SC-100 - Design Solutions that Align with Security Best Practices and Priorities - Section 1.1

Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices.

Design a resiliency strategy that counters ransomware and other destructive attacks by combining secure backup and restore, business continuity and disaster recovery (BCDR) planning, and timely security updates. Prioritise privileged access controls and validate that business resiliency goals are met before, during, and after an incident.

ransomware mitigationbusiness continuity and disaster recovery (BCDR)secure backup and restoreprivileged access prioritisationbusiness resiliency goalssecurity updates

Practice question for this objective

Free sampleDesign Solutions that Align with Security Best Practices and Prioritieshard

During a tabletop exercise, a hospital group finds that responders disagreed about which systems to restore first, so non-urgent applications competed with life-critical clinical systems for the same recovery resources. The architect must add the planning artefact that resolves this before a real ransomware event. Which design practice best addresses the problem?

  • AShorten the recovery time objective for every application equally so that all systems are guaranteed to be restored within the same short window after an incident.
  • BIncrease backup frequency for every system so that more recent restore points are available and the recovery point objective improves uniformly across the estate.
  • CReplicate all clinical and non-clinical workloads to a standby region so that any disagreement can be sidestepped by failing the entire estate over at once.
  • DDefine and agree a tiered list of business-critical services with a fixed recovery priority order so responders restore the most essential systems first during an incident. Correct
Business resiliency planning requires an agreed criticality tiering and recovery priority order so the most essential services are restored first during an incident. Recovery resources are finite during an incident, so without an agreed priority order critical systems compete with trivial ones. Defining business-critical service tiers and a fixed recovery sequence in advance directs responders to restore the most essential services first, which uniform objectives or more copies cannot resolve.

Why A is wrong: Tightening every recovery time objective sounds ambitious and resilience-minded, but treating all systems as equally urgent ignores capacity limits and recreates the very contention observed, so it does not resolve the prioritisation problem.

Why B is wrong: More frequent backups improve data freshness and are tempting as general resilience, but the dispute is about restore order rather than how recent the data is, so this addresses a different dimension and leaves the contention unresolved.

Why C is wrong: A wholesale regional failover seems to make ordering irrelevant and is tempting, but a destructive attack often corrupts the replicated state and the standby still has finite capacity, so the priority question returns rather than disappearing.

Why D is correct: A pre-agreed criticality tiering with a fixed recovery order removes the contention by telling responders exactly which systems come back first, which is the business resiliency planning the requirement is missing.

See more SC-100 practice questions, answers explained.

More in this domain

Back to all Design Solutions that Align with Security Best Practices and Priorities objectives, or the SC-100 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.