Microsoft 365 サブスクリプションをお持ちです。 サードパーティのウイルス対策製品がインストールされ、Microsoft Defender ウイルス対策がパッシブ モードになっている Windows デバイスが 1,000 台あります。サードパーティのウイルス対策製品では検出されなかった悪意のあるアーティファクトからデバイスを保護する必要があります。解決策: 制御されたフォルダー アクセスを構成します。これで目標は達成されますか?
正解:B
Controlled Folder Access (CFA) is an anti-ransomware feature that protects specified folders from unauthorized modification by untrusted apps. While CFA helps prevent malicious processes from encrypting or modifying important files, it is a targeted hardening control and does not provide the broad detection /remediation capability required to ensure devices are protected from arbitrary malicious artifacts that a third- party antivirus missed. CFA blocks certain behaviors (file write/modify) for protected directories but won't detect, quarantine, or remove unknown malicious files system-wide. The documented purpose of CFA is behavior-based protection for protected folders, not full post-breach remediation or EDR-style blocking. Therefore enabling CFA alone does not satisfy the requirement of ensuring devices are protected from artifacts that were undetected by the third-party AV.