A security engineer is configuring Microsoft Defender for Endpoint for a set of critical servers that host sensitive data. Due to the extreme sensitivity of these servers, any potential threat must be immediately contained, but manual approval is required before any destructive actions (like quarantining files or blocking processes) are taken. Which Automated Investigation and Remediation (AIR) automation level should be configured for these servers?
- AFull - remediate threats automatically
- BPartial - require approval for all remediation actions
- CNo automated response
- DSemi-Full - require approval for remediation
Show answer & explanationAnswer & explanation
Correct answer: D. Semi-Full - require approval for remediation
The 'Semi-Full' automation level in AIR allows investigations to run automatically and gather evidence, but it requires explicit approval from a security analyst before any remediation actions, such as quarantining files or blocking processes, are performed. This matches the requirement for immediate containment (investigation) but manual approval for destructive actions.
Why the other options are wrong
- A. Full automation would perform destructive actions without approval, which is not desired.
- B. Partial automation is not a standard AIR level; the closest is 'Semi-Full'.
- C. No automated response would mean no immediate investigation or containment, which contradicts the need for immediate potential threat handling.
AIR Automation Level: Semi-Full
An Automated Investigation and Remediation (AIR) level in Microsoft Defender for Endpoint where investigations run automatically, but all proposed remediation actions require explicit approval from a security analyst.
- Automates investigation.
- Requires approval for remediation actions.
- Balances speed with human oversight.
Memory trick: Semi-Full automation is like a robot that investigates everything but asks 'Permission to proceed?' before taking action.