問題文
During onboarding a team completes the deployment that lets the platform read cloud events, and then asks whether anything else is needed before they can contain a compromised virtual machine from the portal. What should they be told?
選択肢
- Containment is only ever carried out by hand in the provider console, so no additional deployment exists for it and the portal simply records what the responder did.
- Nothing else is needed, because the same access that reads the events can also modify the resources that produced them.
- The Sensor must be installed on every workload in the account first, because containment is carried out from inside the machine and depends on an in-guest component being present and reporting before any action can be taken against the resource.
- A separate Wiz Remediation and Response deployment is required, because carrying out changes in the cloud environment needs permissions that the ingestion path deliberately does not hold.