SC-100 · Question #147
Your organization is in the process of moving its on-premises VMs into Azure; you're using Azure Backup to protect these VMs. The Chief Information Officer is concerned about ransomware attacks and ha
The correct answer is C. Require PINs for critical operations D. Enable soft delete. Both answers address Azure-native, cost-effective ransomware protection. Soft delete (D) retains deleted or overwritten backup data for a configurable retention period (14 days by default), preventing ransomware from permanently destroying backups. Requiring a security PIN for cr
Question
Your organization is in the process of moving its on-premises VMs into Azure; you're using Azure Backup to protect these VMs. The Chief Information Officer is concerned about ransomware attacks and has asked for an Azure native cost-effective solution that can be initiated in case of a ransomware attack, and a backup restoration is necessary. What security configurations can you implement?
Options
- ABackup to Azure Data Box
- BA Veeam backup solution
- CRequire PINs for critical operations
- DEnable soft delete
How the community answered
(25 responses)- A12% (3)
- B4% (1)
- C84% (21)
Explanation
Both answers address Azure-native, cost-effective ransomware protection. Soft delete (D) retains deleted or overwritten backup data for a configurable retention period (14 days by default), preventing ransomware from permanently destroying backups. Requiring a security PIN for critical operations (C) - such as stopping backup protection or deleting backup data - adds a multi-person authorization control so ransomware or a compromised admin account cannot silently disable protection. Azure Data Box (A) is an offline bulk-transfer appliance, not a backup-protection feature. Veeam (B) is a third-party solution, violating the 'Azure native' requirement.
Topics
Community Discussion
No community discussion yet for this question.