Azure Storage and Data Architecture Flashcards
6 cards from real AZ-305 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Azure Storage and Data Architecture flashcards as text
You need to ensure that data stored in an Azure Storage account is encrypted with your own keys and you can revoke access at any time. Which option should you configure?
Answer: Customer-managed keys (CMK) in Azure Key Vault
Customer-managed keys stored in Azure Key Vault give you full control over the encryption key lifecycle including the ability to disable or revoke keys to make data inaccessible.
You need to grant a third-party application temporary read access to specific blobs in a private storage container without exposing the account key. Which mechanism should you use?
Answer: Shared Access Signature (SAS) token with limited permissions and expiry
A SAS token can be scoped to specific containers or blobs, limited to read permissions, and set to expire at a specific time, providing secure temporary access.
An application writes large files to Azure Blob Storage and needs to ensure files are only visible to readers after the entire upload is complete. Which upload method ensures this?
Answer: Block Blob upload with Commit Block List as the final step
Block Blob staging uploads data in blocks using Put Block, and only the final Commit Block List operation makes the complete blob visible to readers.
You need a database solution for storing session state for millions of concurrent users with sub-millisecond read latency and automatic expiry of old sessions. Which service is best?
Answer: Azure Cache for Redis with key expiration
Azure Cache for Redis supports sub-millisecond latency, automatic key expiration (TTL), and millions of concurrent operations, making it ideal for session state storage.
Your analytics pipeline requires transactional consistency for writes but also needs to run OLAP queries over the same data without impacting OLTP performance. Which Azure Cosmos DB feature enables this?
Answer: Cosmos DB Analytical Store (HTAP with Azure Synapse Link)
Azure Synapse Link with the Cosmos DB Analytical Store provides a fully isolated columnar store updated in near real-time from the transactional store for HTAP scenarios.
A storage account must only accept connections from a specific set of Azure VNet subnets and deny all other traffic including from the internet. Which two features should you configure?
Answer: Service Endpoints on subnets + Storage account network firewall deny rule with VNet subnet exceptions
Enabling service endpoints on the subnets and adding those subnets to the storage account's firewall allow list while setting the default action to Deny restricts access to only those subnets.