Courseiva
Monitor and Maintain Azure ResourceshardMatchingObjective-mapped

AZ-104 Monitor and Maintain Azure Resources Practice Question

Match each Recovery Services vault setting or feature to the behavior an administrator should expect after changing it.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Keeps deleted backup items recoverable for a limited retention period.

Stops future backups but preserves existing recovery points in the vault.

Stops protection and removes stored recovery points after the deletion process completes.

Allows restore operations from the secondary region when the vault uses geo-redundant storage and the feature is enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Changing replication to GRS: Replicates all existing recovery points

Changing replication to GRS replicates all existing recovery points. Soft delete retains deleted data for 14 days. Changing storage replication after backup requires reconfiguration. Custom managed identity grants specific resource access. Diagnostics settings send logs to Log Analytics. Cross Region Restore enables restore in paired region with GRS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Changing replication to GRS: Replicates all existing recovery points

    Why this is correct

    When you change a Recovery Services vault's storage redundancy from LRS to GRS, Azure automatically replicates all existing recovery points to the paired region. This is a one-time background operation that propagates historical backups without requiring reconfiguration, and subsequent backups are also replicated. The process ensures that all previously stored restore points become available in the secondary region for disaster recovery.

  • Soft delete: Retains deleted data for 14 days

    Why this is correct

    Soft delete is a security feature that protects backup data from accidental or malicious deletion. When a backup item is deleted, the data is retained in a soft-deleted state for 14 days, during which it can be restored and the deletion can be undone. After 14 days, the data is permanently purged, unless the soft delete state is re-enabled or the security feature is disabled with escalated privileges.

  • Changing storage replication after backup: Requires reconfiguration

    Why this is correct

    If you alter the storage replication type for a Recovery Services vault after a backup has already been taken, the vault must be reconfigured to apply the change. This reconfiguration includes stopping and restarting backup jobs or re-registering the backup items, because the existing recovery points are not automatically moved to the new setting. The change takes effect for future backups, but existing recovery points may not be migrated, so you must plan accordingly to avoid losing access to older restore points.

  • Custom managed identity: Grants specific resource access

    Why this is correct

    A custom managed identity assigned to a Recovery Services vault grants it access to specific Azure resources with a narrowly scoped set of permissions. For example, the vault can use the identity to authenticate to Azure Key Vault for encryption keys or to a storage account for archive or restore operations, without storing user credentials. This follows the principle of least privilege and reduces the risk of credential compromise.

  • Cross Region Restore: Sends logs to Log Analytics

    Why it's wrong here

    This statement is incorrect because Cross Region Restore does not send logs to Log Analytics; it enables restoring backup data to a paired Azure region when the vault is configured with GRS (geo-redundant storage). Log delivery to Log Analytics is accomplished through Diagnostics settings, which stream operational and audit logs to a chosen destination. Confusing the two features would lead you to configure the wrong component when trying to enable monitoring or disaster recovery.

  • Diagnostics settings: Enables restore in paired region with GRS

    Why it's wrong here

    Diagnostics settings are used to stream operational and audit logs from a Recovery Services vault to destinations such as Log Analytics, Event Hubs, or storage accounts. They do not enable or perform restores in a paired region; that capability belongs to Cross Region Restore, which requires GRS storage on the vault. This statement conflates a monitoring feature with a disaster recovery feature, leading to a false expectation about what Diagnostics settings can do.

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.