Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A client is designing a data protection strategy for highly sensitive medical records stored in Azure Blob Storage. These records must meet stringent compliance requirements, including immutable storage for auditing purposes for a fixed period and legal hold capabilities. The solution must prevent any deletion or modification of the data, even by privileged administrators, until the retention period expires or the legal hold is released. Which Azure Blob Storage feature should be implemented?

  1. AAccess Control Lists (ACLs) on Blob Storage
  2. BSoft Delete for Blob Storage
  3. CVersion control for Blob Storage
  4. DBlob immutability policy (time-based retention and legal hold)
Show answer & explanation

Correct answer: D. Blob immutability policy (time-based retention and legal hold)

Blob immutability policies, specifically time-based retention and legal hold, are designed to prevent deletion or modification of data for a specified period or until a legal hold is explicitly removed, satisfying stringent compliance requirements for sensitive records.

Why the other options are wrong

  • A. ACLs control access permissions but do not enforce immutability or prevent deletion by authorized users.
  • B. Soft Delete helps recover accidentally deleted blobs but does not prevent deletion by administrators or enforce immutable retention.
  • C. Version control keeps previous versions but allows the current version to be modified or deleted, not ensuring immutability.

Azure Blob Immutability Policy

Azure Blob Immutability Policy provides Write Once, Read Many (WORM) support for Blob storage, enabling users to store business-critical data in a non-erasable, non-modifiable state for a specified period or for legal hold purposes.

  • WORM (Write Once, Read Many) compliance.
  • Supports time-based retention and legal hold.
  • Prevents deletion or modification of data even by privileged users.
  • Essential for regulatory compliance (e.g., FINRA, HIPAA, SEC 17a-4).

Memory trick: Immutability Locks, Soft Delete Recovers, Versions Track Changes.

More Design security for infrastructure questions