Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Which TWO features in Microsoft Defender for Office 365 help protect against zero-day malware in email attachments?

⚠ Common exam trap

A common mix-up: candidates confuse Zero-hour auto purge (ZAP) as a proactive protection feature, when it is actually a reactive remediation tool that acts on already-delivered messages, not a prevention mechanism for zero-day malware in attachments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Safe Attachments

Safe Attachments (Option A) is correct because it uses a detonation chamber environment to open email attachments in a virtualized sandbox, analyzing behavior for zero-day malware before delivery. This process catches unknown threats by executing the attachment and observing malicious actions, unlike signature-based detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Safe Attachments

    Why this is correct

    Safe Attachments routes email attachments to a hypervisor-isolated detonation chamber where files are opened and executed in a virtual environment to observe behavioral indicators. The resulting signals, combined with global threat intelligence, identify zero-day malware and trigger actions such as blocking, replacing, or alerting before delivery to the user.

  • ✗

    Mail flow rules

    Why it's wrong here

    Mail flow rules (also called transport rules) are conditional message hygiene policies that apply actions based on headers, senders, recipients, keywords, or attachment metadata. They do not detonate files or use behavioral analysis to identify never-before-seen malware, so they cannot catch zero-day threats unless a known indicator like a sender address or subject phrase is already in a block list.

  • ✗

    Anti-spam policies

    Why it's wrong here

    Anti-spam policies are designed to classify messages as spam, bulk email, or phishing by using sender reputation, content filtering, and allow/block lists, then route them to the Junk Email folder or quarantine. Their primary function is reducing inbox noise rather than inspecting attachment payload behavior, so a zero-day malicious file hidden in a clean-looking email would bypass this protection entirely.

  • ✗

    Anti-phishing policies

    Why it's wrong here

    Anti-phishing policies focus on impersonation protection, spoof intelligence, and mailbox intelligence to detect deceptive senders and domains attempting to steal credentials. While they may integrate with Safe Links for URL protection, they do not execute or analyze attachments, and therefore cannot identify a zero-day malware payload embedded in an otherwise convincing message.

  • ✓

    Zero-hour auto purge (ZAP)

    Why this is correct

    Zero-hour auto purge (ZAP) reacts to updated threat intelligence by retroactively locating messages that were already delivered to mailboxes and applying an action such as soft-delete or quarantine to neutralize the attack. This is crucial for zero-day defense because detection can lag delivery; once the attachment or URL is re-scored as malicious, ZAP contains the incident without requiring end-user action or manual cleanup.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.