Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard

A global pharmaceutical company is storing highly sensitive patient data in Azure Blob Storage. They need to ensure that this data, once written, cannot be modified or deleted for a period of 10 years to meet regulatory compliance requirements. Which Azure Blob Storage feature should they implement?

  1. AImmutable Storage for Azure Blob Storage
  2. BAzure Storage Encryption
  3. CSoft Delete for Azure Blob Storage
  4. DAzure Backup
Show answer & explanation

Correct answer: A. Immutable Storage for Azure Blob Storage

Immutable Storage for Azure Blob Storage, specifically with a time-based retention policy in a 'WORM' (Write Once, Read Many) state, ensures that data cannot be modified or deleted for a specified period, fulfilling strict regulatory compliance requirements for data retention.

Why the other options are wrong

  • B. Azure Storage Encryption protects data at rest and in transit but does not prevent modification or deletion.
  • C. Soft Delete for Azure Blob Storage protects against accidental deletions by retaining deleted data for a period, but it does not prevent intentional modification or deletion during its active state.
  • D. Azure Backup provides recovery points for data but does not inherently make data immutable for compliance.

Immutable Storage for Azure Blob Storage

Immutable Storage allows data to be stored in a Write Once, Read Many (WORM) state, preventing modification or deletion for a specified retention period, crucial for regulatory compliance and data integrity.

  • Supports time-based retention policies.
  • Supports legal holds for indefinite retention.
  • Ensures data integrity and compliance.
  • Applies at the blob container level.

Memory trick: Immutable storage locks data for compliance, while soft delete recovers accidents.

More Describe Azure management and governance questions