Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Match each Microsoft 365 threat scenario to the appropriate protection.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Anti-phishing policy in Defender for Office 365

Safe Attachments policy

Safe Links policy

Identity Protection and Conditional Access

Data Loss Prevention policy

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing email with malicious link: Microsoft Defender for Office 365 Safe Links

Correct matches: Phishing links → Safe Links; Malware attachments → Safe Attachments; Data leaks → DLP; Ransomware → Anti-ransomware policies. Common mistakes include confusing Safe Links with Safe Attachments and DLP with Defender protections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing email with malicious link: Microsoft Defender for Office 365 Safe Links

    Why this is correct

    Safe Links is Microsoft Defender for Office 365's time-of-click URL protection feature. When a user clicks a link in email or an Office document, Safe Links rewrites and checks the URL against Microsoft's threat intelligence at click time, blocking or warning if it leads to a malicious site. This makes it the correct control for phishing emails that carry malicious links rather than malicious attachments.

  • Malicious attachment in email: Microsoft Defender for Office 365 Safe Attachments

    Why this is correct

    Safe Attachments protects against malware embedded as email attachments by routing them through a detonation sandbox environment. Each attachment is opened and analyzed with machine learning, behavioral detection, and other reputation checks to catch zero-day malware, and attachments with malicious behavior are blocked or replaced with a warning placeholder. It does not perform URL reputation checks on links inside the message body, so it is not suited for link-centric phishing.

  • Accidental data leak via email: Microsoft Purview Data Loss Prevention

    Why this is correct

    Microsoft Purview Data Loss Prevention applies policies defined from sensitive information types such as credit card numbers, PII, or HR data to outbound and internal email. When a user accidentally sends such data, the DLP engine inspects both the header and body, analyzes context, and can block the message, send a policy tip, or apply encryption, depending on the rule. This is the correct mechanism because the scenario is accidental sensitive data disclosure, not malware or malicious URL detection.

  • Ransomware on SharePoint file: Microsoft Defender for Office 365 Anti-ransomware policies

    Why this is correct

    Anti-ransomware policies in Defender for Office 365 detect behavior like mass file modifications, encryption patterns, and suspicious file-extension changes in SharePoint Online and OneDrive for Business. When triggered, the policy raises high-confidence alerts and enables file recovery and proactive investigation, helping contain ransomware that has reached cloud-stored documents. This is the right mapping because it is a file-level threat on SharePoint, not an email-delivered attack.

  • Phishing email with malicious link: Microsoft Defender for Office 365 Safe Attachments

    Why it's wrong here

    Safe Attachments is designed to detonate attachment payloads, such as executables or macro-enabled documents, in an isolated sandbox to catch malware before it reaches the inbox. A phishing email with just a malicious link contains no attachment payload for the sandbox to analyze, and the danger occurs when the user clicks the URL. Therefore, using Safe Attachments would not protect against the link, which is why Safe Links is the correct service.

  • Accidental data leak via email: Microsoft Defender for Office 365 Safe Links

    Why it's wrong here

    Safe Links is a URL reputation and time-of-click scanning service, so it has no awareness of the data classification or sensitivity of the message's content. An accidental data leak is a policy-driven governance problem where the risk is sensitive content leaving the organization, not a malicious destination or potential malware. Only Purview DLP can apply sensitive-information-type rules and remediation actions like blocking or encrypting the message, which is why Safe Links does not address this scenario.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.