Problem Statement
Which is a safe containment action for a ransomware incident during active encryption?
Explanation
The goal is to stop spread without causing extra damage. Network-isolating infected endpoints and disabling the account’s scheduled or interactive access reduces impact while keeping data available for forensics. Blind mass deletion or global changes can destroy evidence or break operations.
