Storage solution design is one of the most heavily tested areas in the AZ-305 exam. It goes far beyond memorizing service names — the real skill is combining each service's performance characteristics, replication options, and tier-transition rules to select the optimal architecture for a given requirement. This guide distills the core patterns extracted from 53 actual exam questions, covering Blob Storage, Azure Files, Managed Disks, NetApp Files, replication options, and Lifecycle Management all in one place.
---
Blob Storage Design and Access Tiers
Blob Storage is Azure's flagship object storage for unstructured data — images, videos, logs, backups, and more. It is directly accessible via HTTP/HTTPS REST APIs and integrates natively with Azure CDN and Front Door.
The storage account type is your starting point. General Purpose v2 (GPv2) is the all-purpose type that supports all four access tiers (Hot, Cool, Cold, Archive) and Lifecycle Management policies. Enabling the hierarchical namespace (HNS) on a GPv2 account turns it into ADLS Gen2. Premium Block Blob is SSD-backed, delivering consistent sub-millisecond latency, but it only supports the Hot tier and does not support Lifecycle Management policies. FileStorage is exclusively for Azure Files Premium and cannot be created from a GPv2 account.
Access tiers represent a trade-off between storage cost and read cost. Hot suits frequently accessed data, Cool is for data retained 30+ days, Cold for 90+ days, and Archive for 180+ days. If data is accessed infrequently — say, quarterly audits — but must be read immediately when needed, Cool is the right choice. Lifecycle Management policies only work on GPv2 accounts; Cool has a minimum retention of 30 days, Archive 180 days, with early-deletion charges applying if data is moved out sooner.
Data protection options serve different purposes. Blob Versioning automatically retains previous versions on overwrite. Soft Delete enables recovery for up to 365 days after deletion — but because an administrator can restore the data, it does not meet WORM requirements. Point-in-Time Restore is Block Blob-only and requires all three features enabled simultaneously: Soft Delete, Versioning, and Change Feed. An immutability policy (WORM) in a locked state prevents even subscription administrators from modifying or deleting data within the retention period, making it suitable for compliance with regulations such as SEC 17a-4 in finance, healthcare, and legal contexts.
---
Azure Files and File Share Design
Azure Files is a fully managed cloud file share service supporting both SMB and NFS protocols. It comes in two tiers: Standard (GPv2 account, HDD-backed, tens-to-hundreds of milliseconds latency) and Premium (FileStorage account, SSD-backed, single-digit millisecond latency). Premium supports only LRS and ZRS — GRS and RA-GRS are not available.
You cannot create a Premium file share from a GPv2 account. If low-latency file sharing is required, you must choose the FileStorage account type.
Authentication method selection is a frequent exam topic. In environments where Shared Key usage is disabled, if SMB authentication with an Entra ID account is required, enable Azure Files Entra ID authentication (Kerberos). AD DS authentication is for hybrid environments with an on-premises Active Directory.
Azure File Sync keeps branch office file servers and Azure Files automatically synchronized. Even when the local server is offline, employees can access Azure Files directly in the cloud, ensuring business continuity. Cloud tiering retains only frequently used files locally, reducing local storage needs by up to 99%. If three requirements arise simultaneously — low latency at the branch, centralized sync, and fault tolerance — the combination of Azure Files and Azure File Sync is the correct answer.
---
Managed Disks and VM Disk Design
Managed Disks are block storage attached to Azure VMs. Performance increases across these tiers: Standard HDD (dev/test), Standard SSD (general web servers), Premium SSD (SQL Server, production), Premium SSD v2 (high-performance OLTP, sub-millisecond latency, independent IOPS and throughput tuning), and Ultra Disk (highest performance, limited to availability zones). If Ultra Disk's cost and operational complexity are excessive, Premium SSD v2 is a strong alternative.
Host Caching configuration is critical in SQL Server scenarios. Use Read-Only caching for data file disks: reads are served from memory, lowering IOPS, while writes go directly to disk, eliminating the risk of data loss if the cache is lost. For transaction log disks, set caching to None. Writes go directly to disk without a cache, ensuring write durability; the sequential write pattern of transaction logs delivers sufficient performance even without caching.
---
Replication Options and Data Availability (LRS/ZRS/GRS/GZRS)
| Option | Replication Scope | Single DC Failure | Region Failure | Durability | |--------|------------------|-------------------|----------------|------------| | LRS | 3 copies within a single datacenter | Vulnerable | Vulnerable | 11 nines | | ZRS | 3 availability zones in the same region | Protected | Vulnerable | 12 nines | | GRS | LRS + async replication to secondary region | Vulnerable | Protected | 16 nines | | RA-GRS | GRS + read access to secondary region | Vulnerable | Protected + Read | 16 nines | | GZRS | ZRS + async replication to secondary region | Protected | Protected | 16 nines |
Selection guidelines: choose LRS for cost minimization with no disaster recovery requirement; ZRS for single-DC failure tolerance when cross-region replication is prohibited by data sovereignty or regulation; RA-GRS for regional disaster recovery with read availability during an outage; GZRS when protection against both zone and region failures is required.
!Azure Storage replication options compared
Azure Files Premium supports only LRS and ZRS. If tolerance for a single datacenter failure is needed, ZRS is the only high-availability option. If frequent access is expected, keeping data in the Hot tier is necessary to maintain read latency at the millisecond level.
---
Service Comparison Table
| Service | Primary Use Case | Protocol | Replication Options | Tier Support | |---------|-----------------|----------|--------------------|--------------| | Blob Storage GPv2 | Unstructured object storage | HTTP/HTTPS | All (LRS through GZRS) | Hot/Cool/Cold/Archive | | Azure Files Standard | File sharing, server replacement | SMB, NFS | LRS/ZRS/GRS/RA-GRS | - | | Azure Files Premium | Low-latency high-performance file sharing | SMB, NFS | LRS, ZRS only | - | | Managed Disks | VM block storage | - | LRS/ZRS | - | | NetApp Files | High-performance enterprise NAS | NFS v3/v4.1, SMB | Dedicated hardware | Ultra/Premium/Standard | | ADLS Gen2 | Big data and analytics data lake | ABFS/HTTP | All (LRS through GZRS) | Hot/Cool/Archive |
The NetApp Files Ultra service level delivers 128 MiB/s per TiB throughput and sub-millisecond latency — an enterprise-grade NAS. If the keywords are maximum throughput, lowest latency, and performance-first, Azure NetApp Files is the answer. However, if SMB compatibility is the primary requirement and cost efficiency matters, Azure Files Premium is the more suitable choice.
---
Tricky Decision Points on the Exam
WORM Compliance Storage
If the requirement is that even administrators cannot delete data, along with SEC 17a-4 compliance and long-term retention, choose a Blob Storage immutability policy in the locked state. Soft Delete does not qualify as WORM because an administrator can restore deleted data. Azure Backup retention policies do not protect the source Blob. A Resource Lock only prevents deletion of the storage account itself — it does not provide Blob-level protection.
Data Lake + Folder ACLs + Spark
When a hierarchical folder structure, POSIX ACLs, and Apache Spark integration are all required simultaneously, choose ADLS Gen2 (GPv2 with HNS enabled). HNS can only be enabled at account creation time. RBAC controls only the account and container level, so for fine-grained folder and file permissions, POSIX ACLs (which require HNS) are necessary.
High-Throughput Blob + Low Latency + WORM Together
If thousands of log writes per second, WORM compliance, and sub-millisecond latency are all required at the same time, choose Premium Block Blob Storage. Standard GPv2 is HDD-backed and cannot meet these requirements. Premium Block Blob is SSD-backed, fully supports immutability policies (WORM), and when combined with ZRS provides datacenter-failure protection as well.
Per-Department Independent Encryption in a Single Account
If different CMKs are needed per container within the same storage account, choose Blob Encryption Scope. An account-level CMK is a single key for everything, so per-department isolation is not possible. Encryption Scope applies different CMKs at the container or Blob level, and up to 10,000 scopes can be created per storage account.
---
Practical Application Tips
Choosing SAS token types: use SAS for time-limited file sharing with external partners. In environments where Shared Key-based authentication is disabled, User Delegation SAS (signed with an Entra ID OAuth token) is the only option. Account SAS and Service SAS are both signed with Shared Key, so they cannot be used in such environments.
Azure Data Share vs SAS: for cross-organization data sharing where snapshots must be provided, direct access to the source must be denied, and revocation must be possible, choose Azure Data Share. SAS grants temporary direct access to the source storage, which exposes the original data.
ADLS Gen2 initial design: HNS cannot be enabled after an account is created. If a data lake architecture is anticipated, you must select GPv2 with HNS at the initial design stage. For cost minimization combined with analyt