exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 306 discussion

Actual exam question from Microsoft's MS-102
Question #: 306
Topic #: 1
[All MS-102 Questions]

You have a Microsoft 365 subscription that uses Microsoft Defender XDR.

From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi – require approval for non-temp folders for the endpoints.

You need to identify the impact of the Automation level setting on the endpoints.

Which two actions will occur based on the remediation settings? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

  • A. Devices will be remediated only after end-user approval.
  • B. Devices will be remediated automatically if a threat is detected in the \program files (X86)\* folder
  • C. Devices will be remediated automatically if a threat is detected in the \windows\ folder.
  • D. Devices will be remediated automatically if a threat is detected in the \users\*\downloads\* folder.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ody
Highly Voted 5 months, 1 week ago
Correct answer is given: B and D. Go here to view how they define "temporary" https://learn.microsoft.com/en-us/defender-endpoint/automation-levels#levels-of-automation
upvoted 10 times
004b54b
1 week, 3 days ago
Link provided by Ody proves that answer is B + D
upvoted 1 times
...
BigO76
3 months, 2 weeks ago
B. Devices will be remediated automatically if a threat is detected in the \program files (X86)* folder. The \program files (X86)\* folder is classified as a temporary folder under the automation level definitions. This means threats detected in this folder are remediated automatically without requiring approval. D. Devices will be remediated automatically if a threat is detected in the \users*\downloads* folder. The \users\*\downloads\* folder is also classified as a temporary folder, so threats in this location are remediated automatically. C. is the \windows\ directory is not classified as a temporary folder, but its subdirectory \windows\temp\* is. Since the question specifically references \windows\, it would require approval under the "Semi – require approval for non-temp folders" setting.
upvoted 5 times
...
...
004b54b
Most Recent 1 week, 3 days ago
Selected Answer: BD
Link provided by Ody proves that answer is B + D
upvoted 1 times
...
wafferrr
2 months ago
Selected Answer: AC
\Windows\* is not a temp folder but rather a core folder...Core is covered in "Semi - require approval for core folders remediation", which was not selected in this question.
upvoted 1 times
...
kaspen
3 months, 3 weeks ago
Selected Answer: AD
Devices will be remediated only after end-user approval for non-temporary folders such as the \program files (X86)\* and \windows\ folders. This aligns with the need for manual approval for actions in non-temporary folders to prevent unintended disruptions. Devices will be remediated automatically if a threat is detected in the \users\\downloads\ folder**. The Downloads folder is typically considered a temporary location, and automatic remediation can be applied without requiring manual approval. Correct Answers: A. D.
upvoted 4 times
justITtopics
2 months, 3 weeks ago
No, because "\program files (x86)\*" is considered as temporary folder (which is very confusing in this case), so the remediations in this folder will be automatic, without end-user approval. "\windows\*" is a core folder and "\windows\temp\*" temporary.
upvoted 1 times
...
...
HelloItsSam
6 months ago
Seems correct https://learn.microsoft.com/en-us/defender-endpoint/automation-levels
upvoted 2 times
justITtopics
5 months, 2 weeks ago
That seems correct but in the link you provided says: With this level of semi-automation, approval is required for any remediation actions needed on files or executables that aren't* in temporary folders. Remediation actions can be taken AUTOMATICALLY on files or executables that are in temporary folders. Pending actions for files or executables that aren't in temporary folders can be viewed and APPROVED in the Action Center, on the Pending tab. So I think there is a leak of a right option here and the only correct one would be the A. Devices are remediated only after end-user approval. B. is an automatic remediation for non-temp folder C: is a core folder D. is an automatic remediation for non-temp folder
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago