Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You are deploying a critical application on Azure Virtual Machines that must remain highly available. You need to implement a security solution that ensures the application can recover from a ransomware attack that encrypts all data disks. What is the most cost-effective approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Azure Backup with immutable vault and soft delete.

Azure Backup with an immutable vault and soft delete (option A) is the most cost-effective solution because it provides ransomware-resistant, tamper-proof recovery points for the VM data disks at a lower cost than full VM replication, and immutability plus soft delete prevents attackers from deleting or altering backups during an attack. Azure Site Recovery (option C) is designed for disaster recovery and VM replication, which is more expensive and not specifically aimed at protecting backup data from ransomware. Azure Files snapshots (option B) only apply to Azure Files shares, not VM data disks, so they cannot protect the application's disk data. Daily disk snapshots stored in the same storage account (option D) are not immutable and can be deleted or encrypted along with the source data, making them a weak ransomware defense.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure Azure Backup with immutable vault and soft delete.

    Why this is correct

    Azure Backup's immutable vault (now generally available as immutable vault for Azure Backup) enforces a Write-Once, Read-Many (WORM) policy on recovery points, preventing ransomware from encrypting or deleting backups even with compromised administrator credentials. Soft delete adds a configurable retention window during which deleted backup data is retained and recoverable, giving defenders a second chance to restore from an attack. This layered approach directly addresses the backup integrity and recoverability requirements for a critical application, making it the correct choice.

  • ✗

    Use Azure Files share with snapshots for the application data.

    Why it's wrong here

    Azure Files snapshots are point-in-time read-only copies of a file share, not of VM disks. They are designed to protect file-share data, such as SMB/NFS-based workloads, not the operating system and data disks of a virtual machine. While snapshots can guard against accidental deletion or corruption of a file share, they do not provide comprehensive VM-level backup, and they remain subject to ransomware access if the storage account key is compromised—the snapshot shares the same storage account as the live share.

  • ✗

    Enable Azure Site Recovery for the virtual machines.

    Why it's wrong here

    Azure Site Recovery (ASR) replicates virtual machines to a secondary Azure region or on-premises site for disaster recovery (DR), ensuring business continuity during a regional outage or datacenter failure. It does not inherently protect against ransomware because replication is continuous and asynchronously mirrors the VM state; a ransomware-encrypted VM would replicate that corrupted state to the replica. ASR lacks the versioning or immutable copy capability needed for point-in-time recovery from a logical corruption or encryption event, so it is not the right mechanism for ransomware recovery.

  • ✗

    Take daily snapshots of the disks and store them in the same storage account.

    Why it's wrong here

    Storing VM disk snapshots in the same storage account as the source disks is a common but dangerous practice because ransomware that gains access to the storage account can delete or encrypt the snapshots alongside the live disks. Snapshots are point-in-time copies but are not immutable; they inherit the same RBAC permissions and are subject to deletion by any identity with write/delete access. Even if daily snapshots are taken, the recovery point may be lost, and the lack of off-site or isolated storage fails the backup isolation requirement central to ransomware defense.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.