Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security engineer is configuring Microsoft Defender for Endpoint for a critical server farm. Due to the sensitive nature of the applications running on these servers, any potential false positive from automated remediation could cause significant operational disruption. The engineer wants to ensure that while threats are detected and investigated automatically, any remediation actions explicitly require approval from the security team before being applied. Which automation level for automated investigation and remediation (AIR) should be set for these servers?
- ASemi-full - require approval for all remediation
- BSemi-full - require approval for high severity remediation
- CFull - remediate threats automatically
- DNo automated remediation
Show answer & explanationAnswer & explanation
Correct answer: A. Semi-full - require approval for all remediation
The 'Semi-full - require approval for all remediation' automation level in Defender for Endpoint's AIR ensures that all detected threats are automatically investigated, but any proposed remediation actions will be paused and require explicit approval from a security analyst before being executed. This balances automated investigation with manual oversight for critical systems.
Why the other options are wrong
- B. Semi-full with approval for high severity remediation would still automatically remediate lower severity threats, which is not what's desired for critical systems.
- C. Full automation remediates everything automatically, which is not suitable when manual approval is required.
- D. No automated remediation would prevent even the automated investigation, which is not what the question implies (it asks for investigation but manual approval of remediation).
AIR Automation Levels
Settings in Microsoft Defender for Endpoint that define how much human intervention is required for automated investigation and remediation actions.
- Ranges from 'No automated remediation' to 'Full - remediate threats automatically'.
- Semi-full levels allow for approval processes based on severity or for all actions.
- Impacts the speed of response versus the need for human oversight.
Memory trick: Automation levels are like a robot's leash: short, long, or off.