Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium
A financial services company is storing highly sensitive customer data in Azure Blob Storage. They need to ensure that this data is protected against accidental deletion or modification for a specified retention period, even if an attacker gains access and attempts to delete it. Which feature of Azure Blob Storage should they implement?
- AAzure Storage Account encryption
- BAzure Key Vault integration
- CAzure Policy for resource locks
- DImmutable storage for Blob Storage
Show answer & explanationAnswer & explanation
Correct answer: D. Immutable storage for Blob Storage
Immutable storage for Azure Blob Storage allows you to store business-critical data in a WORM (Write Once, Read Many) state. This means that once data is written, it cannot be modified or deleted for a user-specified interval, providing strong data protection.
Why the other options are wrong
- A. Azure Storage Account encryption encrypts data at rest and in transit, but it does not prevent authorized users or attackers from deleting or modifying the data.
- B. Azure Key Vault integration helps manage encryption keys, but it does not directly prevent data modification or deletion within the storage account itself.
- C. Azure Policy can enforce resource locks, but resource locks typically prevent deletion or modification of the storage account itself or its containers, not individual blobs within the account in a WORM fashion for a retention period.
Immutable Storage
A feature of Azure Blob Storage that stores data in a Write Once, Read Many (WORM) state, meaning it cannot be modified or deleted for a specified retention period.
- WORM (Write Once, Read Many) state
- Protects against accidental deletion/modification
- Supports time-based retention and legal hold
Memory trick: Immutable: can't change, can't delete, just read.