CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud administrator is configuring a new storage service for sensitive log data. The company's compliance policy requires that this data be immutable and protected from accidental deletion or modification for a period of seven years. Which feature of cloud object storage should the administrator enable to meet this requirement?
- AGeo-redundant storage with cross-region replication.
- BServer-side encryption with customer-managed keys.
- CWORM (Write Once, Read Many) or Object Lock.
- DObject versioning with lifecycle policies.
Show answer & explanationAnswer & explanation
Correct answer: C. WORM (Write Once, Read Many) or Object Lock.
WORM (Write Once, Read Many) or Object Lock features in cloud object storage are specifically designed to make data immutable for a specified retention period, preventing accidental or malicious deletion or modification, which directly meets the compliance requirement.
Why the other options are wrong
- A. Geo-redundant storage with cross-region replication provides data durability and availability across different geographic locations, but it does not enforce immutability or prevent deletion/modification.
- B. Server-side encryption protects data confidentiality but does not prevent deletion or modification.
- D. Object versioning keeps multiple versions of an object, which helps with recovery from accidental modification, but it doesn't prevent deletion of all versions or enforce immutability for a strict legal hold period.
WORM/Object Lock
A feature in cloud object storage that makes data immutable for a specified retention period, preventing it from being overwritten or deleted, crucial for compliance and legal hold requirements.
- Ensures data integrity and non-repudiation.
- Commonly used for regulatory compliance (e.g., SEC 17a-4, FINRA).
- Data cannot be modified or deleted until the retention period expires.
Memory trick: WORM locks your data like a vault, write once, read many.