Courseiva
Question 1,129 of 1,049
Implement and Manage StoragehardMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Storage Practice Question

Your application stores regulatory records in Azure Blob Storage. The records must remain in a write-once-read-many state for four years and must not be altered or deleted during that time. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse soft delete (which only protects against deletion) with immutable storage (which prevents both modification and deletion), leading them to choose blob soft delete when the question explicitly requires a write-once-read-many state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Immutable blob storage with a time-based retention policy

Immutable blob storage with a time-based retention policy enforces a write-once-read-many (WORM) state, ensuring that blobs cannot be modified or deleted for a specified duration. This directly meets the regulatory requirement of four-year retention without alteration or deletion, as the policy locks the data at the container level and prevents any changes until the retention period expires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Blob soft delete

    Why it's wrong here

    Blob soft delete is a recovery feature that preserves deleted blobs for a configurable retention window, but it does nothing to prevent deletion or modification during the blobs' active lifetime. A user or application with write access can still overwrite or delete a blob, and the soft-deleted copy is only retained after the deletion operation succeeds. Therefore soft delete provides no immutability or compliance-grade WORM assurance.

    When this WOULD be correct

    A question requiring protection against accidental deletion of blobs for a specific retention period, without needing to prevent overwrites or modifications, would make blob soft delete correct.

  • Immutable blob storage with a time-based retention policy

    Why this is correct

    Immutable blob storage with a time-based retention policy provides WORM (Write Once, Read Many) protection at the container level, explicitly preventing any modification or deletion of blobs for the configured retention period. This satisfies regulatory requirements for records retention (e.g., SEC 17a-4) because even the storage account owner cannot overwrite or purge the data. The policy is enforced by Azure Storage itself, independent of client permissions, making it a true compliance-grade control.

  • Lifecycle management to move data to Archive

    Why it's wrong here

    Lifecycle management policies automatically move blobs between access tiers (e.g., hot to cool to Archive) based on age or other conditions, but they never enforce immutability or block writes and deletes. Archive tier still allows modifications and deletions, and a user with permissions can remove the blob entirely. This is a cost-optimization feature, not a regulatory records-retention control.

    When this WOULD be correct

    A question asks: 'You need to automatically move blobs older than 90 days to cool storage to reduce costs. What should you configure?' In that scenario, lifecycle management is the correct answer.

  • A shared access signature

    Why it's wrong here

    A shared access signature (SAS) is a URI-based delegation token that grants granular permissions (read, write, delete, etc.) to a specific resource for a limited time. It controls access only, and cannot impose retention or immutability on the underlying data; once a SAS is issued, the holder can perform whatever operations the permissions allow. Thus it is a security mechanism, not a data preservation control.

    When this WOULD be correct

    A question requiring time-limited, secure access to a specific blob or container for a third-party application, without exposing the storage account key, would make a SAS the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Immutable blob storage with a time-based retention policyCorrect answer

Why this is correct

Immutable blob storage with a time-based retention policy provides WORM (Write Once, Read Many) protection at the container level, explicitly preventing any modification or deletion of blobs for the configured retention period. This satisfies regulatory requirements for records retention (e.g., SEC 17a-4) because even the storage account owner cannot overwrite or purge the data. The policy is enforced by Azure Storage itself, independent of client permissions, making it a true compliance-grade control.

Blob soft deleteWrong answer — click to see why

Why this is wrong here

Blob soft delete protects against accidental deletion but does not prevent overwrites or enforce a write-once-read-many (WORM) state, so it cannot ensure records remain unaltered for four years.

★ When this WOULD be the correct answer

A question requiring protection against accidental deletion of blobs for a specific retention period, without needing to prevent overwrites or modifications, would make blob soft delete correct.

Why candidates choose this

Candidates may confuse soft delete with immutable storage because both offer data protection, but soft delete only handles deletion, not modification, leading to a false sense of compliance.

Lifecycle management to move data to ArchiveWrong answer — click to see why

Why this is wrong here

Lifecycle management moves data to Archive tier based on age, but does not prevent deletion or modification. The question requires a write-once-read-many (WORM) state with deletion protection, which lifecycle management cannot enforce.

★ When this WOULD be the correct answer

A question asks: 'You need to automatically move blobs older than 90 days to cool storage to reduce costs. What should you configure?' In that scenario, lifecycle management is the correct answer.

Why candidates choose this

Candidates may confuse cost optimization (archiving old data) with data protection requirements, assuming that moving data to Archive also prevents modification, which it does not.

A shared access signatureWrong answer — click to see why

Why this is wrong here

A shared access signature (SAS) provides delegated access to storage resources but does not enforce write-once-read-many (WORM) compliance or prevent deletion or modification of blobs.

★ When this WOULD be the correct answer

A question requiring time-limited, secure access to a specific blob or container for a third-party application, without exposing the storage account key, would make a SAS the correct answer.

Why candidates choose this

Candidates may confuse access control mechanisms with data protection policies, thinking that restricting access via SAS can prevent unauthorized modifications or deletions.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.