MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to ensure that when a user clicks a malicious link in an email, the URL is automatically blocked and the user is prevented from accessing the site. Which Microsoft Defender XDR component should you configure?
⚠ Common exam trap
The trap here is assuming that web content filtering or Conditional Access App Control can block email links, but they operate at different layers and do not scan email URLs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365 Safe Links policy
Safe Links in Microsoft Defender for Office 365 is specifically designed to protect users from malicious URLs in emails and documents by scanning and blocking access at click time. Configuring a Safe Links policy ensures that users are prevented from accessing malicious sites when they click links.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Endpoint web content filtering
Why it's wrong here
Web content filtering in Microsoft Defender for Endpoint blocks access to certain categories of websites based on content, but it does not scan URLs in emails for malicious intent. It operates at the device level and is not triggered by email link clicks, so it cannot automatically block malicious links from emails.
- ✗
Microsoft Defender for Cloud Apps conditional access app control
Why it's wrong here
Conditional Access App Control in Microsoft Defender for Cloud Apps monitors and controls access to cloud apps, but it does not specifically block malicious URLs in emails. It enforces policies on app usage, not on individual email links, so it does not fulfill the requirement.
- ✗
Microsoft Defender for Identity sign-in alerts
Why it's wrong here
Microsoft Defender for Identity monitors sign-in activities and detects suspicious authentication attempts, but it does not block URLs or prevent access to malicious sites. It is focused on identity-based threats, not email link protection, so it is not the appropriate component.
- ✓
Microsoft Defender for Office 365 Safe Links policy
Why this is correct
Safe Links in Microsoft Defender for Office 365 scans URLs in emails and documents, and blocks access to malicious sites at time of click. Configuring a Safe Links policy ensures that when a user clicks a malicious link, they are prevented from accessing the site, meeting the requirement.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Security Posture Improvement
Key term
Safe Links
Safe Links is a Microsoft Defender for Office 365 feature that scans URLs in emails and documents in real time to protect users from malicious websites.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.