Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium

A pharmaceutical company is storing highly sensitive patient data in Azure Blob Storage. They need to ensure that this data remains immutable for a legally mandated period of seven years, meaning it cannot be altered or deleted, even by administrators. Which Azure storage feature should they configure?

  1. AAccess policies
  2. BBlob soft delete
  3. CBlob versioning
  4. DImmutability policy (time-based retention)
Show answer & explanation

Correct answer: D. Immutability policy (time-based retention)

An immutability policy with time-based retention ensures that data stored in Azure Blob Storage cannot be modified or deleted for a specified period. This is essential for regulatory compliance requiring data retention and preventing tampering, even by privileged users.

Why the other options are wrong

  • A. Access policies control who can access data and what actions they can perform, but don't enforce immutability.
  • B. Blob soft delete allows recovery of accidentally deleted blobs, but doesn't prevent deliberate modification or deletion after a retention period.
  • C. Blob versioning keeps previous versions of a blob, allowing rollback, but doesn't prevent deletion of all versions or modifications to the current version.

Immutable Storage for Azure Blob Storage

A feature that allows users to store business-critical data in a WORM (Write Once, Read Many) state.

  • Data cannot be modified or deleted for a specified retention interval.
  • Essential for regulatory compliance (e.g., FINRA, SEC, HIPAA).
  • Supports both time-based retention and legal holds.

Memory trick: Immutable: Ironclad Retention, Unchangeable Data, Legal Hold.

More Describe Azure management and governance questions