Courseiva

AZ-305 Design business continuity solutions Practice Question

Which THREE of the following are best practices for designing a business continuity solution using Azure Backup? (Choose three.)

⚠ Common exam trap

Candidates often confuse 'simplifying management' (Option B) with best practice, but Azure Backup requires workload-specific policies to meet RPO/RTO requirements, and a single policy would either over-retain or under-protect different resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable soft delete to protect backup data from accidental deletion

Enabling soft delete in Azure Backup protects backup data from accidental or malicious deletion by retaining deleted backup data for an additional 14 days (configurable up to 14 days). This ensures that even if a backup item is deleted, the data remains recoverable, which is a critical best practice for business continuity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable soft delete to protect backup data from accidental deletion

    Why this is correct

    Soft delete in Azure Backup adds a safety net by retaining deleted backup data for a default retention period (14 days) after deletion, allowing recovery of backup items that were accidentally or maliciously removed. This prevents permanent data loss when a Recovery Services vault or a backup item is deleted, because the protected data and its restore points remain available for restoration within the soft-delete window. Administrators must explicitly re-enable soft delete if disabled, and re-deleting an item after the soft-delete period results in permanent deletion.

  • ✗

    Configure a single backup policy for all resources to simplify management

    Why it's wrong here

    A single backup policy applied to all resources is an anti-pattern because workloads differ in recovery point objectives (RPO) and retention requirements—for example, a database may require hourly backups with 35-day retention, while a file share may only need daily backups with 7-day retention. Using one policy forces a one-size-fits-all approach that either over-provisions storage and costs for low-priority workloads or fails to meet the minimal RPO of critical systems. Azure Backup policies are scoped per vault and per item, so multiple policies should be defined to match the specific SLAs of each workload.

  • ✓

    Use geo-redundant storage (GRS) for the backup data to protect against regional disasters

    Why this is correct

    Configuring geo-redundant storage (GRS) for Azure Backup Recovery Services vaults ensures that backup data is replicated asynchronously to a paired Azure region, providing resilience if the primary region experiences a disaster or becomes unavailable. With GRS, restore points become available in the paired region, enabling cross-region restore to recover from regional outages, and it offers higher durability than locally redundant storage (LRS) by maintaining three copies in the primary and three more in the secondary region. This design choice is a core best practice for disaster recovery scenarios where the primary workload region might fail.

  • ✓

    Use separate Recovery Services vaults for different workloads or regions

    Why this is correct

    Using separate Recovery Services vaults for different workloads or geographic regions enforces isolation boundaries for security, management, and monitoring, preventing a misconfiguration or security incident in one workload from affecting others. Each vault has its own RBAC role assignments, diagnostic settings, and backup policies, allowing fine-grained access control and auditability aligned with the least-privilege principle. It also reduces the blast radius of accidental deletions or policy changes, as operations in one vault do not impact unrelated resources in another vault.

  • ✗

    Grant all users 'Backup Contributor' role to ensure backups are taken

    Why it's wrong here

    Assigning the Backup Contributor role to all users is a violation of the least privilege principle because that role grants permissions to enable backup, configure policies, stop protection, and delete backup data—not just to view or trigger backups. Most users who need to view backup status or perform application-specific operations do not require these administrative capabilities, and excessive permissions increase the risk of accidental or malicious modifications to backup configurations and deletion of recovery points. Access should be granted only to the specific Azure Backup administrators or ops team members who manage backup infrastructure, using scoped roles and resource groups.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.