nerdexam
Microsoft

SC-100 · Question #135

Drag and Drop Question Your company wants to optimize ransomware incident investigations. You need to recommend a plan to investigate ransomware incidents based on the Microsoft Detection and Response

Sign in or unlock SC-100 to reveal the answer and full explanation for question #135. The question stem and answer options stay visible for context.

Design security operations, identity, and compliance capabilities

Question

Drag and Drop Question Your company wants to optimize ransomware incident investigations. You need to recommend a plan to investigate ransomware incidents based on the Microsoft Detection and Response Team (DART) approach. Which three actions should you recommend performing in sequence in the plan? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Answer:

Exhibits

SC-100 question #135 exhibit 1
SC-100 question #135 exhibit 2

Answer Area

Drag items

Identify which line-of-business (LOB) apps are unavailable due to a ransomware incident.Identify the compromise recovery process.Implement a comprehensive strategy to reduce the risk of privileged access compromise.Assess the current situation and identify the scope.Update organizational processes to manage major ransomware events and streamline outsourcing to avoid friction.

Unlock SC-100 to see the answer

You've previewed enough free SC-100 questions. Unlock SC-100 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Ransomware Incident Response#Microsoft DART#Security Operations#Incident Management
Full SC-100 Practice