Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A healthcare organization stores patient records in an Azure Storage account. To meet strict compliance regulations, they must ensure that all data written to a specific container is immutable for a period of 7 years, preventing any deletion or modification during this time. Which Azure Storage feature should be configured?
- AVersion-level immutability support
- BAccess Policy with `Write` and `Delete` permissions removed
- CAzure Policy with Deny action
- DSoft Delete
Show answer & explanationAnswer & explanation
Correct answer: A. Version-level immutability support
Version-level immutability support for Azure Blob Storage allows users to create time-based retention policies that make data immutable for a specified duration, preventing deletion or modification, which directly addresses the compliance requirement for patient records.
Why the other options are wrong
- B. Removing `Write` and `Delete` permissions via an access policy only restricts specific users/applications but does not prevent a user with higher privileges from re-adding those permissions or deleting the data.
- C. Azure Policy with a Deny action can prevent certain operations, but it's not the native, robust solution for WORM compliance on data itself; immutability policies are purpose-built for this.
- D. Soft Delete protects against accidental deletion but does not enforce strict immutability for a defined period against all users, including those with delete permissions.
Version-level Immutability Support
An Azure Blob Storage feature that allows setting time-based retention policies on blobs, making them immutable (Write Once, Read Many) for compliance.
- Ensures data cannot be deleted or modified for a specified period.
- Supports both time-based retention and legal holds.
- Critical for regulatory compliance (e.g., HIPAA, FINRA).
Memory trick: Immutability: Your data's time capsule, sealed for compliance.