MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator wants to ensure that all email attachments are scanned in a sandbox environment and blocked if malicious, with email delivery delayed until scanning completes. Which Microsoft 365 Defender policy should the administrator configure?
⚠ Common exam trap
Candidates often confuse Safe Attachments with Safe Links, assuming both handle attachments, but Safe Links only handles URLs, not file attachments, and the question explicitly requires sandbox scanning of attachments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Attachments policy
Safe Attachments policy is the correct choice because it provides sandbox scanning of email attachments. It can be configured to delay email delivery until scanning is complete, blocking malicious attachments. This directly meets the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Safe Links policy
Why it's wrong here
Safe Links protects against malicious URLs in email and Office documents, not attachments.
- ✓
Safe Attachments policy
Why this is correct
Safe Attachments scans email attachments in a virtual sandbox and blocks malicious ones, delaying delivery until analysis is complete.
- ✗
Anti-spam policy
Why it's wrong here
Anti-spam policy filters junk email based on content and sender reputation, not attachment scanning.
- ✗
Anti-phishing policy
Why it's wrong here
Anti-phishing policy protects against impersonation and spoofing, not attachment-based threats.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Defender policy
A Defender policy is a set of security rules configured in Microsoft 365 Defender that controls how endpoint detection and response (EDR), antivirus, firewall, and other protection features behave on managed devices.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.