A healthcare organization stores patient records in an Azure Storage account. To meet strict HIPAA compliance requirements, they must ensure that once a blob is written, it cannot be modified or deleted for a period of seven years, even by administrators. This policy needs to apply to specific containers within the storage account. Which Azure Storage feature should be implemented?
- AAzure Policy to prevent blob deletions and modifications.
- BVersion-level immutability support with a legal hold.
- CTime-based retention policy on a container with 'AllowProtectedAppendWrites' enabled.
- DSoft delete for blobs with a retention period of seven years.
Show answer & explanationAnswer & explanation
Correct answer: C. Time-based retention policy on a container with 'AllowProtectedAppendWrites' enabled.
A time-based retention policy on a container, with 'AllowProtectedAppendWrites' enabled, directly meets the requirement. This creates an immutable storage where blobs cannot be modified or deleted for the specified duration (seven years). 'AllowProtectedAppendWrites' allows new blocks to be appended to existing block blobs, which might be necessary for logging or auditing without altering historical data, while maintaining immutability for existing content. This feature is designed for WORM (Write Once, Read Many) compliance.
Why the other options are wrong
- A. Azure Policy can enforce configurations but cannot, by itself, create an immutable WORM (Write Once, Read Many) state that prevents even administrators from modifying or deleting data.
- B. Version-level immutability support is a feature, but the core requirement of preventing modification/deletion for a fixed period (seven years) for compliance, and potentially allowing append writes, is best met by a time-based retention policy at the container level.
- D. Soft delete provides data recovery but does not guarantee immutability or prevent deletion/modification by authorized users during the retention period.
Time-based retention policy (WORM)
A feature in Azure Blob Storage that applies an immutable, Write Once, Read Many (WORM) state to a container or blob, preventing modification or deletion for a specified duration, even by users with administrative privileges.
- Enforces immutability for compliance (e.g., HIPAA, FINRA).
- Can be configured at the container level.
- Supports 'AllowProtectedAppendWrites' for specific use cases.
- Retention period can be configured for a fixed time or indefinitely (legal hold).
Memory trick: Lock your storage data in time, so no one can change its history.