Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A security architect is designing a strategy to protect sensitive data in Azure Storage accounts from accidental deletion, ransomware attacks, and unauthorized overwrites. The solution must ensure that data remains immutable for a specified retention period, even by administrators. Which Azure Blob Storage feature should be implemented?

  1. AAccess Control Lists (ACLs) on containers.
  2. BSoft Delete for Blobs
  3. CBlob versioning
  4. DImmutability policy with time-based retention or legal hold.
Show answer & explanation

Correct answer: D. Immutability policy with time-based retention or legal hold.

An immutability policy with time-based retention or legal hold ensures that data in Azure Blob Storage cannot be deleted or modified for a specified period, even by users with administrative privileges. This provides strong protection against accidental deletion, ransomware, and unauthorized overwrites, meeting the 'immutable' requirement.

Why the other options are wrong

  • A. ACLs control access permissions to containers and blobs but do not provide immutability; an authorized user can still modify or delete data if they have the necessary permissions.
  • B. Soft Delete for Blobs allows recovery of accidentally deleted blobs but does not prevent overwrites or provide immutability against malicious actors or administrators for a defined retention period.
  • C. Blob versioning keeps previous versions of a blob when it's modified or deleted, allowing recovery. However, it doesn't prevent deletion of the entire blob or provide a rigid immutability lock against administrators.

Azure Blob Immutability Policy

An Azure Blob Storage feature that allows users to store business-critical data in a Write Once, Read Many (WORM) state, ensuring that data cannot be modified or deleted for a specified retention interval or until a legal hold is removed.

  • Prevents deletion and modification of blobs.
  • Supports time-based retention and legal hold.
  • Protects against accidental deletion, ransomware, and insider threats.
  • Compliance with regulatory requirements (e.g., SEC 17a-4(f)).

Memory trick: Immutability Locks Data Down Tight.

More Design security for infrastructure questions