Microsoft Certified: Azure Administrator AssociateImplement and manage storageEasy

A financial institution needs to store audit logs in Azure Blob Storage. These logs must be retained for a minimum of seven years and cannot be modified or deleted during this period, even by administrators. After seven years, the logs can be deleted. Which Azure Blob Storage feature should be used to meet these requirements?

  1. AAccess control lists (ACLs)
  2. BSoft delete for blobs
  3. CBlob versioning
  4. DImmutable storage with time-based retention policy
Show answer & explanation

Correct answer: D. Immutable storage with time-based retention policy

Immutable storage with a time-based retention policy ensures that data cannot be modified or deleted for a specified duration, even by users with administrative privileges. This meets the strict regulatory compliance requirement for audit logs.

Why the other options are wrong

  • A. ACLs control access but do not prevent modification or deletion by authorized users or administrators.
  • B. Soft delete protects against accidental deletion but allows deletion after a retention period by administrators.
  • C. Blob versioning keeps previous versions but doesn't prevent deletion of the current blob or its versions by administrators.

Immutable Storage

Immutable storage for Azure Blob Storage allows users to store business-critical data in a WORM (Write Once, Read Many) state, meaning it cannot be modified or deleted for a specified retention period.

  • Supports time-based retention policies.
  • Legal holds can be applied for indefinite retention.
  • Data cannot be overwritten or deleted by any user, including root accounts.

Memory trick: Immutability locks data in time.

More Implement and manage storage questions