Courseiva

AZ-305 Design data storage solutions Practice Question

Your company plans to store sensitive customer data in Azure Blob Storage. The data must be encrypted at rest and in transit. Additionally, access must be audited and restricted based on user identity. Which configuration meets these requirements?

⚠ Common exam trap

Candidates often confuse SAS tokens with identity-based access control, thinking that a signed URI provides user-level restriction, when in fact SAS only delegates permissions to anyone holding the token, not to a specific user identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure RBAC for access and Azure Monitor logs for auditing.

Azure RBAC provides identity-based access control using Microsoft Entra ID, which meets the requirement to restrict access based on user identity. Azure Monitor logs (specifically the Azure Activity Log and Storage Analytics logs) capture all read/write operations for auditing. Encryption at rest is automatically provided by Azure Storage Service Encryption (SSE) using Microsoft-managed keys by default, and encryption in transit is enforced via HTTPS when accessing Blob Storage. Together, these satisfy all stated requirements without additional configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use shared access signatures (SAS) for access control.

    Why it's wrong here

    Shared access signatures (SAS) delegate granular permissions to containers or blobs via a bearer token with an expiration time, but the token is not bound to a specific user identity. This means you cannot enforce per-user access policies or track actions back to individual identities, and SAS tokens are not integrated with Microsoft Entra ID for authentication. Consequently, SAS alone fails to meet the requirement for identity-based access control and does not provide the user-centric auditing that Azure Monitor logs deliver.

  • ✓

    Use Azure RBAC for access and Azure Monitor logs for auditing.

    Why this is correct

    Azure RBAC, integrated with Microsoft Entra ID, precisely restricts access to Blob Storage based on user identity by assigning specific roles with defined permissions, directly addressing the requirement for identity-based access control. Concurrently, Azure Monitor logs provide comprehensive auditing by capturing detailed records of all management and data plane operations performed on the storage account, ensuring that access is fully auditable as stipulated.

  • ✗

    Configure network firewalls and use private endpoints.

    Why it's wrong here

    Network firewalls and private endpoints restrict access at the network layer by limiting traffic to approved IP ranges or virtual networks and by exposing the storage account over a private IP address. While these controls significantly reduce the attack surface and secure the network path, they do not authenticate individual users or map permissions to identities. Azure RBAC is still required for identity-based authorization, and network controls provide no user-level audit trail, so this option does not satisfy the stated access control and auditing requirements.

  • ✗

    Enable customer-managed keys (CMK) and use SAS.

    Why it's wrong here

    Customer-managed keys (CMK) control the encryption keys used to encrypt data at rest in Azure Storage, but encryption is separate from authorization and access control. Pairing CMK with shared access signatures (SAS) still relies on bearer tokens that are not tied to user identity, so it does not provide identity-based access management. Additionally, neither CMK nor SAS generates the comprehensive audit logs of user actions that Azure Monitor logs capture, making this combination unsuitable for the stated security and compliance needs.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.