Soru

Zorluk: OrtaAzure Virtual Machine Backup Configuration

An administrator is configuring backups for a new virtual machine named vm-finance-prod that runs Windows Server 2025 and is located in the East US region. The virtual machine has Azure Disk Encryption (ADE) enabled, and its encryption secrets are stored in an Azure Key Vault named kv-finance-keys in the East US region. The Key Vault's firewalls and virtual networks are configured to restrict access to selected networks only.

Which two actions are required to configure backups for vm-finance-prod successfully? (Select two.)

  1. Create a Recovery Services Vault in the East US region.Cevap
  2. Configure the firewall of the Key Vault kv-finance-keys to allow trusted Microsoft services.Cevap
  3. C
    Create a Recovery Services Vault in the West US region.
  4. D
    Create a Backup Vault in the East US region.
  5. E
    Add the public IP address of the Recovery Services Vault to the allowed IP address ranges on the Key Vault firewall.

Cevap

To successfully back up the virtual machine, you must create a Recovery Services Vault in the East US region and configure the Key Vault firewall to allow trusted Microsoft services to bypass the network restrictions.
To back up an Azure Virtual Machine, the backup must be configured in a Recovery Services Vault that matches the region of the source virtual machine (East US). In addition, for virtual machines using Azure Disk Encryption (ADE), the backup service must be able to reach the Key Vault containing the secrets. When the Key Vault has firewalls enabled, enabling the option to allow trusted Microsoft services to bypass the firewall is the supported configuration that permits the backup service to safely retrieve the encryption keys.

Adım Adım Çözüm

1
Identify the geographical region of the target virtual machine.
The virtual machine is located in the East US region.
Azure Virtual Machine backups require the backup vault to be in the same region as the virtual machine.
2
Determine the required vault type for backing up an Azure Virtual Machine.
A Recovery Services Vault must be selected instead of a Backup Vault.
Recovery Services Vaults support virtual machine backup workloads, whereas Backup Vaults support other resources like Azure Disks and Blobs.
3
Configure the Key Vault firewall to allow Azure Backup access.
Enable the 'Allow trusted Microsoft services to bypass this firewall' option.
Since the virtual machine is encrypted using Azure Disk Encryption (ADE), Azure Backup must retrieve the keys and secrets from the Key Vault. If the Key Vault firewall restricts access, this bypass is required to grant the backup service access.

Anahtar Kavram

Azure Virtual Machine Backup Configuration with Azure Disk Encryption and Region Matching
Bu soruyu puanla