100 台の Linux デバイスを含む Microsoft 365 E5 サブスクリプションがあります。デバイスは Microsoft Defender 365 にオンボードされています。Microsoft 365 Defender ポータルを使用して、デバイスから調査パッケージの収集を開始する必要があります。どの応答アクションを使用する必要がありますか?
正解:C
In Microsoft 365 Defender , the Collect investigation package action allows a security analyst to remotely gather forensic evidence (logs, running processes, network info, registry data, etc.) from a device for deeper analysis. This capability is supported on both Windows and Linux devices onboarded to Microsoft Defender for Endpoint. The other options serve different purposes: * Run antivirus scan: triggers a malware scan, not evidence collection. * Initiate Automated Investigation: starts automated threat response but not direct evidence collection. * Initiate Live Response Session: opens an interactive session, but the question specifically asks for package collection via the portal. # Correct Answer: C. Collect investigation package