exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 5 question 4 discussion

Actual exam question from Microsoft's SC-100
Question #: 4
Topic #: 5
[All SC-100 Questions]

HOTSPOT -

Your company wants to optimize using Azure to protect its resources from ransomware.

You need to recommend which capabilities of Azure Backup and Azure Storage provide the strongest protection against ransomware attacks. The solution must follow Microsoft Security Best Practices.

What should you recommend? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
1235813
Highly Voted 2 years ago
Azure Backup: A security PIN Azure Storage: Immutable storage
upvoted 32 times
...
zellck
Highly Voted 1 year, 11 months ago
1. Security PIN 2. Immutable storage https://learn.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against-ransomware#azure-backup Checks have been added to make sure only valid users can perform various operations. These include adding an extra layer of authentication. As part of adding an extra layer of authentication for critical operations, you're prompted to enter a security PIN before modifying online backups. https://learn.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against-ransomware#steps-to-take-before-an-attack Online immutable storage (such as Azure Blob) enables you to store business-critical data objects in a WORM (Write Once, Read Many) state. This state makes the data non-erasable and non-modifiable for a user-specified interval.
upvoted 14 times
TomRoute66
7 months ago
For those not sure about the Azure Storage, also check this out:
upvoted 1 times
...
...
tocane
Most Recent 1 year, 4 months ago
1. Security PIN 2. Immutable storage
upvoted 3 times
...
Murtuza
1 year, 4 months ago
What is immutable storage against ransomware? Immutable storage, however, prevents data from being altered or deleted for a specified period. Even if ransomware gains access to the primary data, it cannot modify or encrypt immutable backup copies. This approach ensures the availability of uncorrupted data for recovery.
upvoted 3 times
...
smanzana
1 year, 6 months ago
1. Security PIN 2. Immutable storage
upvoted 1 times
...
ConanBarb
1 year, 7 months ago
Security pin and Immutable storage "Encryption by using platform-managed keys for Azure Storage" is always on by default, so doesn't makes sense. And even if it did, it doesn't protect against ransomware encryption. It protects the confidentiality of data.
upvoted 1 times
...
calotta1
1 year, 8 months ago
This is my understanding based on this article and why Immutable storage makes sense for the 2nd part: https://learn.microsoft.com/en-us/azure/storage/common/storage-service-encryption Azure Storage uses service-side encryption (SSE) to automatically encrypt your data when it is persisted to the cloud. Data in Azure Storage is encrypted and decrypted transparently using 256-bit AES encryption, one of the strongest block ciphers available, and is FIPS 140-2 compliant. Azure Storage encryption is similar to BitLocker encryption on Windows. Azure Storage encryption is enabled for all storage accounts, including both Resource Manager and classic storage accounts. Azure Storage encryption cannot be disabled. Because your data is secured by default, you don't need to modify your code or applications to take advantage of Azure Storage encryption.
upvoted 2 times
...
MaciekMT
2 years ago
It looks correct to me. A security PIN for backup and Encryption by using platform-managed keys for Azure Storage
upvoted 1 times
uffman
2 years ago
For Azure Backup I agree with a Security PIN. However, for Azure Storage I would argue that Immutable is the strongest, see here: https://learn.microsoft.com/en-us/azure/storage/blobs/security-recommendations#data-protection. Encryption is on by default, we can double encrypt data with infrastructure encryption but this is not an option.
upvoted 8 times
DavidSapery
2 years ago
Isn't immutable only for blobs?
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago