A security review asks which built-in Recovery Services vault capabilities protect backup data from tampering or accidental loss by malicious or unauthorized actors. Which capabilities apply? (Select 2 answers)
- ASoft delete that retains a deleted backup for a recovery window Correct
- BData isolation that keeps backups in a Microsoft-managed tenant Correct
- CAzure Advisor that surfaces hourly cost optimization suggestions
- DCentral monitoring that surfaces backup jobs from one portal
- EAutomatic storage that allocates vault capacity behind the scenes
Why A is correct: Correct. Soft delete that retains a deleted backup for a recovery window is one of the keyed answers. Soft delete retains a maliciously or accidentally deleted backup for an extra recovery window, and data isolation stores vaulted backups in a Microsoft-managed subscription and tenant so unauthorized users cannot tamper with or delete them.
Why B is correct: Correct. Data isolation that keeps backups in a Microsoft-managed tenant is one of the keyed answers. Soft delete retains a maliciously or accidentally deleted backup for an extra recovery window, and data isolation stores vaulted backups in a Microsoft-managed subscription and tenant so unauthorized users cannot tamper with or delete them.
Why C is wrong: Azure Advisor recommends backing up unprotected VMs and optimizing deployments; it is not a data-tamper protection control.
Why D is wrong: Central monitoring gives visibility into Backup and Site Recovery jobs but does not itself protect data from tampering or deletion.
Why E is wrong: Automatic storage management handles capacity allocation; it is not a security control against malicious or accidental data loss.