Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security administrator is implementing Microsoft Defender for Endpoint on a set of critical servers. Due to the sensitive nature of these servers, they want to ensure that any potential threats are automatically remediated with minimal human intervention, but also with a high degree of confidence to prevent legitimate operations from being disrupted. Which Automated Investigation and Remediation (AIR) automation level should be configured for these servers?

  1. ASemi-full - require approval for critical actions
  2. BNo automated remediation
  3. CPartial - require approval for all actions
  4. DFull - remediate threats automatically
Show answer & explanation

Correct answer: A. Semi-full - require approval for critical actions

The 'Semi-full' automation level is suitable for critical assets. It allows AIR to automatically remediate less impactful threats but requires approval from a security operations team for critical actions like quarantining files or stopping processes, balancing automation with cautious oversight to prevent disruption to legitimate operations.

Why the other options are wrong

  • B. No automated remediation means human intervention for everything, defeating the purpose of automation for even minor threats.
  • C. Partial automation requires approval for all actions, which might delay remediation too much for certain threats.
  • D. Full automation might be too aggressive for critical servers, risking disruption of legitimate processes.

AIR Automation Level: Semi-full

A Microsoft Defender for Endpoint Automated Investigation and Remediation (AIR) level that allows automated remediation for less impactful threats but requires human approval for critical actions, balancing speed with careful oversight.

  • Automates low-impact remediation.
  • Requires approval for high-impact actions.
  • Ideal for critical systems needing a balance of automation and control.

Memory trick: Semi-full automation is like a smart assistant: it handles the easy stuff, but asks for your OK on big decisions.

More Mitigate threats using Microsoft Defender XDR questions