Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A security operations team wants to ensure that all endpoints within their organization are configured to automatically investigate and remediate security threats without requiring manual intervention for common incidents. Which Microsoft Defender for Endpoint capability should be explicitly enabled and configured to achieve this goal?

  1. AAutomated investigation and remediation
  2. BEndpoint Detection and Response (EDR)
  3. CAttack Surface Reduction Rules
  4. DVulnerability management
Show answer & explanation

Correct answer: A. Automated investigation and remediation

Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint is designed to automatically investigate alerts, apply remediation actions, and resolve detected threats without human intervention, aligning directly with the requirement.

Why the other options are wrong

  • B. EDR detects and alerts on threats but does not inherently perform automated remediation without AIR enabled.
  • C. Attack Surface Reduction Rules prevent exploits but do not perform automated investigation and remediation of detected threats.
  • D. Vulnerability management identifies and prioritizes software weaknesses, not automated threat response.

Automated Investigation and Remediation (AIR)

A capability within Microsoft Defender for Endpoint that automatically investigates alerts, applies remediation actions, and resolves security threats without requiring manual intervention.

  • Reduces alert fatigue for security teams.
  • Speeds up incident response.
  • Can be configured with various automation levels.

Memory trick: Auto-Investigate, Remediate, Resolve – AIR is your security robot.

More Mitigate threats using Microsoft Defender XDR questions