Fabrikam, Inc. operates 14 manufacturing plants. Security spending is currently spread evenly across all systems, and the audit committee can't tell which outages the company could absorb and which would halt production. You must recommend a security strategy that supports business resiliency goals and that makes the prioritization of business-critical assets defensible to the committee. Which two elements should you include in the recommendation? Each correct answer presents part of the solution. (Choose TWO.)
Choose 2.
- A.
ExpressRoute circuits replacing all site-to-site VPNs between plants and Azure
- B.
Business-agreed impact tiers, each with an RTO, RPO, and protection level
- C.
Scheduled isolated restore tests of the top tier, reporting achieved recovery times
- D.
A 90 percent Secure Score target, funding the fastest-scoring recommendations
- E.
Two-year interactive retention for every table in the Log Analytics workspace
Show answer
Answer: B, C
A defensible resiliency strategy needs business-agreed impact tiers with recovery objectives and regular proof that the most critical tier can be recovered within them.
- A. ExpressRoute is a connectivity decision; it doesn't classify critical assets or prove that they can be recovered.
- B. Tiers agreed with business owners, each with recovery objectives, turn resiliency priorities into a defensible and auditable service level.
- C. Rehearsed restores prove the objectives are achievable and expose hidden dependencies before a real incident, which Microsoft's guidance requires.
- D. Chasing a posture score optimizes a metric and can move funding away from the business-critical systems the committee asked about.
- E. Longer log retention helps investigation, but it neither prioritizes assets nor improves the ability to recover them.