M365EXO-030: Malware emails quarantined or dropped (MS.EXO.10.2)
- Plataforma
- Entra ID / M365
- Categoría
- Advanced Threat Protection
- Severidad
- High
- Pilar de Zero Trust
- Applications & Workloads (peso 2)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
SCuBA MS.EXO.10.2 requires that emails identified as containing malware be quarantined or dropped. Detection alone is insufficient if the malicious message is still delivered. The anti-malware policy must take a removal action so users cannot interact with messages found to contain malware.
Valor recomendado
Anti-malware policy action quarantines or drops messages identified as malware (no deliver-with-warning action)
Remediación
Configure the anti-malware policy so messages identified as containing malware are quarantined or dropped rather than delivered. Verify no policy is set to deliver malware-positive messages with only a warning. Confirm administrator notifications are enabled so the security team is alerted on detections.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| empty | FAIL |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- NIST SP 800-53
- SI-3
- MITRE ATT&CK
- T1566.001