Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium
A financial services company needs to ensure that all sensitive customer data stored in Azure Blob Storage is immutable, meaning it cannot be modified or deleted for a specific retention period, even by administrators. This is a regulatory requirement to prevent data tampering. Which Azure Storage feature should they use?
- AImmutable storage for Azure Blob Storage
- BBlob soft delete
- CAzure Disk Encryption
- DVersioning for blobs
Show answer & explanationAnswer & explanation
Correct answer: A. Immutable storage for Azure Blob Storage
Immutable storage for Azure Blob Storage allows users to store business-critical data in a WORM (Write Once, Read Many) state. This means that data cannot be modified or deleted for a user-specified interval, fulfilling regulatory requirements for data retention and tamper-proofing, even from privileged accounts.
Why the other options are wrong
- B. Blob soft delete protects against accidental deletion by retaining deleted data for a period, but it does not prevent modification or permanent deletion after the soft delete period by an authorized user.
- C. Azure Disk Encryption encrypts OS and data disks for VMs but is unrelated to blob storage immutability.
- D. Versioning for blobs maintains previous versions of a blob when it is modified or deleted, allowing recovery, but it does not prevent modification or deletion of the current version by an authorized user.
Immutable Storage for Azure Blob Storage
A feature that allows data to be stored in a Write Once, Read Many (WORM) state, preventing modification or deletion for a configurable retention period, even by administrators.
- Ensures data integrity and tamper-proofing.
- Supports time-based retention and legal hold.
- Meets regulatory compliance requirements (e.g., FINRA, SEC 17a-4).
Memory trick: Immutable storage makes data a 'WORM' that can't be squashed!