Courseiva

AZ-305 Design data storage solutions Practice Question

Your company stores sensitive customer data in Azure Blob Storage. You must ensure that data is encrypted at rest using customer-managed keys (CMK) and that key rotation is automated. You also need to prevent data from being accessed by any Microsoft administrator. Which solution should you implement?

⚠ Common exam trap

A common mix-up: candidates confuse Azure Key Vault (Standard) with Managed HSM, assuming both provide the same level of isolation and security, but only Managed HSM offers FIPS 140-2 Level 3 HSM-backed keys and prevents Microsoft administrator access, which is critical for sensitive customer data scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure Key Vault Managed HSM with customer-managed keys and enable double encryption with infrastructure encryption.

Azure Key Vault Managed HSM provides FIPS 140-2 Level 3 validated hardware security modules (HSMs) for storing customer-managed keys (CMK), supports automated key rotation, and enables double encryption via infrastructure encryption. This ensures that data is encrypted at rest with a customer-controlled key, and the use of Managed HSM prevents Microsoft administrators from accessing the key material, as the HSM is isolated and Microsoft has no export or visibility permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Azure Key Vault (Standard) to store customer-managed keys and enable automatic key rotation.

    Why it's wrong here

    Azure Key Vault (Standard) does not provide hardware-backed single-tenant isolation; keys reside in a multi-tenant vault that is not guaranteed to exclude Microsoft operator-level access, which fails strict customer-control requirements. Although automatic key rotation is available, the key material is still protected only by a Standard HSM (or software) boundary, not a dedicated HSM. This approach also does not address the added layer of infrastructure encryption, so it cannot meet a double-encryption or highest-isolation mandate.

  • ✗

    Use Azure Disk Encryption with customer-managed keys stored in Azure Key Vault.

    Why it's wrong here

    Azure Disk Encryption with customer-managed keys encrypts OS and data disks attached to virtual machines, not the data stored in Azure Blob Storage. Azure Blob Storage is encrypted, by default, via Storage Service Encryption (SSE), which operates at the service layer independently of disk-level encryption. Trying to protect blob data by encrypting disks is architecturally irrelevant and leaves the storage service unencrypted under customer-controlled keys.

  • ✓

    Use Azure Key Vault Managed HSM with customer-managed keys and enable double encryption with infrastructure encryption.

    Why this is correct

    Azure Key Vault Managed HSM is a dedicated, tenant-isolated HSM service that gives you exclusive control over the HSM itself, with hardware-backed key generation and no direct Microsoft operator access. Storing customer-managed keys in Managed HSM lets you enforce your own key lifecycle and comply with strict regulatory mandates. Enabling infrastructure encryption adds a second, independent AES-256 encryption layer at the storage infrastructure level, resulting in double encryption of blobs at rest with keys you govern—this fully satisfies the question's need.

  • ✗

    Enable Azure Storage Service Encryption with platform-managed keys.

    Why it's wrong here

    Azure Storage Service Encryption with platform-managed keys does encrypt all data at rest, but Microsoft manages the key lifecycle, storage, rotation, and access independently of your organization. This fails any compliance or security requirement that demands customer-controlled cryptographic key material, and it provides only a single encryption layer unless infrastructure encryption is separately enabled with your own keys. Since the customer has no control or visibility into key material, this option does not meet the stated 'customer-managed' and 'double encryption' conditions.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.