The production Key Vault and Recovery Services vault for the canal must survive an accidental delete by a privileged operator. Which control should be applied?
Select an answer to reveal the explanation.
Short Explanation
Training and wiki pages are polite suggestions. A CanNotDelete lock is the steel bolt on the vault door—and Policy can check that the bolt is still there on every critical asset.
Full Explanation
Azure resource locks with CanNotDelete prevent accidental or unauthorized deletion of critical assets such as Key Vault and Recovery Services vaults. Azure Policy can audit or enforce lock presence on those resource types. RBAC that still allows delete, documentation-only controls, and subscription moves do not provide the same deletion guardrail.