SC-100 - Design Solutions that Align with Security Best Practices and Priorities (23% of the exam) - Section 1.1

Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices.

Design a resiliency strategy that counters ransomware and other destructive attacks by combining secure backup and restore, business continuity and disaster recovery (BCDR) planning, and timely security updates. Prioritise privileged access controls and validate that business resiliency goals are met before, during, and after an incident.

ransomware mitigationbusiness continuity and disaster recovery (BCDR)secure backup and restoreprivileged access prioritisationbusiness resiliency goalssecurity updates

Practice question for this objective

Free sampleDesign Solutions that Align with Security Best Practices and Prioritieshard

During a tabletop exercise, a hospital group finds that responders disagreed about which systems to restore first, so non-urgent applications competed with life-critical clinical systems for the same recovery resources. The architect must add the planning artefact that resolves this before a real ransomware event. Which design practice best addresses the problem?

  • AShorten the recovery time objective for every application equally so that all systems are guaranteed to be restored within the same short window after an incident.
  • BIncrease backup frequency for every system so that more recent restore points are available and the recovery point objective improves uniformly across the estate.
  • CReplicate all clinical and non-clinical workloads to a standby region so that any disagreement can be sidestepped by failing the entire estate over at once.
  • DDefine and agree a tiered list of business-critical services with a fixed recovery priority order so responders restore the most essential systems first during an incident. Correct
Business resiliency planning requires an agreed criticality tiering and recovery priority order so the most essential services are restored first during an incident. Recovery resources are finite during an incident, so without an agreed priority order critical systems compete with trivial ones. Defining business-critical service tiers and a fixed recovery sequence in advance directs responders to restore the most essential services first, which uniform objectives or more copies cannot resolve.

Why A is wrong: Tightening every recovery time objective sounds ambitious and resilience-minded, but treating all systems as equally urgent ignores capacity limits and recreates the very contention observed, so it does not resolve the prioritisation problem.

Why B is wrong: More frequent backups improve data freshness and are tempting as general resilience, but the dispute is about restore order rather than how recent the data is, so this addresses a different dimension and leaves the contention unresolved.

Why C is wrong: A wholesale regional failover seems to make ordering irrelevant and is tempting, but a destructive attack often corrupts the replicated state and the standby still has finite capacity, so the priority question returns rather than disappearing.

Why D is correct: A pre-agreed criticality tiering with a fixed recovery order removes the contention by telling responders exactly which systems come back first, which is the business resiliency planning the requirement is missing.

See more SC-100 practice questions, answers explained.

Exam traps in Design Solutions that Align with Security Best Practices and Priorities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-100 bank for this domain.

  • Add a Conditional Access policy that requires multifactor authentication at sign-in for the operators before they reach the vault, directory, and restore tooling from their existing everyday laptops.

    Why it is wrong: Requiring multifactor at sign-in raises the bar for an initial logon and feels protective, but it leaves administration originating from a compromised productivity device, where a stolen session token can be replayed after the multifactor check, so the pivot path remains open.

  • Restore in parallel across all systems simultaneously to minimise the recovery time objective and return to operations fastest.

    Why it is wrong: Parallel mass restore optimises speed and is attractive under pressure, but skipping validation risks reinfecting the whole estate at once, so prioritising recovery time over verification undermines trustworthy recovery.

  • Keep one shared recovery time objective but procure additional standby compute so that the single target can be met for the whole estate at once during a destructive incident.

    Why it is wrong: Buying enough standby capacity to meet one tight target everywhere sounds thorough, but it spends heavily to give trivial systems a critical-grade target and still cannot differentiate by impact, so it fails the requirement to match objectives to each tier.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.