MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A company uses Microsoft Defender for Office 365. They want to ensure that users cannot ignore warning messages when clicking on a malicious link in an email. What should they configure?
⚠ Common exam trap
The trap is that 'warning messages' sounds like anti-phishing or Safe Attachments, but the specific control for preventing click-through is a Safe Links policy setting — candidates must know which policy owns URL click behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Safe Links policy with 'Do not allow users to click through to original URL' selected.
Safe Links policies include a setting 'Do not allow users to click through to the original URL' (or 'Block the following URLs' / 'Let users click through to the original URL' toggles). Selecting the option to prevent click-through ensures users cannot bypass the warning page and reach a malicious link. This is the direct control for the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the anti-phishing policy with 'Impersonation protection' enabled.
Why it's wrong here
Impersonation protection in Microsoft Defender for Office 365 anti-phishing policies detects spoofed sender domains or display names (e.g., CEO impersonation) and applies actions like quarantining or redirecting messages. However, it never intercepts, rewrites, or evaluates URLs contained in the email body; there is no overlap with link-click behavior or URL threat warnings. Since the company's requirement is specifically to stop users from bypassing link warnings, impersonation protection alone leaves the click-through capability fully intact, making it the wrong tool for this scenario.
- ✓
Configure a Safe Links policy with 'Do not allow users to click through to original URL' selected.
Why this is correct
A Safe Links policy with 'Do not allow users to click through to original URL' selected is the definitive control for stopping users from bypassing URL threat warnings. When a recipient clicks a link that Safe Links has evaluated as malicious or suspicious, Microsoft displays an interstitial warning page; this setting removes any 'proceed anyway' or 'continue to site' link, forcing a hard block. This directly addresses the stated requirement and is the only option among those listed that governs click-through behavior on links in email messages.
- ✗
Enable the 'Anti-malware' policy with 'Common attachments filter'.
Why it's wrong here
The Common Attachments Filter in an anti-malware policy blocks email attachments based on file type (e.g., .exe, .scr, .js) at the transport layer, preventing malware-laden files from reaching inboxes. It performs no URL scanning or rewriting and does not affect what happens when a recipient clicks a hyperlink embedded in the message body. This option is misaligned because the scenario is about link clicks, not attachment-borne malware, so it would leave the user's ability to bypass URL warnings completely unchanged.
- ✗
Configure a Safe Attachments policy with 'Block' action.
Why it's wrong here
A Safe Attachments policy with the 'Block' action routes messages that contain attachments to a virtual detonation environment and quarantines the message if the attachment is found malicious. This action is scoped strictly to attachments; it never extracts, rewrites, or manages URLs within the message body, nor does it generate a warning interface for links. Consequently, it cannot prevent users from clicking through to an original URL, because Safe Links is the only mechanism in Defender for Office 365 that controls user interaction with link warnings.
Go deeper
Related to this question
Learn chapter
Named Locations and Network-Based Policies
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Safe Links
Safe Links is a Microsoft Defender for Office 365 feature that scans URLs in emails and documents in real time to protect users from malicious websites.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.