Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A manufacturing company uses Azure Storage accounts to store sensor data from IoT devices. They need to ensure that this data is immutable and cannot be modified or deleted for a period of seven years to comply with regulatory requirements. Which Azure Storage feature should be configured to meet this retention and immutability requirement?
- ABlob versioning
- BSoft delete for blobs
- CAzure Backup for Storage accounts
- DImmutability policy (time-based retention)
Show answer & explanationAnswer & explanation
Correct answer: D. Immutability policy (time-based retention)
An immutability policy with time-based retention is designed to make data non-erasable and non-modifiable for a specified period, directly fulfilling the regulatory compliance requirement.
Why the other options are wrong
- A. Blob versioning keeps previous versions of a blob, but the current version can still be modified or deleted.
- B. Soft delete protects against accidental deletion but allows data to be permanently deleted after the retention period.
- C. Azure Backup creates copies of data but doesn't inherently make the source data immutable within the storage account.
Immutability policy (time-based retention)
A feature of Azure Blob Storage that allows users to store business-critical data in a WORM (Write Once, Read Many) state for a user-specified interval, ensuring data cannot be modified or deleted for the retention period.
- Enforces WORM state for regulatory compliance.
- Supports time-based retention and legal holds.
- Once set, cannot be shortened or removed in a locked state.
Memory trick: Immutability: a digital concrete block for your data.