AZ-104 - Monitor and Maintain Azure Resources (14% of the exam) - Section 5.2

Implement backup and recovery solutions using Azure Backup and Azure Site Recovery.

Configure Azure Backup by registering resources with a Recovery Services vault and assigning backup policies that define frequency and retention. Distinguish Azure Backup, which protects against data loss and accidental deletion, from Azure Site Recovery, which replicates workloads to a secondary region using replication policies to meet recovery time and recovery point objectives.

Azure BackupRecovery Services vaultbackup policiesAzure Site Recoveryreplication policies

Practice question for this objective

Free sampleMonitor and Maintain Azure Resourcesmedium

A security review asks which built-in Recovery Services vault capabilities protect backup data from tampering or accidental loss by malicious or unauthorized actors. Which capabilities apply? (Select 2 answers)

  • ASoft delete that retains a deleted backup for a recovery window Correct
  • BData isolation that keeps backups in a Microsoft-managed tenant Correct
  • CAzure Advisor that surfaces hourly cost optimization suggestions
  • DCentral monitoring that surfaces backup jobs from one portal
  • EAutomatic storage that allocates vault capacity behind the scenes
Soft delete and data isolation are the vault controls that defend backup data against tampering or accidental deletion. Soft delete retains a maliciously or accidentally deleted backup for an extra recovery window, and data isolation stores vaulted backups in a Microsoft-managed subscription and tenant so unauthorized users cannot tamper with or delete them.

Why A is correct: Correct. Soft delete that retains a deleted backup for a recovery window is one of the keyed answers. Soft delete retains a maliciously or accidentally deleted backup for an extra recovery window, and data isolation stores vaulted backups in a Microsoft-managed subscription and tenant so unauthorized users cannot tamper with or delete them.

Why B is correct: Correct. Data isolation that keeps backups in a Microsoft-managed tenant is one of the keyed answers. Soft delete retains a maliciously or accidentally deleted backup for an extra recovery window, and data isolation stores vaulted backups in a Microsoft-managed subscription and tenant so unauthorized users cannot tamper with or delete them.

Why C is wrong: Azure Advisor recommends backing up unprotected VMs and optimizing deployments; it is not a data-tamper protection control.

Why D is wrong: Central monitoring gives visibility into Backup and Site Recovery jobs but does not itself protect data from tampering or deletion.

Why E is wrong: Automatic storage management handles capacity allocation; it is not a security control against malicious or accidental data loss.

See more AZ-104 practice questions, answers explained.

Exam traps in Monitor and Maintain Azure Resources

Answers that look right on this material and are not. Each one is a distractor from a different question in the AZ-104 bank for this domain.

  • Customer-managed keys, encrypting the restored data with your own keys

    Why it is wrong: Customer-managed keys control encryption of backup data; they do not let you restore into the paired secondary region on demand.

  • Yes

    Why it is wrong: Answering Yes would conflate VM-level snapshots with the workload-aware SQL backup. The default VM backup uses VSS Full Copy-Only for SQL, which does not truncate logs and does not give log-based point-in-time database recovery.

  • Replication every 30 seconds for Azure VMs, with Hyper-V continuous

    Why it is wrong: Azure VMs and VMware VMs get continuous replication, while the as-low-as 30-second frequency applies to Hyper-V, not the other way around.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.