MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator notices that users are receiving phishing emails that evade built-in anti-spam filters. The administrator wants to enable users to report these suspicious emails from Outlook and have them automatically trigger an investigation and block the sender. Which feature should be configured in Microsoft Defender for Office 365?
⚠ Common exam trap
It's easy for candidates to confuse user reporting features with attack simulation training or threat hunting tools, not realizing that the specific setting to enable automated investigation and blocking from user reports is found in the User reported settings within the Microsoft 365 Defender portal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User reported settings in the Microsoft 365 Defender portal
User reported settings in the Microsoft 365 Defender portal allow administrators to configure how user-reported messages are handled. When enabled, users can report suspicious emails directly from Outlook, and these reports can automatically trigger an investigation and block the sender via automated investigation and response (AIR) policies. This directly addresses the requirement to have user-reported emails initiate security actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attack simulation training
Why it's wrong here
Attack simulation training is fundamentally a phishing simulation and awareness platform that measures user susceptibility and then delivers targeted educational content, so it operates in the user-awareness domain rather than in the email ingestion or remediation pipeline. It does not inspect user-submitted messages, and its automation, such as scheduling simulated campaigns, never extracts a sender from a real user report or writes to tenant-level sender block lists. Consequently, it cannot block an attacker's sending infrastructure merely because users report the original emails.
- ✗
Threat Explorer
Why it's wrong here
Threat Explorer is a manual hunting and investigation tool in the Microsoft 365 Defender portal that provides real-time and historical visibility into email, content, and collaboration threats, letting analysts pivot across metadata and detonation outcomes. However, every remediation action, such as soft-delete or disabling a sender, is a manual decision; the product does not automatically ingest user report signals and convert them into policy changes. It shows the analyst what happened, but it cannot independently act on user submissions, so it does not meet the requirement for automated sender blocking.
- ✓
User reported settings in the Microsoft 365 Defender portal
Why this is correct
User reported settings in the Microsoft 365 Defender portal, found under Settings > Email & collaboration, are the native control plane that connects end-user report actions to backend automation. An admin can route reported messages to Microsoft for analysis, to a custom mailbox, or directly into automated investigation and response, and can enable the automatically block sender rule so that confirmed phishing verdicts instantly update the tenant block list. This is precisely the kind of correlated, report-initiated blocking that the other options lack, making it the correct choice for this scenario.
- ✗
Safe Links
Why it's wrong here
Safe Links is the URL protection component of Defender for Office 365 that rewrites and inspects hyperlinks in email and collaboration workloads at click time, checking against reputation data for path, domain, and file detonation. It never parses user-reported submissions and does not maintain or update sender-level allow/block lists, because its remediation is link-centric, not sender-centric. Thus, even if Safe Links blocks a malicious URL, the original attacker sender remains unaffected, so it cannot satisfy the requirement to block the sender based on user report.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.