CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud administrator is configuring a new storage service for sensitive log data. The company's compliance policy requires that this data be immutable and protected from accidental deletion or modification for a period of seven years. Which feature of cloud object storage should the administrator enable to meet this requirement?

  1. AGeo-redundant storage with cross-region replication.
  2. BServer-side encryption with customer-managed keys.
  3. CWORM (Write Once, Read Many) or Object Lock.
  4. DObject versioning with lifecycle policies.
Show answer & explanation

Correct answer: C. WORM (Write Once, Read Many) or Object Lock.

WORM (Write Once, Read Many) or Object Lock features in cloud object storage are specifically designed to make data immutable for a specified retention period, preventing accidental or malicious deletion or modification, which directly meets the compliance requirement.

Why the other options are wrong

  • A. Geo-redundant storage with cross-region replication provides data durability and availability across different geographic locations, but it does not enforce immutability or prevent deletion/modification.
  • B. Server-side encryption protects data confidentiality but does not prevent deletion or modification.
  • D. Object versioning keeps multiple versions of an object, which helps with recovery from accidental modification, but it doesn't prevent deletion of all versions or enforce immutability for a strict legal hold period.

WORM/Object Lock

A feature in cloud object storage that makes data immutable for a specified retention period, preventing it from being overwritten or deleted, crucial for compliance and legal hold requirements.

  • Ensures data integrity and non-repudiation.
  • Commonly used for regulatory compliance (e.g., SEC 17a-4, FINRA).
  • Data cannot be modified or deleted until the retention period expires.

Memory trick: WORM locks your data like a vault, write once, read many.

More Security questions