Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy

A global e-commerce company uses Azure Blob Storage to store customer images, product catalogs, and order history. Due to regulatory requirements and legal hold policies, certain critical data, specifically archived order history, must be retained for a fixed period and cannot be modified or deleted, even by administrators. Which Azure Blob Storage feature should the company implement for this specific data?

  1. ABlob versioning
  2. BAccess control lists (ACLs)
  3. CImmutable storage with time-based retention
  4. DBlob soft delete
Show answer & explanation

Correct answer: C. Immutable storage with time-based retention

Immutable storage with time-based retention policies for Azure Blob Storage ensures that data, once written, cannot be modified or deleted for a specified retention period, even by users with administrative privileges. This meets the requirement for regulatory compliance and legal hold policies.

Why the other options are wrong

  • A. Blob versioning keeps previous versions of a blob when it's modified or deleted, but doesn't prevent modification or deletion of the current version or older versions by administrators.
  • B. Access control lists (ACLs) manage permissions but do not provide immutability; an authorized user could still modify or delete data if they have the necessary permissions.
  • D. Blob soft delete allows recovery of accidentally deleted blobs but does not prevent deletion or modification by administrators.

Azure Blob Storage Immutable Storage

A feature of Azure Blob Storage that allows objects to be stored in a write-once, read-many (WORM) state, preventing modification or deletion for a specified retention period, even by users with administrative privileges. It supports time-based retention and legal hold policies.

  • Creates a WORM state for blobs.
  • Prevents modification or deletion for a set period.
  • Supports time-based retention and legal hold.
  • Essential for regulatory compliance (e.g., FINRA, HIPPA, SEC 17a-4(f)).

Memory trick: Immutable Storage: Time-locked data, no changes allowed.

More Design security for applications and data questions