⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All AWS & Cloud Architecture Interview Questions Scenario 172 of 186 in AWS & Cloud Architecture
Staff Cloud Architect Azure & Cloud Cloud Security & Compliance Compliance Architecture

Q: Your financial trading platform must comply with SEC Rule 17a-4 and FINRA regulations requiring financial transaction records to be stored in Write-Once-Read-Many (WORM) format for 7 years, encrypted with customer-controlled HSM keys. Even global administrators must be prohibited from deleting or modifying files. How do you design and configure Azure Blob Storage?

Engineering a SEC Rule 17a-4 compliant immutable audit storage architecture using Azure Blob Storage Customer-Managed Keys (CMEK), time-based WORM retention, and legal hold policies.

#Azure #Storage Accounts #CMEK #Key Vault #Immutability #WORM #Compliance
🎙️ Candidate Opening & Architectural Context
"Standard cloud storage allows account administrators to delete containers or overwrite files. To satisfy strict SEC compliance, we architected an immutable blob storage framework utilizing Azure Key Vault Managed HSM CMEK and Locked Immutability Policies."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Provision Azure Key Vault Managed HSM & Encryption Key

Deploy dedicated FIPS 140-2 Level 3 hardware security modules for customer-managed encryption:

  • Managed HSM Creation: Provisioned Azure Key Vault Managed HSM: az keyvault create --hsm-name hsm-compliance --resource-group rg-sec --location eastus --retention-days 90 --enable-purge-protection true.
  • Create RSA Key: Generated an RSA 4096-bit key with automated annual key rotation policies enabled.
Pro Tip: Enabling purge protection and soft-delete guarantees that encryption keys cannot be permanently destroyed by rogue administrators or compromised credentials.
2️⃣

Configure Storage Account with User-Assigned Managed Identity CMEK

Bind storage account encryption to the Managed HSM key:

  • Storage CMEK Config: Updated storage account: az storage account update -g rg-sec -n stcompliance --encryption-key-name comp-key --encryption-key-vault $HSM_URI --encryption-key-source Microsoft.Keyvault --identity-type UserAssigned --user-identity-id $MI_ID.
  • Auto-Key Rotation: Enabled automatic key rotation detection so the storage service adopts newly rotated key versions without manual intervention.
Pro Tip: If the CMEK key is revoked or disabled in Key Vault, all data in the storage account becomes cryptographically inaccessible within minutes.
3️⃣

Apply Time-Based Immutability Policy and Lock the Policy

Enforce Write Once, Read Many (WORM) compliance at the container level:

  • Create Immutability Policy: Configured policy on audit container: az storage container immutability-policy create --account-name stcompliance --container-name audit-records --period 2555 --allow-protected-append-writes false (2,555 days = 7 years).
  • Lock the Policy: Executed az storage container immutability-policy lock --account-name stcompliance --container-name audit-records.
Pro Tip: WARNING: Once an immutability policy is locked, it CANNOT be removed or shortened—even by Microsoft Azure support or tenant Global Admins. Files cannot be overwritten or deleted until the retention timer expires.
4️⃣

Test Legal Hold Enforcement & SEC 17a-4 Attestation

Validate regulatory enforcement and generate non-repudiation audit trails:

  • Simulate Deletion: Attempted to delete a blob and delete the container using Tenant Administrator credentials; operation rejected with HTTP 409 BlobImmutableDueToPolicy.
  • Legal Hold Capability: Verified that placing a Legal Hold tag locks blobs indefinitely regardless of retention expiration for ongoing litigation.
Pro Tip: Azure provides formal SEC Rule 17a-4(f) and CFTC 1.31 compliance attestation letters confirming this configuration satisfies federal financial requirements.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Locked Azure Blob Immutability Policies enforce tamper-proof WORM storage compliance that cannot be overridden by any administrator, while Key Vault Managed HSM CMEK provides full cryptographic data ownership."
⚡ 60-Second Elevator Pitch Talking Points
  • Deploy Azure Key Vault Managed HSM with purge protection and 4096-bit RSA keys.
  • Configure Storage Accounts with Customer-Managed Keys (CMEK) and auto-rotation.
  • Apply time-based immutability retention policies (7 years) and permanently lock the policy.
  • Satisfy SEC Rule 17a-4 and FINRA requirements with cryptographic non-repudiation.
Advertisement
Want more AWS & Cloud Architecture scenarios?
Explore our complete collection of scenario-based AWS & Cloud Architecture interview runbooks.
Browse All AWS & Cloud Architecture Questions →