70-158 · Question #65
You administer a Forefront Identity Management (FIM) 2010 server in your company network. You need to configure a regular backup of the FIM Synchronization Service while minimizing interruption to…
The correct answer is D. Export the FIM Synchronization Service encryption key during the backup process. When backing up the FIM Synchronization Service, exporting the encryption key is a critical step because the key protects sensitive data and is required for restoring the service. This approach allows backups to proceed without necessarily stopping the service.
Question
Options
- AInclude the FIM Service database along with the backup.
- BStop the FIM Synchronization Service before performing the backup.
- CEnsure that all management agents are running during the backup process.
- DExport the FIM Synchronization Service encryption key during the backup process.
How the community answered
(33 responses)- A3% (1)
- B9% (3)
- C12% (4)
- D76% (25)
Why each option
When backing up the FIM Synchronization Service, exporting the encryption key is a critical step because the key protects sensitive data and is required for restoring the service. This approach allows backups to proceed without necessarily stopping the service.
The FIM Service database is a separate component from the FIM Synchronization Service database; including it does not specifically address the backup requirements of the Synchronization Service or its encryption key.
Stopping the FIM Synchronization Service before backup would cause unnecessary interruption to the service, which contradicts the requirement to minimize interruption if possible.
Having management agents running during a backup does not constitute a backup best practice for FIM Sync and does not protect or capture the encryption key or service configuration data.
The FIM Synchronization Service uses an encryption key to protect sensitive credential and configuration data stored in the metaverse and connector spaces. Exporting this encryption key during the backup process ensures that the backup is fully restorable, since without the encryption key, the backed-up data cannot be decrypted and the service cannot be recovered. This is the recommended best practice for FIM Sync backups and does not require stopping the service, thus minimizing interruption.
Concept tested: FIM Synchronization Service backup and encryption key export
Source: https://learn.microsoft.com/en-us/microsoft-identity-manager/mim-how-provision-users-adds
Topics
Community Discussion
No community discussion yet for this question.