問題文
The platform watches the change rate of the protected data and the volume of snapshots that differ from their predecessors, and raises an alert when a protection run falls outside the usual range. Why is that measure useful for spotting an encryption attack?
選択肢
- Encrypting files in place rewrites them, so the amount that a run reports as changed rises far above the pattern that the same workload has produced day after day.
- Encrypting files in place delays them, so the time that a run needs stretches far beyond the window that the same workload has fitted into day after day.
- Encrypting files in place renames them, so the number of objects which a run reports drops far below the count that the same workload has produced day after day.
- Encrypting files in place compresses them, so the size that a run stores falls far below the volume that the same workload has produced day after day.