Courseiva
Monitor and Maintain Azure ResourcesmediumMultiple ChoiceObjective-mapped

AZ-104 Monitor and Maintain Azure Resources Practice Question

Exhibit

Recovery Services vault settings
--------------------------------
Soft delete: Disabled
Backup item state: Protection stopped
Deleted backup item: vm-fin-02
Time since deletion: 14 hours
Recovery requirement: Re-enable protection and recover deleted backup data

Based on the exhibit, a backup administrator accidentally stopped protection for a critical VM and then deleted its backup item. The team wants Azure Backup to retain the deleted item long enough to recover it after the mistake is discovered the next day. What should be enabled on the vault?

⚠ Common exam trap

Many candidates confuse soft delete for backup data with resource locks or network security rules, mistakenly thinking that protecting the VM itself or enabling network access will preserve deleted backup items, when in fact only the vault-level soft delete feature retains the backup data after deletion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Soft delete for backup data

Soft delete for backup data is the correct answer because it provides a safety net for accidentally deleted backup items. When enabled, Azure Backup retains deleted backup data for an additional 14 days (default) in a soft-deleted state, allowing administrators to recover the data before it is permanently purged. This directly addresses the scenario where protection was stopped and the backup item was deleted, as the data remains recoverable within the retention period.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Soft delete for backup data

    Why this is correct

    Soft delete for backup data in Azure Backup retains accidentally deleted backup items for a default grace period of 14 days after protection is stopped or the backup item is deleted. During this window, the backup data is not permanently purged and can be recovered or restored without any data loss. This makes it the direct solution for a scenario where an administrator mistakenly stops protection and later wants to retrieve that backup data. Note that soft delete is a vault-level setting and must be enabled in the Recovery Services vault to take effect.

  • A read-only resource lock on the VM

    Why it's wrong here

    A read-only resource lock on the VM protects the Azure virtual machine resource from being modified or deleted, but backup data lives in a separate Recovery Services vault, not on the VM itself. Even if a lock is placed on the vault, it only prevents changes to the vault's configuration and would not restore a backup item that was already deleted or whose protection was stopped. Resource locks are governance controls for Azure resources and do not interact with or preserve backup items in the backup lifecycle. Thus it cannot address the accidental deletion of backup data.

    When this WOULD be correct

    A read-only resource lock on a VM would be correct in a scenario where you need to prevent accidental deletion or modification of the VM by users or automated processes, such as protecting a critical production VM from being stopped or deleted.

  • A network security group rule allowing port 445

    Why it's wrong here

    An NSG rule allowing port 445 would open SMB access to the VM, which is used for file shares, not for Azure Backup traffic. Azure Backup communicates with the vault over HTTPS (port 443) and does not rely on inbound port 445 for backup or restore operations. Network security groups control traffic at the network layer and have absolutely no effect on the retention, deletion, or recovery of backup items in a Recovery Services vault. Therefore, configuring port 445 cannot help recover a stopped or deleted backup item.

    When this WOULD be correct

    This option would be correct in a scenario where you need to enable file-level restore from an Azure VM backup to an on-premises machine, which requires port 445 (SMB) to be open for the restore process.

  • Instant restore snapshots set to 30 days

    Why it's wrong here

    Instant restore snapshots are locally stored VM snapshots that Azure Backup keeps for quick recovery, typically for 1–5 days based on the backup policy's instant restore settings. When you stop protection, these snapshots are not retained indefinitely and are eventually cleaned up, so a 30-day snapshot retention does not protect against the permanent deletion of backup data in the vault. Instant restore is designed to speed up recovery from recent recovery points, not to provide soft-delete protection or restore deleted backup items after the fact. Thus it does not address an accidental stop of protection.

    When this WOULD be correct

    This option would be correct in a scenario where the question asks: 'You need to ensure that recovery points for a VM are available for instant restore for a longer duration. What should you configure?' In that case, setting instant restore snapshots to 30 days would be the appropriate answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Soft delete for backup dataCorrect answer

Why this is correct

Soft delete for backup data in Azure Backup retains accidentally deleted backup items for a default grace period of 14 days after protection is stopped or the backup item is deleted. During this window, the backup data is not permanently purged and can be recovered or restored without any data loss. This makes it the direct solution for a scenario where an administrator mistakenly stops protection and later wants to retrieve that backup data. Note that soft delete is a vault-level setting and must be enabled in the Recovery Services vault to take effect.

A read-only resource lock on the VMWrong answer — click to see why

Why this is wrong here

A read-only resource lock on the VM prevents deletion or modification of the VM itself, but does not affect the backup vault's retention of deleted backup items. The lock does not enable soft delete or extend retention of backup data.

★ When this WOULD be the correct answer

A read-only resource lock on a VM would be correct in a scenario where you need to prevent accidental deletion or modification of the VM by users or automated processes, such as protecting a critical production VM from being stopped or deleted.

Why candidates choose this

Candidates may think that locking the VM prevents the backup item from being deleted, confusing resource-level protection with backup data retention.

A network security group rule allowing port 445Wrong answer — click to see why

Why this is wrong here

A network security group rule allowing port 445 is used for SMB file sharing, not for retaining deleted backup items. It does not affect backup retention or recovery of deleted backups.

★ When this WOULD be the correct answer

This option would be correct in a scenario where you need to enable file-level restore from an Azure VM backup to an on-premises machine, which requires port 445 (SMB) to be open for the restore process.

Why candidates choose this

Candidates might confuse network connectivity requirements for backup restore operations with backup retention features, or think that enabling SMB port helps in recovering deleted backup data.

Instant restore snapshots set to 30 daysWrong answer — click to see why

Why this is wrong here

Instant restore snapshots set to 30 days controls how long recovery points are retained for immediate restoration, but it does not protect against deletion of the backup item itself. The question asks for retaining a deleted backup item after accidental deletion, which is achieved by soft delete, not by extending snapshot retention.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the question asks: 'You need to ensure that recovery points for a VM are available for instant restore for a longer duration. What should you configure?' In that case, setting instant restore snapshots to 30 days would be the appropriate answer.

Why candidates choose this

Candidates may confuse the retention of recovery points with the ability to recover a deleted backup item. They might think that increasing snapshot retention would keep the data available after deletion, not realizing that deletion of the backup item removes all associated recovery points regardless of retention settings.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.