MS-102 · Question #311
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi - require approval for non-temp…
The correct answer is B. Devices will be remediated automatically if a threat is detected in the \program files (X86)\* folder D. Devices will be remediated automatically if a threat is detected in the \users\*\downloads\* folder. With the "Semi - require approval for non-temp folders" automation level, Microsoft Defender XDR automatically remediates threats found in common application and download directories, while requiring approval for more critical system files.
Question
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi - require approval for non-temp folders for the endpoints. You need to identify the impact of the Automation level setting on the endpoints. Which two actions will occur based on the remediation settings? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Options
- ADevices will be remediated only after end-user approval.
- BDevices will be remediated automatically if a threat is detected in the \program files (X86)* folder
- CDevices will be remediated automatically if a threat is detected in the \windows\ folder.
- DDevices will be remediated automatically if a threat is detected in the \users*\downloads* folder.
How the community answered
(24 responses)- A17% (4)
- B75% (18)
- C8% (2)
Why each option
With the "Semi - require approval for non-temp folders" automation level, Microsoft Defender XDR automatically remediates threats found in common application and download directories, while requiring approval for more critical system files.
The setting "Semi - require approval for non-temp folders" does not imply end-user approval, but rather approval by security administrators via the Microsoft Defender portal.
Under the "Semi - require approval for non-temp folders" automation level, files located in commonly infected areas like \program files (X86)\* are often configured for automatic remediation, as they are not typically considered part of the most critical system files that require explicit approval.
The \windows\ folder contains critical operating system files; under the "Semi - require approval for non-temp folders" setting, remediation actions affecting these core system files would typically require administrative approval, not automatic remediation.
Similarly, files detected in \users\*\downloads\* are also typically subject to automatic remediation under this policy setting, as the downloads folder is a frequent entry point for malware and files within it are less critical than core operating system components.
Concept tested: Defender for Endpoint automation levels
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-automation-remediation?view=o365-worldwide#automation-levels
Topics
Community Discussion
No community discussion yet for this question.