nerdexam
Microsoft

MS-102 · Question #311

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi - require approval for non-temp…

The correct answer is B. Devices will be remediated automatically if a threat is detected in the \program files (X86)\* folder D. Devices will be remediated automatically if a threat is detected in the \users\*\downloads\* folder. With the "Semi - require approval for non-temp folders" automation level, Microsoft Defender XDR automatically remediates threats found in common application and download directories, while requiring approval for more critical system files.

Submitted by katya_ua· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi - require approval for non-temp folders for the endpoints. You need to identify the impact of the Automation level setting on the endpoints. Which two actions will occur based on the remediation settings? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • ADevices will be remediated only after end-user approval.
  • BDevices will be remediated automatically if a threat is detected in the \program files (X86)* folder
  • CDevices will be remediated automatically if a threat is detected in the \windows\ folder.
  • DDevices will be remediated automatically if a threat is detected in the \users*\downloads* folder.

How the community answered

(24 responses)
  • A
    17% (4)
  • B
    75% (18)
  • C
    8% (2)

Why each option

With the "Semi - require approval for non-temp folders" automation level, Microsoft Defender XDR automatically remediates threats found in common application and download directories, while requiring approval for more critical system files.

ADevices will be remediated only after end-user approval.

The setting "Semi - require approval for non-temp folders" does not imply end-user approval, but rather approval by security administrators via the Microsoft Defender portal.

BDevices will be remediated automatically if a threat is detected in the \program files (X86)\* folderCorrect

Under the "Semi - require approval for non-temp folders" automation level, files located in commonly infected areas like \program files (X86)\* are often configured for automatic remediation, as they are not typically considered part of the most critical system files that require explicit approval.

CDevices will be remediated automatically if a threat is detected in the \windows\ folder.

The \windows\ folder contains critical operating system files; under the "Semi - require approval for non-temp folders" setting, remediation actions affecting these core system files would typically require administrative approval, not automatic remediation.

DDevices will be remediated automatically if a threat is detected in the \users\*\downloads\* folder.Correct

Similarly, files detected in \users\*\downloads\* are also typically subject to automatic remediation under this policy setting, as the downloads folder is a frequent entry point for malware and files within it are less critical than core operating system components.

Concept tested: Defender for Endpoint automation levels

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-automation-remediation?view=o365-worldwide#automation-levels

Topics

#Microsoft Defender XDR#Endpoint Security#Automatic Remediation#Automation Levels

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice