Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium
A security architect is designing a strategy to protect sensitive data in Azure Storage accounts from accidental deletion, ransomware attacks, and unauthorized overwrites. The solution must ensure that data remains immutable for a specified retention period, even by administrators. Which Azure Blob Storage feature should be implemented?
- AAccess Control Lists (ACLs) on containers.
- BSoft Delete for Blobs
- CBlob versioning
- DImmutability policy with time-based retention or legal hold.
Show answer & explanationAnswer & explanation
Correct answer: D. Immutability policy with time-based retention or legal hold.
An immutability policy with time-based retention or legal hold ensures that data in Azure Blob Storage cannot be deleted or modified for a specified period, even by users with administrative privileges. This provides strong protection against accidental deletion, ransomware, and unauthorized overwrites, meeting the 'immutable' requirement.
Why the other options are wrong
- A. ACLs control access permissions to containers and blobs but do not provide immutability; an authorized user can still modify or delete data if they have the necessary permissions.
- B. Soft Delete for Blobs allows recovery of accidentally deleted blobs but does not prevent overwrites or provide immutability against malicious actors or administrators for a defined retention period.
- C. Blob versioning keeps previous versions of a blob when it's modified or deleted, allowing recovery. However, it doesn't prevent deletion of the entire blob or provide a rigid immutability lock against administrators.
Azure Blob Immutability Policy
An Azure Blob Storage feature that allows users to store business-critical data in a Write Once, Read Many (WORM) state, ensuring that data cannot be modified or deleted for a specified retention interval or until a legal hold is removed.
- Prevents deletion and modification of blobs.
- Supports time-based retention and legal hold.
- Protects against accidental deletion, ransomware, and insider threats.
- Compliance with regulatory requirements (e.g., SEC 17a-4(f)).
Memory trick: Immutability Locks Data Down Tight.