Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium
A development team is deploying a new application that processes sensitive customer data. They need to ensure that the data is protected against accidental deletion or corruption, and that they can recover previous versions of the data if necessary. Which Azure data protection strategy should they implement for their Azure storage accounts?
- AAzure Firewall rules
- BAzure DDoS Protection
- CSoft delete and versioning for Blob Storage
- DAzure Active Directory authentication
Show answer & explanationAnswer & explanation
Correct answer: C. Soft delete and versioning for Blob Storage
Soft delete for Azure Blob Storage allows you to recover accidentally deleted data or overwritten blobs, while blob versioning automatically maintains previous versions of a blob. These features directly address the need to protect against accidental deletion/corruption and recover previous data versions.
Why the other options are wrong
- A. Azure Firewall rules control network traffic to and from resources, which is a security measure but doesn't protect data from accidental deletion or provide version recovery.
- B. Azure DDoS Protection safeguards against Distributed Denial of Service attacks, focusing on availability, not data integrity or recovery from accidental deletion.
- D. Azure Active Directory authentication controls access to data, which is a security measure but doesn't offer recovery from accidental deletion or versioning.
Azure Blob Storage Soft Delete & Versioning
Features for Azure Blob Storage that protect data against accidental deletion or modification. Soft delete allows recovery of deleted blobs, and versioning maintains previous states of a blob.
- Soft delete: Recovers deleted blobs for a retention period.
- Versioning: Automatically saves previous versions of a blob.
- Crucial for data protection and recovery from human error.
Memory trick: Keep your data safe, recover old versions, avoid accidental loss.