AZ-305 · Question 33 · Domain 3.1: Backup and Disaster Recovery
A financial company uses Azure Blob Storage to store immutable audit logs.
Recently, a compromised administrator account was used to maliciously delete several storage accounts and their associated backups.
You need to design a solution to protect against this specific ransomware/malicious insider threat. The solution must ensure that even a user with the highest administrative privileges cannot delete the backup data before a specified retention period expires.
What should you configure?
Answer options:
Soft delete for Azure Backup
Multi-user authorization (MUA) for Azure Backup
Azure Resource Locks (CanNotDelete)
Customer-managed keys (CMK) for encryption
55 questions · hints · full answers · grading