enable it later. Even if encryption with Key Vault is configured correctly afterward, the account would remain unsuitable as a data lake solution. Therefore, the account must be provisioned with hierarchical namespace enabled from the start, before any identity or encryption settings are applied.
- ✗
Create the storage account and specify customer-managed key encryption during creation using the Azure portal.
Why it's wrong here
The Azure portal does not allow specifying customer-managed key encryption for Azure Storage during the account creation workflow; this setting is only available after the account exists, under the Encryption blade. Attempting to select customer-managed keys at creation time is not a valid action, so this approach cannot produce the required configuration. The correct sequence is to create the account, enable the appropriate managed identity, and then configure encryption with Azure Key Vault as a post-creation step.
- ✓
Create the storage account with hierarchical namespace enabled, then assign a system-assigned managed identity, and configure encryption with Azure Key Vault.
Why this is correct
This is the correct sequence because the hierarchical namespace is an immutable account-level feature that must be set when the storage account is created for Azure Data Lake Storage Gen2. After creation, a system-assigned managed identity should be assigned to the account so it can authenticate to Azure Key Vault for customer-managed key encryption. Finally, encryption is configured using that Key Vault, completing a valid and supported data lake solution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.