MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are configuring Microsoft Defender for Office 365 anti-phish policy. You want to protect against user impersonation attacks. The CEO and CFO are frequent targets. What should you configure in the anti-phish policy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable user impersonation protection and add the CEO and CFO as protected users
User impersonation protection in anti-phish policies allows you to add specific users (e.g., CEO and CFO) as protected users. This protects against attacks where an attacker impersonates those users. Option A is incorrect because spoof intelligence protects against domain spoofing, not user impersonation. Option B is incorrect because domain impersonation protects against impersonation of entire domains, not individual users. Option D is incorrect because mailbox intelligence is a feature that learns user communication patterns to detect impersonation, but it is not the configuration to protect specific users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure spoof intelligence
Why it's wrong here
Spoof intelligence handles forged sender addresses from domains you don't own, not impersonation of named executives. It is tempting because it addresses phishing, but the CEO/CFO targets require the impersonation settings for protected users, where their names are matched in the From display name.
- ✗
Add the CEO and CFO's domains to domain impersonation
Why it's wrong here
Domain impersonation protects against senders using a lookalike of your own domain, not the executives' personal display names. It is tempting because it is an impersonation control, but the CEO/CFO targets require the user impersonation setting, where their individual names are listed for protection.
- ✓
Enable user impersonation protection and add the CEO and CFO as protected users
Why this is correct
User impersonation protection compares the sender's display name and address against a defined list, so adding the CEO and CFO as protected users blocks spoofed messages impersonating those executives, directly meeting the stated targeting of frequent executive targets.
- ✗
Enable mailbox intelligence
Why it's wrong here
Mailbox intelligence builds sender behavioural profiles to flag anomalous senders, not to protect specific named executives from display-name impersonation. It is tempting because it also targets phishing, but the CEO/CFO requirement needs their names added to the protected users list for impersonation detection.
Go deeper
Related to this question
Learn chapter
SharePoint External Sharing and Guest Policies
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.