Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium

A healthcare organization stores patient records in an Azure Storage account. To meet strict regulatory compliance requirements, all stored data must be immutable for a specific duration, preventing any modification or deletion, even by administrators. After this duration, the data can be modified or deleted. Which Azure Storage feature should be configured?

  1. AAzure Active Directory (AAD) authentication for storage.
  2. BSoft delete for blobs.
  3. CCustomer-Managed Keys (CMK) for encryption.
  4. DVersion-level immutability support.
Show answer & explanation

Correct answer: D. Version-level immutability support.

Version-level immutability support (time-based retention policy) for Azure Blob Storage allows you to set an immutable policy on a blob version for a specified retention period. This prevents deletion or modification of the blob version, even by privileged users, meeting the 'Write Once, Read Many' (WORM) requirement for compliance.

Why the other options are wrong

  • A. AAD authentication controls who can access the storage account, but not the immutability of the data itself once access is granted.
  • B. Soft delete retains deleted blobs for a period, allowing recovery, but does not prevent modification or deletion by authorized users during the active state.
  • C. CMK controls the encryption key, but does not prevent modification or deletion of the data itself.

Version-level immutability support (WORM)

A feature for Azure Blob Storage that enables Write Once, Read Many (WORM) compliance by allowing you to set a time-based retention policy on individual blob versions, making them immutable for the specified duration.

  • Achieves WORM compliance.
  • Prevents modification or deletion for a set period.
  • Applies at the blob version level.

Memory trick: Version immutability 'freezes' your data like a timestamped, unchangeable record.

More Secure data and applications questions