問題文
An analyst picks up a new threat. Which order of steps gets to a defensible understanding fastest?
選択肢
- Read the threat summary, find the triggering event on the timeline, use the Investigation graph to see which assets are involved, then follow the main principal on the cloud events page.
- Carry out the containment actions first and investigate afterwards, since the investigation is easier once the environment has stopped changing.
- Open the Response Actions Catalog and read every action that applies to the resource types involved, so that the options are understood before the evidence is examined.
- Start from the cloud events page and read every record in the account for the period, so that nothing is missed before any conclusion is drawn.