MS-700 Manage Teams, Channels, Chats, and Apps Practice Question
You are a Teams administrator for Fabrikam. The security team requires that all files shared in Teams chats and channels are scanned for malware before users can download them. You need to ensure this scanning occurs without affecting user ability to upload files. What should you do?
⚠ Common exam trap
The trap here is assuming DLP or Conditional Access can scan for malware; they address data leakage and access control, not antivirus scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Safe Attachments in Microsoft Defender for Office 365 and apply a policy to SharePoint Online and OneDrive for Business.
Safe Attachments in Microsoft Defender for Office 365 is the correct solution because it provides malware scanning for files in SharePoint Online, OneDrive, and Microsoft Teams. By applying a Safe Attachments policy to these workloads, files are scanned asynchronously, and malicious files are blocked from download, ensuring security without hindering uploads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up a third-party antivirus integration in Teams admin center > Teams apps > Manage apps.
Why it's wrong here
Teams admin center does not provide a native antivirus integration for scanning files in chats and channels. Third-party apps may offer security features, but they do not automatically scan all shared files for malware before download. This approach is not the correct or supported method.
- ✗
Enable Conditional Access policy requiring compliant devices for Teams access.
Why it's wrong here
Conditional Access controls access based on device compliance, location, and user risk, but it does not scan files for malware. It ensures only compliant devices connect, but files could still contain malware. This does not meet the file scanning requirement.
- ✓
Enable Safe Attachments in Microsoft Defender for Office 365 and apply a policy to SharePoint Online and OneDrive for Business.
Why this is correct
Safe Attachments in Defender for Office 365 can scan files in SharePoint Online, OneDrive, and Teams. Configuring a policy for these workloads ensures files are scanned before download, meeting the security requirement without blocking uploads. This is the correct integrated solution.
- ✗
Configure a Data Loss Prevention (DLP) policy in Microsoft Purview to block files containing malware.
Why it's wrong here
DLP policies are designed to prevent sharing of sensitive information based on content, not to scan for malware. They do not perform antivirus scanning. While DLP can block files, it does not detect malware signatures, so it would not satisfy the requirement.
About these practice questions
This MS-700 question is part of Courseiva's 211-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-700 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-700 exam.