Drag or tap steps into the slots.
MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Drag and drop the steps to deploy Microsoft Defender for Office 365 policies in the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Create the policy, configure protection settings, specify recipients, enable the policy
Defender for Office 365 policies are created in the Defender portal, configured with threat protection settings, and applied to recipients.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create the policy, configure protection settings, specify recipients, enable the policy
Why this is correct
This is the correct order because you must first create the policy in the Defender portal, then configure its threat protection settings (e.g., anti-phishing, safe attachments), then specify which recipients (users, groups, domains) it applies to, and finally enable the policy to activate protection.
- ✗
Create the policy, specify recipients, configure protection settings, enable the policy
Why it's wrong here
This sequence misplaces the recipient assignment ahead of the protection configuration. In the Microsoft 365 Defender portal, the policy creation wizard requires you to finalize the threat protection actions (e.g., Safe Attachments quarantine policy, anti-phishing spoof and impersonation settings, threshold levels) before selecting the users, groups, or domains in the 'Applied to' step. Defining recipients first would tie an unconfigured protection profile to an audience, so the policy would not deliver the intended security controls when enabled.
- ✗
Configure protection settings, create the policy, specify recipients, enable the policy
Why it's wrong here
This order is impossible in the Defender portal because protection settings are not standalone objects—they are properties stored inside a specific policy, such as an anti-phishing or Safe Attachments policy. You must first create the policy container (via 'Create a policy' in Email & Collaboration > Policies & rules > Threat policies), and only then can you populate its actions, thresholds, and notification options. Attempting to configure settings before the policy exists has no target object to persist them to.
- ✗
Create the policy, enable the policy, configure protection settings, specify recipients
Why it's wrong here
Switching the policy to 'On' before defining protection settings and recipients makes the policy active but functionally empty—it has no Safe Links/Safe Attachments actions, no anti-phishing exemptions or impersonation policies, and no users assigned to it. In the Defender portal, the Enable toggle is part of the final review step, after you've completed the Protection settings and Applied to tabs. Enabling earlier can also interfere with audit and reporting because an enabled policy with no recipients is an invalid configuration that doesn't protect any mail flow.
Go deeper
Related to this question
Learn chapter
Anti-Spam and Anti-Malware Policies
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.