Azure Resource Locks for Storage Containers
You have an Azure Storage account named storage1. You need to ensure that containers can be created in, but not deleted from, storage1. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests Azure governance tools, specifically the difference between soft delete (retention) and hard delete prevention via locks.
This question tests the use of Azure Resource Manager locks to prevent accidental deletion of resources. It establishes that a Delete lock is the correct control to enforce immutability at the resource level.
Learners often confuse Soft Delete with Locks, thinking C or D prevents deletion entirely rather than just providing a recovery window.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure Resource Manager locks are designed to protect resources from unwanted changes or deletions. A 'Delete' lock specifically prevents users from deleting the resource, while still allowing them to modify it. Since the requirement is to allow container creation (modification/addition) but prevent deletion, a Delete lock on the storage account is the appropriate mechanism.Why the Other Options Are Wrong
ReadOnly locks prevent both modification and deletion, which violates the requirement to create containers. Soft Delete (options C and D) allows data to be deleted but retained for a period for recovery; it does not prevent the initial deletion action itself, nor does it strictly prohibit the act of deleting in the way a lock does.Community Comment Notes
The community consensus strongly supports option B, with multiple users confirming that a delete lock is the standard solution for this scenario. One user noted the practical steps involve navigating to the Locks blade in the Settings section, reinforcing that this is a manual configuration task within the Azure portal.Exam Strategy
When asked to prevent deletion while allowing modification, look for 'Delete Lock'. When asked to prevent any changes, look for 'ReadOnly Lock'. Soft delete is for recovery, not prevention.
Frequently Asked Questions
Why doesn't Soft Delete prevent containers from being deleted?
Soft Delete retains deleted data for recovery but does not block the deletion operation itself. A Delete lock explicitly blocks the permission to delete.
Can I apply a lock directly to a container instead of the account?
Yes, locks can be applied to individual resources, but applying it to the storage account covers all its containers automatically.
Related Analysis
Practice All AZ-900 Questions
Access 90 questions with complete answers and detailed explanations.
View Full AZ-900 Practice Test →