Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are configuring Microsoft Defender for Office 365 anti-phish policy. You want to protect against user impersonation attacks. The CEO and CFO are frequent targets. What should you configure in the anti-phish policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable user impersonation protection and add the CEO and CFO as protected users

User impersonation protection in anti-phish policies allows you to add specific users (e.g., CEO and CFO) as protected users. This protects against attacks where an attacker impersonates those users. Option A is incorrect because spoof intelligence protects against domain spoofing, not user impersonation. Option B is incorrect because domain impersonation protects against impersonation of entire domains, not individual users. Option D is incorrect because mailbox intelligence is a feature that learns user communication patterns to detect impersonation, but it is not the configuration to protect specific users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure spoof intelligence

    Why it's wrong here

    Spoof intelligence handles forged sender addresses from domains you don't own, not impersonation of named executives. It is tempting because it addresses phishing, but the CEO/CFO targets require the impersonation settings for protected users, where their names are matched in the From display name.

  • ✗

    Add the CEO and CFO's domains to domain impersonation

    Why it's wrong here

    Domain impersonation protects against senders using a lookalike of your own domain, not the executives' personal display names. It is tempting because it is an impersonation control, but the CEO/CFO targets require the user impersonation setting, where their individual names are listed for protection.

  • ✓

    Enable user impersonation protection and add the CEO and CFO as protected users

    Why this is correct

    User impersonation protection compares the sender's display name and address against a defined list, so adding the CEO and CFO as protected users blocks spoofed messages impersonating those executives, directly meeting the stated targeting of frequent executive targets.

  • ✗

    Enable mailbox intelligence

    Why it's wrong here

    Mailbox intelligence builds sender behavioural profiles to flag anomalous senders, not to protect specific named executives from display-name impersonation. It is tempting because it also targets phishing, but the CEO/CFO requirement needs their names added to the protected users list for impersonation detection.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.