あなたの会社は、Microsoft セキュリティのベスト プラクティスに基づいて、Microsoft Defender for Endpoint の使用を最適化し、ランサムウェアからリソースを保護したいと考えています。 Microsoft セキュリティのベスト プラクティスの Microsoft Detection and Response Team (DART) のアプローチに基づいて、侵害されたコンピューターに対する侵害後の対応計画を準備する必要があります。 対応計画には何を含めるべきですか?
正解:D
If a ransomware attack is detected the affected entity should immediately activate its security incident response plan, which should include measures to isolate the infected computer systems in order to halt propagation of the attack. Note: Isolate devices from the network Depending on the severity of the attack and the sensitivity of the device, you might want to isolate the device from the network. This action can help prevent the attacker from controlling the compromised device and performing further activities such as data exfiltration and lateral movement. Reference: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-machine- alerts?view=o365-worldwide#isolate-devices-from-the- network