During a Data Domain bring-up, a compliance officer sees hourly snapshots configured and says the immutability requirement is met. Which feature should you enable to satisfy enforced undeletability for protected data?
Select an answer to reveal the explanation.
Short Explanation
Think of snapshots like bookmarks in a book: they show where you were, but they don't stop you tearing out pages. Retention lock is the enforceable 'do not delete' rule, so if compliance demands immutability, you need it, not just frequent recovery points.
Full Explanation
Data Domain snapshots capture a point-in-time view of the file system so you can recover to an earlier state if data is corrupted or accidentally deleted. They are still subject to normal deletion and lifecycle management, so a snapshot schedule alone does not prove immutability. Retention lock, especially compliance mode, places an enforced retention period on protected data; until that period expires, deletion and modification are blocked even for privileged administrators, which is what an immutability requirement needs. Hourly snapshots are wrong because frequency improves recovery-point objective but does not prevent deletion. Secure Multi-Tenancy is wrong because it separates tenants and administrative domains, reducing cross-tenant access, but it does not make an object undeletable. DD Boost is wrong because it is an integration and deduplication offload mechanism for backup applications, not a data-protection or retention enforcement feature. Exam caveat: do not confuse recovery points, access isolation, and retention lock; only retention lock provides enforced undeletability. Operational check: verify the MTree or protected data set has a compliance-mode retention lock with an expiration date that matches the policy, then test that a delete attempt is rejected before expiry.