MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Which TWO features in Microsoft Defender for Office 365 help protect against zero-day malware in email attachments?
⚠ Common exam trap
A common mix-up: candidates confuse Zero-hour auto purge (ZAP) as a proactive protection feature, when it is actually a reactive remediation tool that acts on already-delivered messages, not a prevention mechanism for zero-day malware in attachments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Attachments
Safe Attachments (Option A) is correct because it uses a detonation chamber environment to open email attachments in a virtualized sandbox, analyzing behavior for zero-day malware before delivery. This process catches unknown threats by executing the attachment and observing malicious actions, unlike signature-based detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Safe Attachments
Why this is correct
Safe Attachments routes email attachments to a hypervisor-isolated detonation chamber where files are opened and executed in a virtual environment to observe behavioral indicators. The resulting signals, combined with global threat intelligence, identify zero-day malware and trigger actions such as blocking, replacing, or alerting before delivery to the user.
- ✗
Mail flow rules
Why it's wrong here
Mail flow rules (also called transport rules) are conditional message hygiene policies that apply actions based on headers, senders, recipients, keywords, or attachment metadata. They do not detonate files or use behavioral analysis to identify never-before-seen malware, so they cannot catch zero-day threats unless a known indicator like a sender address or subject phrase is already in a block list.
- ✗
Anti-spam policies
Why it's wrong here
Anti-spam policies are designed to classify messages as spam, bulk email, or phishing by using sender reputation, content filtering, and allow/block lists, then route them to the Junk Email folder or quarantine. Their primary function is reducing inbox noise rather than inspecting attachment payload behavior, so a zero-day malicious file hidden in a clean-looking email would bypass this protection entirely.
- ✗
Anti-phishing policies
Why it's wrong here
Anti-phishing policies focus on impersonation protection, spoof intelligence, and mailbox intelligence to detect deceptive senders and domains attempting to steal credentials. While they may integrate with Safe Links for URL protection, they do not execute or analyze attachments, and therefore cannot identify a zero-day malware payload embedded in an otherwise convincing message.
- ✓
Zero-hour auto purge (ZAP)
Why this is correct
Zero-hour auto purge (ZAP) reacts to updated threat intelligence by retroactively locating messages that were already delivered to mailboxes and applying an action such as soft-delete or quarantine to neutralize the attack. This is crucial for zero-day defense because detection can lag delivery; once the attachment or URL is re-scored as malicious, ZAP contains the incident without requiring end-user action or manual cleanup.
Go deeper
Related to this question
Learn chapter
Attack Simulation Training in Defender
Key term
Safe Attachments
Safe Attachments is a Microsoft Defender for Office 365 feature that opens email attachments in a virtual sandbox to detect and block malicious content before they reach your inbox.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.