MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
An administrator needs to configure the default anti-spam policy for all users in the Microsoft 365 Defender portal. Where should the administrator navigate to find these settings?
⚠ Common exam trap
Test-takers frequently confuse the Anti-spam policy with Anti-phishing or Anti-malware policies because all are under Threat policies, but each addresses a distinct security layer, and the question specifically asks for spam configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email & collaboration > Policies & rules > Threat policies > Anti-spam
The default anti-spam policy is configured under Email & collaboration > Policies & rules > Threat policies > Anti-spam in the Microsoft 365 Defender portal. This is the correct location because anti-spam settings, including the default policy that applies to all users, are managed specifically within the Anti-spam section of Threat policies. The other options address different threat protection areas (anti-phishing, anti-malware, Safe Attachments) that do not contain spam filtering configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Email & collaboration > Policies & rules > Threat policies > Anti-spam
Why this is correct
The Anti-spam section in the Microsoft 365 Defender portal (Email & collaboration > Policies & rules > Threat policies) is the proper location to manage the default anti-spam policy, which applies to all recipients. This is where you configure the spam filter policy (e.g., 'Default' policy), connection filter policy, and outbound spam filter settings, including bulk email thresholds, spam actions, and allow/block lists. It directly addresses unwanted bulk email and spam.
- ✗
Email & collaboration > Policies & rules > Threat policies > Anti-phishing
Why it's wrong here
Anti-phishing policies under the same Threat policies menu are designed to detect and mitigate phishing attacks, including user impersonation, domain impersonation, and spoofing intelligence. They do not provide controls for spam filtering, such as bulk mail thresholds or spam confidence level actions. While both protect email, phishing is a targeted social engineering attack, distinct from generic spam, so this is not the correct location.
- ✗
Email & collaboration > Policies & rules > Threat policies > Anti-malware
Why it's wrong here
Anti-malware policies are responsible for scanning email messages and attachments for known malicious software, including viruses, worms, and ransomware. These policies define malware filters and quarantine settings, but they do not handle spam classification or bulk email filtering. Since the task is to configure anti-spam settings, navigating here would not provide access to the default spam policy.
- ✗
Email & collaboration > Policies & rules > Threat policies > Safe Attachments
Why it's wrong here
Safe Attachments is a feature of Microsoft Defender for Office 365 that provides time-of-click attachment detonation in a sandbox environment to detect unknown malware. This policy type is unrelated to spam filtering; it is a protection layer for malicious content, not unsolicited bulk email. Configuring the default anti-spam policy requires going to the Anti-spam node instead.
Go deeper
Related to this question
Learn chapter
Safe Links and Safe Attachments Policies
Key term
Collaboration
Collaboration in Microsoft 365 refers to the integrated tools and services that enable people to work together in real time, share information, and coordinate tasks from anywhere.
Key term
Safe Attachments
Safe Attachments is a Microsoft Defender for Office 365 feature that opens email attachments in a virtual sandbox to detect and block malicious content before they reach your inbox.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.