MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A company is experiencing a significant number of phishing attempts that target high-level executives by impersonating their email addresses. The security team wants to configure protection against user impersonation in Microsoft Defender for Office 365. Which setting must be enabled in the anti-phishing policy to protect these specific users?
⚠ Common exam trap
It's easy for candidates to confuse 'user impersonation protection' with 'domain impersonation protection' or 'spoof intelligence,' but the question specifically asks for protection against impersonation of individual users, which requires the user-based setting, not domain-level or spoof-based controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable users to protect against impersonation
The 'Enable users to protect against impersonation' setting in an anti-phishing policy allows you to specify a list of users (such as high-level executives) whose email identities will be monitored for impersonation attempts. When enabled, Defender for Office 365 analyzes inbound messages for display name and email address matches against the protected users, and if a match is found with a suspicious sender, the message is flagged or quarantined. This directly addresses the scenario of attackers spoofing executive email addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable users to protect against impersonation
Why this is correct
This setting allows you to define a list of specific users (e.g., executives) whose email addresses are protected from being impersonated in inbound emails. When impersonation is detected, the action defined in the policy is applied.
- ✗
Enable domains to protect against impersonation
Why it's wrong here
This setting protects an entire domain from being impersonated in the From header, but it does not flag a sender who simply mimics a specific executive's display name or email alias while using an unrelated domain. Impersonation of high-value individuals is usually based on the user identity (e.g., 'CEO Jane Doe') rather than the domain, so this option fails to catch attacks that target a named user. It also cannot be scoped to individual protected mailboxes, which is exactly what the scenario requires.
- ✗
Mailbox intelligence
Why it's wrong here
Mailbox intelligence leverages machine learning to baseline a user's normal email behavior and then flags anomalies such as unusual sending patterns or a compromised account sending bulk mail. It does not detect an external attacker spoofing a known user's display name or email address; instead, it focuses on behavioral deviations after the fact. This means it cannot proactively prevent impersonation attempts against specific executives before they reach the inbox.
- ✗
Spoofed sender posture
Why it's wrong here
Spoofed sender posture is part of spoof intelligence and evaluates the envelope and From domains against SPF, DKIM, and DMARC authentication results to identify senders who are unauthorized to use a domain. It addresses domain spoofing, not user impersonation, where the attacker may use a display name like 'Chief Financial Officer' while the underlying email address is a free webmail domain that passes authentication checks. Thus, it is ineffective for stopping attacks that rely on name-based deception.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.