Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Drag and drop the steps to deploy Microsoft Defender for Office 365 policies in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create the policy, configure protection settings, specify recipients, enable the policy

Defender for Office 365 policies are created in the Defender portal, configured with threat protection settings, and applied to recipients.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create the policy, configure protection settings, specify recipients, enable the policy

    Why this is correct

    This is the correct order because you must first create the policy in the Defender portal, then configure its threat protection settings (e.g., anti-phishing, safe attachments), then specify which recipients (users, groups, domains) it applies to, and finally enable the policy to activate protection.

  • ✗

    Create the policy, specify recipients, configure protection settings, enable the policy

    Why it's wrong here

    This sequence misplaces the recipient assignment ahead of the protection configuration. In the Microsoft 365 Defender portal, the policy creation wizard requires you to finalize the threat protection actions (e.g., Safe Attachments quarantine policy, anti-phishing spoof and impersonation settings, threshold levels) before selecting the users, groups, or domains in the 'Applied to' step. Defining recipients first would tie an unconfigured protection profile to an audience, so the policy would not deliver the intended security controls when enabled.

  • ✗

    Configure protection settings, create the policy, specify recipients, enable the policy

    Why it's wrong here

    This order is impossible in the Defender portal because protection settings are not standalone objects—they are properties stored inside a specific policy, such as an anti-phishing or Safe Attachments policy. You must first create the policy container (via 'Create a policy' in Email & Collaboration > Policies & rules > Threat policies), and only then can you populate its actions, thresholds, and notification options. Attempting to configure settings before the policy exists has no target object to persist them to.

  • ✗

    Create the policy, enable the policy, configure protection settings, specify recipients

    Why it's wrong here

    Switching the policy to 'On' before defining protection settings and recipients makes the policy active but functionally empty—it has no Safe Links/Safe Attachments actions, no anti-phishing exemptions or impersonation policies, and no users assigned to it. In the Defender portal, the Enable toggle is part of the final review step, after you've completed the Protection settings and Applied to tabs. Enabling earlier can also interfere with audit and reporting because an enabled policy with no recipients is an invalid configuration that doesn't protect any mail flow.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.