Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator is configuring Microsoft Defender for Office 365 to protect against zero-day malware in attachments. The administrator wants to use dynamic delivery so that users can view the email body while the attachment is being analyzed. However, the administrator is concerned about false positives and wants to ensure that if a benign attachment is later found to be malicious, it is removed from the user's inbox. What should the administrator configure?

⚠ Common exam trap

A common mix-up: candidates confuse Safe Attachments dynamic delivery with Safe Links URL detonation, or assume that anti-malware policies alone can retroactively remove malicious attachments, missing the critical ZAP integration for post-delivery remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a Safe Attachments policy with dynamic delivery and enable ZAP.

Safe Attachments policies with dynamic delivery allow users to view the email body while the attachment is being detonated in a sandbox. Zero-Hour Auto Purge (ZAP) then retroactively removes messages from the user’s inbox if a previously deemed benign attachment is later identified as malicious, addressing the false-positive concern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure a Safe Attachments policy with dynamic delivery and enable ZAP.

    Why this is correct

    A Safe Attachments policy with dynamic delivery exposes the attachment to Microsoft's sandbox detonation environment while the message is delivered to the user's mailbox; a placeholder is used until the verdict is clean and the real attachment becomes available. Enabling zero-hour auto purge (ZAP) adds retroactive remediation so that if the system later identifies the message as malicious, it is automatically removed from the mailbox. This combination fulfills the requirement for both low-latency attachment delivery and post-delivery protection.

  • ✗

    Configure a Safe Links policy with URL detonation.

    Why it's wrong here

    Safe Links policies operate on URLs contained in email messages and supported Office files; they do not detonate or scan binary attachment content. Even if an attachment contains a hyperlink, Safe Links rewrites and time-of-click checks that link, but the attachment file itself is never sandboxed or subjected to dynamic delivery. Therefore, this policy cannot satisfy a requirement that centers on attachment malware handling.

  • ✗

    Configure an anti-phishing policy with mailbox intelligence.

    Why it's wrong here

    Mailbox intelligence, configured in anti-phishing policies, uses user contact graphs and organizational hierarchies to detect impersonation attempts and anomalous sender patterns, not malware in message payloads. It can flag a suspicious sender or phishing lure, but it has no mechanism to open, detonate, or delay an attachment for security analysis. Because the stated requirement is about attachment handling, this policy is not applicable.

  • ✗

    Configure an anti-malware policy with common attachments filter.

    Why it's wrong here

    An anti-malware policy's common attachment filter blocks messages based on a predefined list of dangerous file extensions or names, such as .exe or .scr, before delivery. It is not a sandbox and has no dynamic delivery mode, so users cannot receive the email while the attachment is being analyzed. This static extension-based block may reduce risk but does not meet the need for detonation-based scanning and post-delivery zero-hour auto purge protection.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.