A security administrator is implementing Microsoft Defender for Endpoint on a set of critical servers. Due to the sensitive nature of these servers, they want to ensure that any potential threats are automatically remediated with minimal human intervention, but also with a high degree of confidence to prevent legitimate operations from being disrupted. Which Automated Investigation and Remediation (AIR) automation level should be configured for these servers?
- ASemi-full - require approval for critical actions
- BNo automated remediation
- CPartial - require approval for all actions
- DFull - remediate threats automatically
Show answer & explanationAnswer & explanation
Correct answer: A. Semi-full - require approval for critical actions
The 'Semi-full' automation level is suitable for critical assets. It allows AIR to automatically remediate less impactful threats but requires approval from a security operations team for critical actions like quarantining files or stopping processes, balancing automation with cautious oversight to prevent disruption to legitimate operations.
Why the other options are wrong
- B. No automated remediation means human intervention for everything, defeating the purpose of automation for even minor threats.
- C. Partial automation requires approval for all actions, which might delay remediation too much for certain threats.
- D. Full automation might be too aggressive for critical servers, risking disruption of legitimate processes.
AIR Automation Level: Semi-full
A Microsoft Defender for Endpoint Automated Investigation and Remediation (AIR) level that allows automated remediation for less impactful threats but requires human approval for critical actions, balancing speed with careful oversight.
- Automates low-impact remediation.
- Requires approval for high-impact actions.
- Ideal for critical systems needing a balance of automation and control.
Memory trick: Semi-full automation is like a smart assistant: it handles the easy stuff, but asks for your OK on big decisions.