CV0-004 Operations and Support Practice Question
A cloud administrator is responsible for a Microsoft Azure environment where several production virtual machines must be backed up nightly. The recovery requirements state that backups must be retained for 90 days, that individual files must be restorable without recovering the entire VM, and that the backup data must be encrypted at rest. Which Azure Backup configuration should the administrator implement?
⚠ Common exam trap
A common mix-up: candidates confuse replication for disaster recovery, such as Azure Site Recovery, with point-in-time backup that supports file-level restore and long-term retention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Recovery Services vault, enable Azure Backup for the VMs, and set a daily backup policy with 90-day retention.
Azure Backup with a Recovery Services vault is the native solution for VM backup in Azure. The vault encrypts backup data at rest, the backup policy defines the nightly schedule and 90-day retention, and file-level recovery lets administrators restore individual files from a recovery point without recovering the entire VM, matching all three requirements in the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Recovery Services vault, enable Azure Backup for the VMs, and set a daily backup policy with 90-day retention.
Why this is correct
Azure Backup stores VM backups in a Recovery Services vault, which encrypts data at rest by default. The policy controls the backup schedule and retention, and file-level recovery is supported directly from the recovery point. This combination satisfies the nightly schedule, 90-day retention, file restore, and encryption requirements.
- ✗
Configure Azure Site Recovery replication with a 90-day retention policy.
Why it's wrong here
Azure Site Recovery replicates virtual machines to a secondary region for disaster recovery and failover. It does not produce point-in-time backups that allow individual file restoration, and its retention model is based on recovery points, not a 90-day file-level backup archive, so it does not meet the stated requirements.
- ✗
Configure Azure Files share snapshots with a 90-day retention policy for the VM data.
Why it's wrong here
Azure Files share snapshots apply to data stored in Azure Files shares, not to the operating system and data disks of virtual machines. Unless the VM data lives on an Azure Files share, this does not protect the VMs, and it cannot restore VM files from a VM backup in the way the scenario requires.
- ✗
Enable Azure Disk Encryption on each VM and schedule snapshots with a 90-day retention rule.
Why it's wrong here
Azure Disk Encryption protects data at rest on the disks, and snapshots can be retained, but snapshots are block-level copies that do not natively support restoring a single file without attaching and mounting the snapshot. This approach adds complexity and does not deliver the straightforward file-level restore the recovery requirements specify.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.