Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy

A manufacturing company uses Azure Storage accounts to store sensor data from IoT devices. They need to ensure that this data is immutable and cannot be modified or deleted for a period of seven years to comply with regulatory requirements. Which Azure Storage feature should be configured to meet this retention and immutability requirement?

  1. ABlob versioning
  2. BSoft delete for blobs
  3. CAzure Backup for Storage accounts
  4. DImmutability policy (time-based retention)
Show answer & explanation

Correct answer: D. Immutability policy (time-based retention)

An immutability policy with time-based retention is designed to make data non-erasable and non-modifiable for a specified period, directly fulfilling the regulatory compliance requirement.

Why the other options are wrong

  • A. Blob versioning keeps previous versions of a blob, but the current version can still be modified or deleted.
  • B. Soft delete protects against accidental deletion but allows data to be permanently deleted after the retention period.
  • C. Azure Backup creates copies of data but doesn't inherently make the source data immutable within the storage account.

Immutability policy (time-based retention)

A feature of Azure Blob Storage that allows users to store business-critical data in a WORM (Write Once, Read Many) state for a user-specified interval, ensuring data cannot be modified or deleted for the retention period.

  • Enforces WORM state for regulatory compliance.
  • Supports time-based retention and legal holds.
  • Once set, cannot be shortened or removed in a locked state.

Memory trick: Immutability: a digital concrete block for your data.

More Secure data and applications questions