Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Which TWO actions should you take to protect Azure Virtual Machines from ransomware? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure Backup with immutable vault.

Option C is correct because Azure Backup with an immutable vault prevents backup data from being altered or deleted during the retention period, which is essential for recovering VMs after a ransomware attack encrypts or destroys production data. Option E is correct because Microsoft Defender for Servers provides threat detection, vulnerability assessment, and file integrity monitoring, and it can raise alerts on suspicious ransomware-like behavior on the VM. Option A is not correct because blocking all inbound traffic with Azure Firewall would not stop ransomware delivered through outbound connections, compromised credentials, or already-running workloads, and it is not a ransomware-specific protection. Option B is not correct because Azure Site Recovery provides replication and disaster recovery failover, but it does not by itself protect backups from tampering or detect ransomware. Option D is not correct because encryption at rest protects data confidentiality if disks are stolen, but it does not prevent ransomware from encrypting files on a running VM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Azure Firewall to block all inbound traffic.

    Why it's wrong here

    Azure Firewall controls network layer access by blocking inbound traffic, but it does not prevent ransomware from executing on a VM once the attacker has compromised a legitimate service or user account. Ransomware often spreads via outbound connections, email attachments, or vulnerability exploitation that bypasses simple inbound rules. A firewall is a preventive control, not a detection or recovery control, so it cannot protect against internal execution or lateral movement.

  • ✗

    Configure Azure Site Recovery for all VMs.

    Why it's wrong here

    Azure Site Recovery (ASR) is designed for disaster recovery, replicating VMs to a secondary region for failover during outages. It is not a backup service and does not provide granular, immutable restore points that can be used to recover individual files or VMs after a ransomware attack. ASR replicated copies are also vulnerable if the primary and secondary environments are compromised together, and ASR does not offer WORM protection to prevent encryption or deletion by malicious actors.

  • ✓

    Enable Azure Backup with immutable vault.

    Why this is correct

    Azure Backup with an immutable vault uses Write-Once, Read-Many (WORM) storage, which prevents backups from being deleted, modified, or encrypted by ransomware even if admin credentials are stolen. This ensures you always have a clean, valid recovery point to restore VMs to a pre-infection state. Immutable backups are a critical last line of defense because they isolate recovery data from the attack surface and align with Azure's recommended ransomware protection strategy.

  • ✗

    Assign Azure Policy to require encryption at rest.

    Why it's wrong here

    Requiring encryption at rest via Azure Policy protects data confidentiality by ensuring that stored data is unreadable without a decryption key, but it does nothing to stop ransomware from encrypting the active filesystem on a running VM. Ransomware attacks target the integrity and availability of data, not confidentiality, so the files are still encrypted by the attacker and held for ransom. Encryption at rest is a complementary control, not a direct mitigation for ransomware execution or data extortion.

  • ✓

    Enable Microsoft Defender for Servers.

    Why this is correct

    Microsoft Defender for Servers provides continuous threat detection, endpoint detection and response (EDR), and automated investigation that can identify ransomware behavior such as mass file encryption or suspicious PowerShell activity. It alerts security teams in real time, enabling rapid response to contain the attack before data loss occurs. Defender also integrates with Azure Backup to validate and initiate recovery, making it an active defense layer rather than a passive prevention or recovery mechanism.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.