
Answer-first summary for fast verification
Answer: Disable Microsoft OneDrive sync and Exchange ActiveSync.
The correct answer is D: Disable Microsoft OneDrive sync and Exchange ActiveSync. According to Microsoft Security Best Practices, the first step in recovering from a ransomware attack is to prevent the spread of the ransomware. Disabling OneDrive sync and Exchange ActiveSync helps to protect your cloud data from being updated by potentially infected devices.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
Given your Microsoft 365 subscription that integrates with Active Directory Domain Services (AD DS), you face a scenario where ransomware has encrypted data within this subscription. Your objective is to outline the recovery process. Ensure that the recovery strategy aligns with Microsoft Security Best Practices. What should be the first step in your recovery plan?
A
From Microsoft Defender for Endpoint, perform a security scan.
B
Recover files to a cleaned computer or device.
C
Contact law enforcement.
D
Disable Microsoft OneDrive sync and Exchange ActiveSync.
No comments yet.