AZ300 Microsoft Azure Architect Technologies Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A global financial services firm is migrating its customer relationship management (CRM) data to Azure, storing it in Azure Blob Storage. Due to strict regulatory mandates, including GDPR and upcoming industry-specific data protection laws, the firm requires that all encryption keys used for data at rest in Azure Storage must be managed within a FIPS 140-2 Level 2 certified Hardware Security Module (HSM). The architecture must also allow for the possibility of the firm managing its own encryption keys in the future. Which Azure storage configuration best meets these stringent requirements for data security and compliance?

Enable Azure Key Vault integration for Azure Storage, utilizing a Key Vault-managed key that is backed by an HSM-protected key within Azure Key Vault.
Implement Azure Disk Encryption on virtual machines hosting the CRM application, and use Azure Information Protection to classify and protect the data before it is uploaded to Blob Storage.
Configure Azure Storage to use Azure Confidential Computing for all data transactions, ensuring that keys are managed through a separate, on-premises HSM solution that is manually synchronized with Azure Storage.
Leverage Azure Storage Service Encryption (SSE) with platform-managed keys, and implement a robust access control policy that restricts direct access to the storage account, relying on application-level encryption for sensitive fields.

About the AZ300 Microsoft Azure Architect Technologies Certification

These free practice questions are designed to help you assess your readiness for the AZ300 Microsoft Azure Architect Technologies exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.