Microsoft
SC-100 · Question #135
Drag and Drop Question Your company wants to optimize ransomware incident investigations. You need to recommend a plan to investigate ransomware incidents based on the Microsoft Detection and Response
Sign in or unlock SC-100 to reveal the answer and full explanation for question #135. The question stem and answer options stay visible for context.
Design security operations, identity, and compliance capabilities
Question
Drag and Drop Question Your company wants to optimize ransomware incident investigations. You need to recommend a plan to investigate ransomware incidents based on the Microsoft Detection and Response Team (DART) approach. Which three actions should you recommend performing in sequence in the plan? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Answer:
Exhibits
Answer Area
Drag items
Identify which line-of-business (LOB) apps are unavailable due to a ransomware incident.Identify the compromise recovery process.Implement a comprehensive strategy to reduce the risk of privileged access compromise.Assess the current situation and identify the scope.Update organizational processes to manage major ransomware events and streamline outsourcing to avoid friction.
Unlock SC-100 to see the answer
You've previewed enough free SC-100 questions. Unlock SC-100 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Ransomware Incident Response#Microsoft DART#Security Operations#Incident Management

