Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your company stores compliance-sensitive documents in an Azure Storage account. Regulations state that, after a blob is written, no user (including account owners) may modify or delete it for at least seven years, but administrators must retain the ability to create or remove whole containers when projects end. Which configuration change best satisfies the requirement with the least ongoing management effort?

  • Configure Azure Backup to protect the storage account with a seven-year retention vault policy.

  • Enable blob versioning and rely on automatic version retention for seven years.

  • Enable blob soft delete on the storage account and set the retention period to seven years.

  • Enable immutable storage on the container and set a time-based retention policy of seven years.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot