Azure Resource Locks for Storage Containers

Describe features and tools in Azure for governance and compliance
Answer Correct answer: B — Create a delete lock for storage1 to prevent deletion while allowing modifications like container creation.

You have an Azure Storage account named storage1. You need to ensure that containers can be created in, but not deleted from, storage1. What should you do?

  1. Create a ReadOnly lock for storage1.
  2. Create a delete lock for storage1. Correct Answer
  3. Enable container soft delete.
  4. Enable blob soft delete.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests Azure governance tools, specifically the difference between soft delete (retention) and hard delete prevention via locks.

This question tests the use of Azure Resource Manager locks to prevent accidental deletion of resources. It establishes that a Delete lock is the correct control to enforce immutability at the resource level.

Learners often confuse Soft Delete with Locks, thinking C or D prevents deletion entirely rather than just providing a recovery window.

Community Discussion (4 comments)

ThugLifeB3 👍 5 Selected: B
Correct answer is B
jambroba 👍 1 Selected: B
✅ B. Create a delete lock for storage1.
TestTaker09876 👍 1
Its exactly, what it sounds like (create a delete lock), but here is how you would actually do it 1) In the Settings blade for the resource, resource group, or subscription that you wish to lock, select Locks 2) To add a lock, select Add. If you want to create a lock at a parent level, select the parent. The currently selected resource inherits the lock from the parent. For example, you could lock the resource group to apply a lock to all its resources. 3) Give the lock a name and lock level. Optionally, you can add notes that describe the lock (in this case delete) 4 (to remove the lock) To delete the lock, select the Delete button https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/lock-resources?tabs=json#portal
TaboloDude 👍 3
B. is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure Resource Manager locks are designed to protect resources from unwanted changes or deletions. A 'Delete' lock specifically prevents users from deleting the resource, while still allowing them to modify it. Since the requirement is to allow container creation (modification/addition) but prevent deletion, a Delete lock on the storage account is the appropriate mechanism.

Why the Other Options Are Wrong

ReadOnly locks prevent both modification and deletion, which violates the requirement to create containers. Soft Delete (options C and D) allows data to be deleted but retained for a period for recovery; it does not prevent the initial deletion action itself, nor does it strictly prohibit the act of deleting in the way a lock does.

Community Comment Notes

The community consensus strongly supports option B, with multiple users confirming that a delete lock is the standard solution for this scenario. One user noted the practical steps involve navigating to the Locks blade in the Settings section, reinforcing that this is a manual configuration task within the Azure portal.

Exam Strategy

When asked to prevent deletion while allowing modification, look for 'Delete Lock'. When asked to prevent any changes, look for 'ReadOnly Lock'. Soft delete is for recovery, not prevention.

Frequently Asked Questions

Why doesn't Soft Delete prevent containers from being deleted?

Soft Delete retains deleted data for recovery but does not block the deletion operation itself. A Delete lock explicitly blocks the permission to delete.

Can I apply a lock directly to a container instead of the account?

Yes, locks can be applied to individual resources, but applying it to the storage account covers all its containers automatically.

Related Analysis

Practice All AZ-900 Questions

Access 90 questions with complete answers and detailed explanations.

View Full AZ-900 Practice Test →

← Back to AZ-900 Study Guide