Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security engineer is configuring Microsoft Defender for Endpoint for a critical production server. Due to the server's sensitive nature and the need for extreme stability, all automated remediation actions must be reviewed and approved by a human operator before being applied. The system should still automatically investigate threats. Which Automated Investigation and Remediation (AIR) automation level should be set for this server?

  1. ASemi-full
  2. BNo automation
  3. CFull
  4. DPassive
Show answer & explanation

Correct answer: A. Semi-full

The 'Semi-full' automation level for Automated Investigation and Remediation (AIR) allows Defender for Endpoint to automatically investigate threats but requires explicit approval from a security operations team member before any remediation actions, such as isolating a device or quarantining a file, are taken. This aligns with the requirement for human review for critical servers.

Why the other options are wrong

  • B. No automation means no automatic investigation or remediation, which doesn't meet the 'automatically investigate' requirement.
  • C. Full automation automatically investigates and remediates without human approval, which is too aggressive for a critical server.
  • D. Passive mode means the device is monitored but no investigation or remediation actions are taken automatically, similar to 'No automation' in terms of response.

AIR Automation Level: Semi-full

An Automated Investigation and Remediation (AIR) automation level in Microsoft Defender for Endpoint where the system automatically investigates detected threats but requires explicit approval from a security analyst before performing any remediation actions.

  • Provides automatic investigation without automatic remediation.
  • Requires human approval for all remediation actions.
  • Suitable for critical systems where human oversight is essential.

Memory trick: Semi-full: Investigate, then ask for permission.

More Mitigate threats using Microsoft Defender XDR questions