Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A user receives an email from an unknown sender with a .zip attachment. The attachment contains a potentially malicious executable file. Microsoft Defender for Office 365 is enabled. Which feature dynamically detonates the attachment in a sandbox environment and blocks it if malicious behavior is detected?

⚠ Common exam trap

Many candidates confuse Safe Attachments with Safe Links, assuming both handle attachments, but Safe Links only rewrites and checks URLs, not file payloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Safe Attachments

Safe Attachments is the correct feature because it specifically detonates email attachments in a dynamic sandbox environment, analyzing behavior in real time. If the .zip file contains a malicious executable, Safe Attachments will block the email before delivery, preventing the user from accessing the threat. This is distinct from other Defender for Office 365 features that focus on URLs, phishing content, or spam filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Safe Attachments

    Why this is correct

    Safe Attachments is the correct answer because it uses behavioral analysis, machine learning, and sandbox detonation to inspect email attachments such as a zip file. When a message contains a zip, Safe Attachments extracts the archive and detonates its contents in a controlled, isolated environment, monitoring for malicious actions like process injection, file writes, or network calls. This catches zero-day and polymorphic malware that signature-based scanners miss, and the email is held until analysis completes.

  • Safe Links

    Why it's wrong here

    Safe Links is incorrect because it protects users by scanning and rewriting malicious URLs in email messages, Office documents, and other supported locations, but it does not inspect the binary content of attached files. Even though a zip attachment could contain a URL-based payload like an .html or .lnk file, Safe Links only evaluates live links during click time, not the attachment itself in this context. The threat vector here is the attachment payload, not an embedded hyperlink in the message body, so Safe Links would not block it.

  • Anti-phishing

    Why it's wrong here

    Anti-phishing is incorrect because its core function is to detect impersonation, spoofing, and social-engineering patterns such as lookalike domains or fraudulent senders, not to scan attached files. It analyzes the message envelope, sender reputation, and header indicators like SPF, DKIM, and DMARC, and applies mailbox intelligence to identify phishing threats. A zip attachment containing malware may be delivered by a non-phishing email, and anti-phishing policies lack the sandboxing or content extraction needed to detonate and analyze the attachment's payload.

  • Anti-spam

    Why it's wrong here

    Anti-spam is incorrect because it filters unwanted bulk email by evaluating the message's metadata, content heuristics, and reputation scores, but it does not dissect or execute attached files. It classifies messages as spam, high-confidence spam, or bulk mail using allow/block lists and content filtering, yet a zip file with malware can arrive in an otherwise cleanly-scored message. Attachment-level threat detection requires Safe Attachments' sandboxing and behavioral analysis, which is beyond the scope of anti-spam policy enforcement.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.