お客様は、Microsoft Defender XDR を使用する Microsoft 365 サブスクリプションをご利用中です。このサブスクリプションには、Microsoft Defender ウイルス対策を使用する Windows 11 デバイスが 100 台含まれています。これらのデバイスは、単一の Microsoft Defender for Endpoint デバイス グループに属しています。 デバイス上で潜在的に悪意のあるファイルをブロックできるように、「ファイルの許可」または「ファイルのブロック」オプションを使用する必要があります。 Microsoft Defender ポータルから、「ファイルの許可またはブロック」を「オン」に設定します。 次に何をすべきでしょうか?
正解:B
After enabling the Allow or block file setting in the Microsoft Defender portal, the next step to block potentially malicious files is to create file indicators for the specific file hashes you want to block. You can add these indicators by following these steps in the Microsoft Defender portal: Navigate to Indicators: Go to Settings > Endpoints > Indicators (under the Rules section). Add File Hashes: Select the File hashes tab and click Add item. Define the Indicator: Enter the file's hash (MD5, SHA1, or SHA256) and set the Action to Block execution or Block and remediate. Set the Scope: Choose the organizational scope. Since you have a single device group including all devices, you can apply the indicator to that specific group or the entire organization. Requirements for Blocking to Work: Active Mode: Microsoft Defender Antivirus must be running in Active mode on the devices. Cloud Protection: Cloud-delivered protection must be enabled to allow the endpoint to communicate with the service for real-time blocking. Reference: https://learn.microsoft.com/en-us/defender-endpoint/indicator-file