SC-100 · Question #165
You design cloud-based software as a service (SaaS) solutions. You need to recommend a recovery solution for ransomware attacks. The solution must follow Microsoft Security Best Practices. What…
The correct answer is D. Prepare a recovery plan. Microsoft Security Best Practices for ransomware recovery (the 'Ransomware and Extortion' guidance) explicitly state that organizations should prepare a recovery plan first-before focusing on privileged access or data protection hardening-because recovery capability is the most…
Question
You design cloud-based software as a service (SaaS) solutions. You need to recommend a recovery solution for ransomware attacks. The solution must follow Microsoft Security Best Practices. What should you recommend doing first?
Options
- ADevelop a privileged identity strategy.
- BImplement data protection.
- CDevelop a privileged access strategy.
- DPrepare a recovery plan.
How the community answered
(39 responses)- A3% (1)
- B8% (3)
- C18% (7)
- D72% (28)
Explanation
Microsoft Security Best Practices for ransomware recovery (the 'Ransomware and Extortion' guidance) explicitly state that organizations should prepare a recovery plan first-before focusing on privileged access or data protection hardening-because recovery capability is the most foundational protection against a ransomware attack. Without a tested recovery plan and reliable backups, all other controls become last-resort measures. The plan must cover backup integrity, clean recovery targets, and restoration procedures. Privileged identity strategy (A) and privileged access strategy (C) are important hardening steps but are not the first priority in a recovery-focused design. Implementing data protection (B) is also valuable for prevention but is secondary to having a recovery plan in place.
Topics
Community Discussion
No community discussion yet for this question.