AZ-500 exam dumps

AZ-500 practice question 209 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 209

Select 2

You are a security engineer at Contoso. The organization is concerned about accidental or malicious deletion of backups stored in an Azure Recovery Services vault. You need to recommend steps to secure these backups so they remain protected even if unauthorized or unintended actions occur. Which two actions should you configure to meet this requirement?

  1. A

    Enable soft delete for the Recovery Services vault

  2. B

    Use encryption at rest with a customer-managed key stored in Azure Key Vault

  3. C

    Store backup copies in a different region using an openly accessible public endpoint

  4. D

    Grant the 'Owner' role to all backup operators to accelerate recovery

Show answer and explanation

Correct answers: A, B

Explanation

To protect backups in Azure, you should enable soft delete for the Recovery Services vault so that deleted backups remain recoverable for a retention period, preventing permanent data loss during accidental or malicious actions. Additionally, encrypting backups at rest with a customer-managed key stored in Azure Key Vault helps secure the data and comply with organizational or regulatory requirements. Refer to Microsoft Azure documentation for more details on configuring soft delete (https://learn.microsoft.com/azure/backup/backup-azure-protect-workloads) and customer-managed keys in Azure (https://learn.microsoft.com/azure/backup/backup-cmk-overview).

  • A. Correct.

    Enabling soft delete for the Recovery Services vault ensures that even if backup data is deleted (maliciously or accidentally), it remains recoverable for a specified retention period. This is a key best practice to protect backups from unauthorized deletion.

  • B. Correct.

    Using encryption at rest with your own key (BYOK) in Azure Key Vault helps maintain control over the encryption process and enhances data protection. This ensures that backup data is not readable without possession of the correct key.

  • C. Incorrect.

    Storing backups in an openly accessible public endpoint exposes them to unnecessary risk and is not a recommended best practice. Leveraging private endpoints and secure networking configurations is safer.

  • D. Incorrect.

    Assigning the 'Owner' role to all backup operators grants excessive privileges. This introduces a higher risk of accidental or malicious configuration changes, including deletion of backups.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam