MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Which THREE settings can you configure in a Microsoft Defender for Office 365 anti-phish policy?
⚠ Common exam trap
The trap is conflating all Defender for Office 365 protections into one policy type; candidates must know that Safe Attachments and DKIM are configured elsewhere, not inside anti-phish policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mailbox intelligence
Mailbox intelligence (A) is a configurable setting in an anti-phish policy that uses a user's past communication patterns to detect impersonation attempts. User impersonation protection (D) is also configured in anti-phish policies, allowing you to protect specific internal or external senders from impersonation. Spoof intelligence (E) is a configurable setting in anti-phish policies that controls how the service handles senders who spoof domains you don't own. Safe Attachments (B) is a separate Defender for Office 365 policy (Safe Attachments policy), not a setting within an anti-phish policy. DKIM signing (C) is configured via DNS and Exchange Online mail flow settings, not within an anti-phish policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mailbox intelligence
Why this is correct
Mailbox intelligence is configurable within anti-phish policies, satisfying the requirement for a genuine anti-phishing setting. It uses each user's historical communication patterns and frequent contacts to distinguish legitimate senders from impersonators, strengthening spoof and impersonation detection. Unlike transport rules or DLP settings, it belongs specifically to the anti-phish policy configuration surface.
- ✗
Safe Attachments
Why it's wrong here
Safe Attachments is a separate Defender for Office 365 policy type, configured independently of anti-phish policies, so it is not a setting within them. It is tempting because it also defends against email threats, and would be the correct choice when configuring malware payload detonation rather than phishing thresholds.
- ✗
DKIM signing
Why it's wrong here
DKIM signing is configured through Exchange Online mail flow rules and DNS records, not within an anti-phish policy. It is tempting because it is an email authentication mechanism related to spoofing, and would be correct when publishing a selector record to cryptographically sign outbound mail.
- ✓
User impersonation protection
Why this is correct
User impersonation protection lets administrators list specific internal senders whose display names are frequently spoofed, so mail claiming to be from those executives is flagged or quarantined, satisfying the anti-phish policy requirement for targeted impersonation defence.
- ✓
Spoof intelligence
Why this is correct
Spoof intelligence is configurable within Microsoft Defender for Office 365 anti-phish policies, satisfying the requirement for settings available in that policy type. It controls how the service handles senders who spoof your domain, allowing you to review and manage allowed or blocked spoofed senders via the Tenant Allow/Block List.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Deployment via Intune
Key term
Exchange Online
Exchange Online is Microsoft's cloud-based email, calendar, and contact hosting service that is part of the Microsoft 365 suite, allowing organizations to manage corporate messaging without maintaining their own mail servers.
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are configuring Microsoft Defender for Office 365 anti-phish policy. You want to protect against user impersonation attacks. The CEO and CFO are frequent targets. What should you configure in the anti-phish policy?
hard- A.Configure spoof intelligence
- B.Add the CEO and CFO's domains to domain impersonation
- ✓ C.Enable user impersonation protection and add the CEO and CFO as protected users
- D.Enable mailbox intelligence
Why C: User impersonation protection in anti-phish policies allows you to add specific users (e.g., CEO and CFO) as protected users. This protects against attacks where an attacker impersonates those users. Option A is incorrect because spoof intelligence protects against domain spoofing, not user impersonation. Option B is incorrect because domain impersonation protects against impersonation of entire domains, not individual users. Option D is incorrect because mailbox intelligence is a feature that learns user communication patterns to detect impersonation, but it is not the configuration to protect specific users.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.