Valid SC-100 Dumps shared by ExamDiscuss.com for Helping Passing SC-100 Exam! ExamDiscuss.com now offer the newest SC-100 exam dumps, the ExamDiscuss.com SC-100 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com SC-100 dumps with Test Engine here:
You have an Azure subscription that contains virtual machines, storage accounts, and Azure SQL databases. All resources are backed up multiple times a day by using Azure Backup. You are developing a strategy to protect against ransomware attacks. You need to recommend which controls must be enabled to ensure that Azure Backup can be used to restore the resources in the event of a successful ransomware attack. Which two controls should you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Correct Answer: A,B
https://docs.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against-ransomware 'You need to recommend which CONTROLS must be enabled to ENSURE that Azure Backup can be used to RESTORE the resources in the event of a successful ransomware attack.' Whilst helpful for auditing purposes and detection of a malicious attack, monitoring configuration changes and alerting after a change is made does not represent a CONTROL which ENSURES Azure Backup can be used to RESTORE the resources.
Recent Comments (The most recent comments are at the top.)
sam - Jan 08, 2025
BE E Enable Soft Delete for Backups: Soft delete adds an additional layer of protection for your backup data. Even if a backup is deleted (whether accidentally or maliciously), it is retained for an additional period (14 days by default for Azure VMs and 30 days for Azure Blob Storage). During this retention period, the backup data can be recovered, ensuring that you can restore from these backups even if they are targeted in a ransomware attack.
B. Require PINs for Critical Operations: This control adds an extra layer of security by requiring a PIN for critical operations, such as deleting backup data or changing backup configurations. This can prevent malicious actors from easily performing destructive actions, even if they have compromised your environment. It's a form of multi-factor authentication that ensures only authorized users can perform sensitive operations on your backups.
Recent Comments (The most recent comments are at the top.)
BE
E Enable Soft Delete for Backups: Soft delete adds an additional layer of protection for your backup data. Even if a backup is deleted (whether accidentally or maliciously), it is retained for an additional period (14 days by default for Azure VMs and 30 days for Azure Blob Storage). During this retention period, the backup data can be recovered, ensuring that you can restore from these backups even if they are targeted in a ransomware attack.
B. Require PINs for Critical Operations: This control adds an extra layer of security by requiring a PIN for critical operations, such as deleting backup data or changing backup configurations. This can prevent malicious actors from easily performing destructive actions, even if they have compromised your environment. It's a form of multi-factor authentication that ensures only authorized users can perform sensitive operations on your backups.