Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You manage an Azure Recovery Services vault that backs up workloads hosted in Azure and on-premises. Security administrators ask you to guarantee that no user-including a compromised subscription owner-can delete or modify any recovery point for 180 days while still allowing restores during that time. Which action should you take to meet this requirement?

  • Enable immutability on the Recovery Services vault and set the retention lock to 180 days.

  • Configure cross-region restore for the vault to replicate recovery points to a secondary region.

  • Encrypt the vault with a customer-managed key stored in Azure Key Vault.

  • Turn on soft delete for the vault so deleted backup items are kept for 14 days.

Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot