Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

A Microsoft 365 tenant uses a custom domain named fabrikam.com for all user principal names and email addresses. The security team requires that any email message sent from an external sender that spoofs fabrikam.com be rejected outright, while legitimate messages from the on-premises mail relay must still be accepted. You configure DKIM signing and SPF with a hard fail. What should you configure next to meet the rejection requirement?

⚠ Common exam trap

The trap here is believing that an SPF hard fail by itself rejects spoofed mail, when receivers only enforce rejection if a DMARC policy of p=reject is published.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a DMARC TXT record with p=reject and add the on-premises relay to the SPF record's include list.

Enforcing rejection of spoofed fabrikam.com mail requires a DMARC record with p=reject, because DMARC is the only mechanism that tells receivers to refuse messages failing SPF and DKIM alignment. Legitimate on-premises relay traffic must still authenticate, so the relay's sending infrastructure belongs in the SPF record. Quarantine softens the action, duplicate SPF records are invalid, and transport rules cannot influence external receivers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a DMARC TXT record with p=quarantine and rely on the existing SPF hard fail to block spoofed messages.

    Why it's wrong here

    A quarantine policy directs receivers to treat failing messages as suspicious rather than reject them, so spoofed mail may still land in junk folders instead of being refused. The requirement explicitly calls for outright rejection, and SPF hard fail alone does not enforce rejection at the receiver when DMARC is set to quarantine.

  • ✓

    Create a DMARC TXT record with p=reject and add the on-premises relay to the SPF record's include list.

    Why this is correct

    A DMARC policy of p=reject instructs receiving systems to reject messages that fail both SPF and DKIM alignment for fabrikam.com, which stops external spoofing. Including the on-premises relay in SPF ensures its legitimate messages pass authentication, so they are not caught by the reject policy, satisfying both halves of the requirement.

  • ✗

    Add a second SPF record for fabrikam.com that lists only the on-premises relay's public IP address.

    Why it's wrong here

    Publishing multiple SPF TXT records for one domain is invalid per RFC 7208 and causes a permanent SPF error at receivers, which can break delivery of legitimate mail. It also does nothing to enforce rejection of spoofed messages, since SPF by itself is advisory and receivers decide how to treat failures.

  • ✗

    Configure an Exchange Online transport rule that rejects messages where the sender's domain is fabrikam.com and the message originates outside the organization.

    Why it's wrong here

    Transport rules evaluate mail after it reaches Exchange Online and cannot stop messages sent directly to external recipients or other tenants, so spoofing to third parties continues. The requirement is to stop spoofed fabrikam.com mail globally, which requires a DNS-based authentication policy rather than an internal mail flow rule.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.