exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 5 question 5 discussion

Actual exam question from Microsoft's SC-100
Question #: 5
Topic #: 5
[All SC-100 Questions]

You have an Azure AD tenant that syncs with an Active Directory Domain Services (AD DS) domain.

You have an on-premises datacenter that contains 100 servers. The servers run Windows Server and are backed up by using Microsoft Azure Backup Server (MABS).

You are designing a recovery solution for ransomware attacks. The solution follows Microsoft Security Best Practices.

You need to ensure that a compromised administrator account cannot be used to delete the backups.

What should you do?

  • A. From Azure Backup, configure multi-user authorization by using Resource Guard.
  • B. From Microsoft Azure Backup Setup, register MABS with a Recovery Services vault.
  • C. From a Recovery Services vault, generate a security PIN for critical operations.
  • D. From Azure AD Privileged Identity Management (PIM), create a role assignment for the Backup Contributor role.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MaciekMT
Highly Voted 2 years, 2 months ago
Selected Answer: C
Option A is incorrect because multi-user authorization by using Resource Guard is used to provide additional protection for Azure resources, but it does not address the issue of compromised administrator accounts in MABS.
upvoted 30 times
deadheadx
11 months, 1 week ago
it does: https://learn.microsoft.com/en-us/azure/backup/protect-backups-from-ransomware-faq#what-are-the-best-practices-to-configure-and-protect-azure-backups-against-security-and-ransomware-threats
upvoted 2 times
...
EM1234
2 years, 1 month ago
I think this is correct. It is subtle but, being that both a and c do kind of satisfy the requirements, this difference is very important. Thank you MaciekMT.
upvoted 2 times
...
...
DashRyde
Highly Voted 2 years, 2 months ago
Selected Answer: A
MUA for Azure Backup uses a new resource called the Resource Guard to ensure critical operations, such as disabling soft delete, stopping and deleting backups, or reducing retention of backup policies, are performed only with applicable authorization. ref: https://learn.microsoft.com/en-us/azure/backup/protect-backups-from-ransomware-faq
upvoted 18 times
424ede1
2 months, 3 weeks ago
This wont help with a compromised admin account! The Backup admin must NOT have Contributor, Backup MUA Admin, or Backup MUA Operator access on the Resource Guard or the subscription that contains it.
upvoted 1 times
...
...
424ede1
Most Recent 2 months, 3 weeks ago
Selected Answer: C
To protect against ransomware, we need proper authentication to prevent a compromised admin account from performing critical operations. As part of adding an extra layer of authentication, you're prompted to enter a security PIN before modifying online backups. https://learn.microsoft.com/en-us/azure/backup/backup-azure-security-feature#prevent-attacks https://learn.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against-ransomware#azure-backup
upvoted 1 times
...
Ali96
4 months, 1 week ago
Selected Answer: A
A. From Azure Backup, configure multi-user authorization by using Resource Guard.
upvoted 1 times
...
emartiy
12 months ago
Selected Answer: A
Using MUA make you "ensure that a compromised administrator account cannot be used to delete the backups." since it needs multiple admin check and mua can't be disabled by admin backup admin without security admin approval for mua operator role activation.. https://learn.microsoft.com/en-us/azure/backup/multi-user-authorization?tabs=azure-portal&pivots=vaults-recovery-services-vault#disable-mua-on-a-recovery-services-vault To disable MUA on a vault, follow these steps: The Backup admin requests the Security admin for Backup MUA Operator role on the Resource Guard. They can request this to use the methods approved by the organization such as JIT procedures, like Microsoft Entra Privileged Identity Management, or other internal tools and procedures. The Security admin approves the request (if they find it worthy of being approved) and informs the Backup admin. Now the Backup admin has the Backup MUA Operator role on the Resource Guard.
upvoted 4 times
...
bxlin
1 year ago
Selected Answer: A
Only A works to ensure that a compromised administrator account cannot be used to delete the backups.
upvoted 4 times
...
wsrudmen
1 year, 3 months ago
Selected Answer: C
It's C and not A because: configuring multi-user authorization may not specifically prevent a compromised administrator account from deleting backups if the compromised account has sufficient permissions.
upvoted 3 times
jvallespin
10 months, 3 weeks ago
It's C but not because of this, MUA is multi-user so a compromised Admin alone could not do it ig you configure more approvers. MUA is not natively supported by MABS, that is the reason because its C.
upvoted 1 times
...
...
masby661
1 year, 3 months ago
Selected Answer: A
https://techcommunity.microsoft.com/t5/azure-governance-and-management/security-and-ransomware-protection-with-azure-backup/ba-p/3986246
upvoted 4 times
...
lt9898
1 year, 4 months ago
Selected Answer: A
Leaning toward Option A for the following reasons - Option A (MUA) and Option C (PIN) are both effective ways to add resistance to deletion of backups from a Recovery Services Vault https://learn.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against-ransomware?toc=%2Fazure%2Fbackup%2Ftoc.json&bc=%2Fazure%2Fbackup%2Fbreadcrumb%2Ftoc.json#steps-to-take-before-an-attack https://learn.microsoft.com/en-us/azure/backup/protect-backups-from-ransomware-faq#what-are-the-best-practices-to-configure-and-protect-azure-backups-against-security-and-ransomware-threats - The question's ask is "ensure that a compromised administrator account cannot be used to delete the backups" ... continued in reply
upvoted 5 times
lt9898
1 year, 4 months ago
- Reading this question literally, it's possible a compromised account means that not only are the admin credentials compromised, but also the 2nd factor of authentication generating the PIN neutralising the protection offered by Option C (PIN) - Option A (MUA) separates security concerns into two separate admin accounts, the Security Admin and Backup Admin. A malicious actor would need to compromise BOTH accounts simultaneously to delete a backup if MUA was implemented correctly.
upvoted 4 times
...
...
billo79152718
1 year, 4 months ago
I will go for A. MUA by Resource Guard recommend by microsoft. See link: https://learn.microsoft.com/en-us/azure/backup/protect-backups-from-ransomware-faq#what-are-the-best-practices-to-configure-and-protect-azure-backups-against-security-and-ransomware-threats
upvoted 5 times
...
Murtuza
1 year, 5 months ago
Selected Answer: C
Choice C is correct
upvoted 1 times
...
Murtuza
1 year, 5 months ago
Here are the subtle differences in the question. Pay attention to disabled vs deleted backups As part of adding an extra layer of authentication for critical operations, you're prompted to enter a security PIN when you perform Stop Protection with Delete data and Change Passphrase operations. Multi-user authorization (MUA) for Azure Backup allows you to add an additional layer of protection to critical operations on your Recovery Services vaults and Backup vaults. For MUA, Azure Backup uses another Azure resource called the Resource Guard to ensure critical operations are performed only with applicable authorization. MUA protects against disabling backups and reducing retention for backups.
upvoted 2 times
...
juanpe147
1 year, 6 months ago
i think now the recommendation MUA for Azure Backup, so i go with A
upvoted 2 times
...
Arjanussie
1 year, 6 months ago
A : f you have a compromised administrator account, you should configure multi-user authorization by using Resource Guard for your vaults. This will prevent the admin from deleting the backups without the approval of another user who owns the Resource Guard. A security PIN is not sufficient to protect your backups, as the compromised admin may be able to access or reset the PIN
upvoted 3 times
...
smanzana
1 year, 8 months ago
C. From a Recovery Services vault, generate a security PIN for critical operations
upvoted 1 times
...
sherifhamed
1 year, 9 months ago
Selected Answer: C
C. From a Recovery Services vault, generate a security PIN for critical operations. Configuring a security PIN for critical operations adds an extra layer of security for performing actions like deleting backups. Even if an administrator account is compromised, an attacker would also need access to the security PIN to perform critical operations, such as deleting backups. This aligns with the goal of preventing backups from being deleted, even if an administrator account is compromised. Options A and D are not directly related to securing backup operations: Options A and D are not directly related to securing backup operations: Options A and D are not directly related to securing backup operations: Options A and D are not directly related to securing backup operations: Options A and D are not directly related to securing backup operations:
upvoted 4 times
...
calotta1
1 year, 10 months ago
A is correct.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...