Microsoft Defender for Endpoint を使用する Microsoft 365 E5 サブスクリプションをご利用の場合、マルウェア警告をトリガーしたデバイスを特定し、警告に関連する証拠を収集する必要があります。このソリューションは、収集した結果を使用して、影響を受けたデバイスの隔離を開始できることを保証する必要があります。
Microsoft 365 Defender ポータルでは何を使用すべきですか?
正解:B
In Microsoft Defender for Endpoint , an Investigation (also known as an Automated Investigation and Response - AIR ) collects evidence related to alerts, analyzes device behavior, and enables response actions such as device isolation, file quarantine, or remediation .
While Incidents aggregate multiple alerts for a single attack chain, and Advanced hunting is used for custom KQL queries, Investigations are specifically designed to automate evidence collection and analysis for triggered malware alerts.
From the investigation results, analysts can then initiate isolation of affected endpoints directly in the portal.
# Answer: B. Investigations