Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium
A pharmaceutical company is storing highly sensitive patient data in Azure Blob Storage. They need to ensure that this data remains immutable for a legally mandated period of seven years, meaning it cannot be altered or deleted, even by administrators. Which Azure storage feature should they configure?
- AAccess policies
- BBlob soft delete
- CBlob versioning
- DImmutability policy (time-based retention)
Show answer & explanationAnswer & explanation
Correct answer: D. Immutability policy (time-based retention)
An immutability policy with time-based retention ensures that data stored in Azure Blob Storage cannot be modified or deleted for a specified period. This is essential for regulatory compliance requiring data retention and preventing tampering, even by privileged users.
Why the other options are wrong
- A. Access policies control who can access data and what actions they can perform, but don't enforce immutability.
- B. Blob soft delete allows recovery of accidentally deleted blobs, but doesn't prevent deliberate modification or deletion after a retention period.
- C. Blob versioning keeps previous versions of a blob, allowing rollback, but doesn't prevent deletion of all versions or modifications to the current version.
Immutable Storage for Azure Blob Storage
A feature that allows users to store business-critical data in a WORM (Write Once, Read Many) state.
- Data cannot be modified or deleted for a specified retention interval.
- Essential for regulatory compliance (e.g., FINRA, SEC, HIPAA).
- Supports both time-based retention and legal holds.
Memory trick: Immutable: Ironclad Retention, Unchangeable Data, Legal Hold.