AZ-305 Design data storage solutions Practice Question
A financial services company needs to store transaction logs for regulatory compliance. The logs must be stored in a cost-effective manner, and they must be immutable to prevent tampering. The logs are accessed infrequently but must be retained for 7 years. Which Azure storage solution should you recommend?
⚠ Common exam trap
Candidates often confuse Azure SQL Database long-term retention (which is for backup recovery, not immutable storage) with true immutability, or assume that any snapshot or TTL mechanism can satisfy regulatory immutability requirements when they actually allow deletion or modification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Blob Storage with immutable storage policy and cool access tier
Azure Blob Storage with an immutable storage policy (WORM) ensures that transaction logs cannot be modified or deleted during the retention period, meeting compliance requirements. The cool access tier is cost-effective for infrequently accessed data, and the 7-year retention aligns with the policy's time-based retention. This combination provides both immutability and low-cost storage for long-term archival.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Cosmos DB with time-to-live (TTL)
Why it's wrong here
Azure Cosmos DB is a multi-model NoSQL database engineered for low-latency transactional access and elastic scale, not for serving as an append-only log repository. Its TTL feature only schedules automatic deletion of expired documents—it still permits in-place updates and deletes before expiration, so it cannot provide the tamper-evident, write-once-read-many guarantees required for financial transaction logs. Moreover, Cosmos DB's request-unit consumption and provisioned throughput make it significantly more expensive than object storage for high-volume, write-heavy log data that is rarely read.
- ✓
Azure Blob Storage with immutable storage policy and cool access tier
Why this is correct
Azure Blob Storage with an immutable storage policy (WORM) ensures that blobs cannot be modified or deleted for a user-specified retention interval, which directly meets the compliance requirements for tamper-proof financial transaction logs. The cool access tier offers low storage costs for data that is infrequently accessed—ideal for logs retained for regulatory audits—while still allowing blob versioning and lifecycle management for eventual archival or deletion. This combination delivers durable, scalable, and cost-effective storage optimised for append-only log workloads.
- ✗
Azure SQL Database with long-term retention backup
Why it's wrong here
Azure SQL Database long-term retention (LTR) backups are designed for disaster recovery and point-in-time restoration of relational databases, not for immutable audit trails. LTR backups are internal system-managed copies, not independently accessible log files, and they do not provide WORM guarantees—administrators with database permissions can still modify or delete live data before a backup occurs. Additionally, the cost of storing relational data with indexes and high transaction throughput scales poorly for massive volumes of log entries, making this option impractical and uneconomical.
- ✗
Azure Files with share snapshots
Why it's wrong here
Azure Files share snapshots create point-in-time read-only copies of an Azure file share, but the live share remains fully writable, allowing application-level tampering before any snapshot is taken and providing no immutable, append-only guarantee. Snapshots also lack granular retention policies and management features needed for regulatory compliance, such as locked time-based retention or legal holds. Frequent snapshots of large log shares consume excessive storage capacity and generate operational overhead, making this approach cost-prohibitive and functionally inadequate for secure transaction log storage.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.