What's changed: Created SC-200 Chapter 1 (Domain 1 first-half: Defender XDR notifications/alert tuning (suppression)/correlation; Defender for Endpoint (advanced features/custom data collection/ASR rules/device groups/permissions/automation levels); AIR (automated investigation and response)/Action center/automatic attack disruption; Sentinel automation rules (declarative triage)/playbooks (Logic Apps, SOAR)).
1.3Automated investigation/response and automatic attack disruption
Understand managing automated investigation and response (AIR) in Microsoft Defender XDR and configuring automatic attack disruption.
Humans alone cannot match attack speed. Defender XDR automates investigation and containment, freeing analysts for judgment. This section covers AIR and automatic attack disruption that halts in-progress attacks instantly.
1.3.1Automated investigation and response (AIR)
Automated investigation and response (AIR) auto-runs an investigation triggered by an alert, identifies affected entities, and proposes/executes remediation actions (quarantine files, stop processes, etc.). The automation level (previous section) decides whether remediation is auto-approved or awaits approval (pending actions). Analysts approve/reject pending remediations in the Action center and review AIR results.
1.3.2Automatic attack disruption
Automatic attack disruption auto-executes containment the instant it detects a high-confidence in-progress attack (ransomware, BEC, etc.)—isolating compromised devices, disabling compromised user accounts, etc. XDR’s cross-domain signals provide high confidence, so it limits blast radius without waiting for human approval. Analysts then investigate and take additional manual action if needed.
Cues: "auto-investigate from an alert, propose/execute remediation; approve pending in Action center" = AIR. "instantly auto-contain a high-confidence in-progress attack (isolate device/disable account)" = automatic attack disruption. Auto vs await-approval is controlled by the automation level.
Watch the mix-ups: (1) AIR (alert-triggered auto-investigation/remediation) differs from automatic attack disruption (instant containment of a high-confidence in-progress attack). (2) Approve/reject pending remediations in the Action center. (3) Disruption relies on XDR cross-domain signals—single-product confidence is insufficient.
1.3.3Section summary
- AIR = auto-investigate from an alert, propose/execute remediation; approve pending in Action center; auto vs await per automation level
- Automatic attack disruption = instantly auto-contain a high-confidence in-progress attack (isolate device/disable account)
- Disruption uses XDR cross-domain signals for high confidence to limit blast radius
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Ransomware is in progress; based on high-confidence detection you want to instantly stop spread (auto-isolate device, disable account). Which is best?
Q2. An alert triggered an auto-investigation that identified affected entities and proposed remediation, now pending because it is a critical server. Where do you approve it?
Q3. What determines whether remediation is auto-approved or waits for human approval?
Q4. Which correctly distinguishes AIR from automatic attack disruption?
Q5. What justifies automatic attack disruption acting without waiting for human approval?

