Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Which THREE settings can you configure in a Microsoft Defender for Office 365 anti-phish policy?

⚠ Common exam trap

The trap is conflating all Defender for Office 365 protections into one policy type; candidates must know that Safe Attachments and DKIM are configured elsewhere, not inside anti-phish policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mailbox intelligence

Mailbox intelligence (A) is a configurable setting in an anti-phish policy that uses a user's past communication patterns to detect impersonation attempts. User impersonation protection (D) is also configured in anti-phish policies, allowing you to protect specific internal or external senders from impersonation. Spoof intelligence (E) is a configurable setting in anti-phish policies that controls how the service handles senders who spoof domains you don't own. Safe Attachments (B) is a separate Defender for Office 365 policy (Safe Attachments policy), not a setting within an anti-phish policy. DKIM signing (C) is configured via DNS and Exchange Online mail flow settings, not within an anti-phish policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mailbox intelligence

    Why this is correct

    Mailbox intelligence is configurable within anti-phish policies, satisfying the requirement for a genuine anti-phishing setting. It uses each user's historical communication patterns and frequent contacts to distinguish legitimate senders from impersonators, strengthening spoof and impersonation detection. Unlike transport rules or DLP settings, it belongs specifically to the anti-phish policy configuration surface.

  • ✗

    Safe Attachments

    Why it's wrong here

    Safe Attachments is a separate Defender for Office 365 policy type, configured independently of anti-phish policies, so it is not a setting within them. It is tempting because it also defends against email threats, and would be the correct choice when configuring malware payload detonation rather than phishing thresholds.

  • ✗

    DKIM signing

    Why it's wrong here

    DKIM signing is configured through Exchange Online mail flow rules and DNS records, not within an anti-phish policy. It is tempting because it is an email authentication mechanism related to spoofing, and would be correct when publishing a selector record to cryptographically sign outbound mail.

  • ✓

    User impersonation protection

    Why this is correct

    User impersonation protection lets administrators list specific internal senders whose display names are frequently spoofed, so mail claiming to be from those executives is flagged or quarantined, satisfying the anti-phish policy requirement for targeted impersonation defence.

  • ✓

    Spoof intelligence

    Why this is correct

    Spoof intelligence is configurable within Microsoft Defender for Office 365 anti-phish policies, satisfying the requirement for settings available in that policy type. It controls how the service handles senders who spoof your domain, allowing you to review and manage allowed or blocked spoofed senders via the Tenant Allow/Block List.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are configuring Microsoft Defender for Office 365 anti-phish policy. You want to protect against user impersonation attacks. The CEO and CFO are frequent targets. What should you configure in the anti-phish policy?

hard
  • A.Configure spoof intelligence
  • B.Add the CEO and CFO's domains to domain impersonation
  • ✓ C.Enable user impersonation protection and add the CEO and CFO as protected users
  • D.Enable mailbox intelligence

Why C: User impersonation protection in anti-phish policies allows you to add specific users (e.g., CEO and CFO) as protected users. This protects against attacks where an attacker impersonates those users. Option A is incorrect because spoof intelligence protects against domain spoofing, not user impersonation. Option B is incorrect because domain impersonation protects against impersonation of entire domains, not individual users. Option D is incorrect because mailbox intelligence is a feature that learns user communication patterns to detect impersonation, but it is not the configuration to protect specific users.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.