Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A global e-commerce company uses Azure Blob Storage to store customer images, product catalogs, and historical order data. Due to regulatory compliance (e.g., GDPR, CCPA) and internal auditing requirements, the company must ensure that certain critical data, once written, cannot be modified or deleted for a specific period. This protection must apply at the object level and prevent even privileged administrators from altering the data. Which Azure Blob Storage feature should the architect recommend?
- AAzure Blob Storage immutable storage with time-based retention
- BAzure Blob Storage soft delete
- CAzure Blob Storage versioning
- DAzure Blob Storage access tiers (Hot, Cool, Archive)
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Blob Storage immutable storage with time-based retention
Azure Blob Storage immutable storage with time-based retention policies ensures that data, once written, cannot be modified or deleted for a specified duration. This feature is designed to meet regulatory compliance requirements and protects data even from privileged users, fulfilling the requirement for unalterable data retention.
Why the other options are wrong
- B. Azure Blob Storage soft delete protects against accidental deletions by retaining deleted blobs for a configurable period, but it does not prevent modification of existing blobs or ensure immutability for compliance.
- C. Azure Blob Storage versioning keeps previous versions of a blob when it's modified or deleted, allowing for recovery, but it does not prevent the current version from being modified or deleted.
- D. Azure Blob Storage access tiers (Hot, Cool, Archive) are used for cost optimization based on access frequency and do not provide data protection against modification or deletion.
Azure Blob Storage Immutable Storage
A feature of Azure Blob Storage that allows users to store business-critical data in a WORM (Write Once, Read Many) state, meaning it cannot be modified or deleted for a specified retention period or indefinitely.
- WORM (Write Once, Read Many) capability
- Supports time-based retention and legal hold
- Protects against accidental or malicious deletion/modification
- Meets regulatory compliance for data retention
Memory trick: Immutable storage makes data 'rock solid' for compliance.