Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium

A financial services company is storing highly sensitive customer data in Azure Blob Storage. They need to ensure that this data is protected against accidental deletion or modification for a specified retention period, even if an attacker gains access and attempts to delete it. Which feature of Azure Blob Storage should they implement?

  1. AAzure Storage Account encryption
  2. BAzure Key Vault integration
  3. CAzure Policy for resource locks
  4. DImmutable storage for Blob Storage
Show answer & explanation

Correct answer: D. Immutable storage for Blob Storage

Immutable storage for Azure Blob Storage allows you to store business-critical data in a WORM (Write Once, Read Many) state. This means that once data is written, it cannot be modified or deleted for a user-specified interval, providing strong data protection.

Why the other options are wrong

  • A. Azure Storage Account encryption encrypts data at rest and in transit, but it does not prevent authorized users or attackers from deleting or modifying the data.
  • B. Azure Key Vault integration helps manage encryption keys, but it does not directly prevent data modification or deletion within the storage account itself.
  • C. Azure Policy can enforce resource locks, but resource locks typically prevent deletion or modification of the storage account itself or its containers, not individual blobs within the account in a WORM fashion for a retention period.

Immutable Storage

A feature of Azure Blob Storage that stores data in a Write Once, Read Many (WORM) state, meaning it cannot be modified or deleted for a specified retention period.

  • WORM (Write Once, Read Many) state
  • Protects against accidental deletion/modification
  • Supports time-based retention and legal hold

Memory trick: Immutable: can't change, can't delete, just read.

More Describe Azure management and governance questions