AZ-500 exam dumps

AZ-500 practice question 160 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 160

Select 2

You are an Azure Security Engineer for a medical research organization that stores sensitive data in Azure Blob Storage. Your primary requirements include: 1) Recovering data if a blob is accidentally or maliciously deleted, and 2) Storing certain critical data in a way that prevents any modifications or deletions to comply with regulatory requirements. Which two features should you enable on your Azure Storage account to meet these needs?

  1. A

    Enable soft delete for Azure Blobs

  2. B

    Enable blob versioning

  3. C

    Configure immutable storage with a legal hold policy

  4. D

    Use geo-redundant replication (GRS) for the storage account

  5. E

    Enable Azure Backup on the storage account

Show answer and explanation

Correct answers: A, C

Explanation

To protect data against accidental or malicious deletion in Azure Blob Storage, you should enable soft delete (and optionally set an appropriate retention period). This feature retains deleted blob snapshots for the configured time, allowing you to restore them if needed. For regulatory compliance or any scenario requiring data to be unalterable, configure immutable blob storage via legal hold or time-based retention. This ensures blobs remain in a write-once, read-many (WORM) state throughout the retention period or until a legal hold is explicitly cleared. For more information, see Microsoft Docs on Azure Blob Storage features (https://learn.microsoft.com/azure/storage/blobs/).

  • A. Correct.

    Option 1 (Enable soft delete for Azure Blobs): CORRECT. Soft delete allows you to recover blob data that has been accidentally or maliciously deleted within a specified retention period, fulfilling part of your requirement for recoverability.

  • B. Incorrect.

    Option 2 (Enable blob versioning): INCORRECT. While blob versioning provides a way to retain previous versions of blobs if data is overwritten, it does not directly prevent deletions or create an unmodifiable storage scenario. Though versioning can be valuable, it is not strictly necessary to meet the specific requirements of recovery from deletion and immutability.

  • C. Correct.

    Option 3 (Configure immutable storage with a legal hold policy): CORRECT. Immutable storage with a legal hold ensures that critical data cannot be modified or deleted once it is placed under the legal hold policy, addressing compliance requirements for unchangeable data.

  • D. Incorrect.

    Option 4 (Use geo-redundant replication (GRS) for the storage account): INCORRECT. GRS provides geographic redundancy for high availability but does not prevent or reverse deletions; a malicious or accidental delete can still propagate to the secondary region.

  • E. Incorrect.

    Option 5 (Enable Azure Backup on the storage account): INCORRECT. Azure Backup is not the primary solution for preventing malicious or accidental deletes on blob data. While Azure Backup can protect certain workloads, soft delete and immutable storage are more directly aligned with the stated requirements of data recoverability and immutability.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam