Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A global e-commerce company is migrating its entire product catalog and customer order history, including credit card details, to Azure Blob Storage. The company has a strict regulatory requirement to retain all data for a minimum of seven years and ensure that the data cannot be altered or deleted during this period, even by administrators. Which Azure Blob Storage feature should the security architect recommend to meet this specific immutability requirement?
- ASoft Delete
- BAccess Control Lists (ACLs)
- CTime-based Retention Policy
- DVersion Management
Show answer & explanationAnswer & explanation
Correct answer: C. Time-based Retention Policy
Azure Blob Storage's Time-based Retention Policy (part of Immutability Policies) allows you to set a retention period during which objects cannot be deleted or modified, even by privileged users, fulfilling the strict regulatory requirement for data immutability.
Why the other options are wrong
- A. Soft Delete protects against accidental deletion but allows recovery, not strict immutability.
- B. Access Control Lists (ACLs) manage permissions but do not prevent data alteration or deletion during a retention period, even by authorized users.
- D. Version Management keeps previous versions of blobs but does not prevent modification or deletion of the current version or guarantee immutability over time.
Azure Blob Storage Immutability Policies
Immutability policies for Azure Blob Storage allow you to store business-critical data in a WORM (Write Once, Read Many) state, ensuring it cannot be deleted or modified for a specified duration.
- Supports regulatory compliance (e.g., FINRA, GDPR).
- Includes time-based retention and legal holds.
- Once locked, policies cannot be modified or deleted.
Memory trick: WORM storage means Write Once, Read Many, like a digital time capsule.