nerdexam
Microsoft

SC-100 · Question #201

You have a Microsoft Entra tenant that syncs with an Active Directory Domain Services (AD DS) domain. You have an on-premises datacenter that contains 100 servers. The servers run Windows Server and…

The correct answer is A. From Azure Backup, configure multi-user authorization by using Resource Guard. MUA for Azure Backup uses a new resource called the Resource Guard to ensure critical operations, such as disabling soft delete, stopping and deleting backups, or reducing retention of backup policies, are performed only with applicable authorization…

Design solutions that align with security best practices and priorities

Question

You have a Microsoft Entra tenant that syncs with an Active Directory Domain Services (AD DS) domain. You have an on-premises datacenter that contains 100 servers. The servers run Windows Server and are backed up by using Microsoft Azure Backup Server (MABS). You are designing a recovery solution for ransomware attacks. The solution follows Microsoft Security Best Practices. You need to ensure that a compromised local administrator account cannot be used to stop scheduled backups. What should you do?

Options

  • AFrom Azure Backup, configure multi-user authorization by using Resource Guard.
  • BFrom Microsoft Entra Privileged Identity Management (PIM), create a role assignment for the
  • CFrom Microsoft Azure Backup Setup, register MABS with a Recovery Services vault.
  • DFrom a Recovery Services vault, generate a security PIN for critical operations.

How the community answered

(35 responses)
  • A
    77% (27)
  • B
    11% (4)
  • C
    9% (3)
  • D
    3% (1)

Explanation

MUA for Azure Backup uses a new resource called the Resource Guard to ensure critical operations, such as disabling soft delete, stopping and deleting backups, or reducing retention of backup policies, are performed only with applicable authorization. https://learn.microsoft.com/en-us/azure/backup/protect-backups-from-ransomware-faq

Topics

#Azure Backup Security#Ransomware Recovery#Data Protection#Security Best Practices

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice