Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard
A global e-commerce company uses Azure Blob Storage to store customer images, product catalogs, and order fulfillment documents. Some of this data contains PII and is subject to GDPR regulations. The security architect needs to implement a data retention policy that automatically deletes data after a specified period, encrypts all data at rest, and prevents accidental deletion or modification of critical historical records for a certain duration. Which combination of Azure Blob Storage features should be used?
- ASoft Delete, Object Replication, and default platform-managed keys.
- BLifecycle Management policies, Blob inventory, and network access restrictions.
- CImmutability Policies (Time-based Retention and Legal Hold), Versioning, and Customer-Managed Encryption Keys (CMEK).
- DShared Access Signatures (SAS), Access Tiers (Hot/Cool/Archive), and Transparent Data Encryption (TDE).
Show answer & explanationAnswer & explanation
Correct answer: C. Immutability Policies (Time-based Retention and Legal Hold), Versioning, and Customer-Managed Encryption Keys (CMEK).
Immutability Policies (Time-based Retention and Legal Hold) prevent accidental deletion/modification and meet data retention requirements. Versioning protects against accidental overwrites. CMEK provides strong encryption with customer control, addressing regulatory needs.
Why the other options are wrong
- A. Soft Delete is good for accidental deletion but doesn't provide immutability or a legal hold. Object Replication is for DR/HA, not retention. PMEK might not meet all regulatory encryption standards.
- B. Lifecycle Management policies automate tiering and deletion, but don't prevent modification or provide legal hold. Blob inventory lists blobs, and network restrictions control access, but neither addresses immutability or robust encryption directly for data at rest.
- D. SAS tokens are for granular access, not retention. Access Tiers are for cost optimization. TDE is for SQL Database, not Blob Storage.
Azure Blob Storage Immutability Policies
Allow users to store business-critical data in a WORM (Write Once, Read Many) state, meaning it cannot be modified or deleted for a specified retention interval or until a legal hold is removed.
- Supports time-based retention (fixed period) and legal hold (indefinite until removed).
- Essential for regulatory compliance (e.g., GDPR, HIPAA, SEC 17a-4).
- Protects against accidental and malicious data modification/deletion.
Memory trick: Immutable Versions with CMEK for GDPR Compliance.