MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are configuring Microsoft Defender for Office 365. Which TWO actions should you take to protect users from phishing attacks that use impersonation?
⚠ Common exam trap
MS-102 often tests the confusion between anti-spam, anti-phishing, and Safe Attachments features, leading candidates to select spam confidence level adjustments or DLP instead of the specific impersonation settings in anti-phishing policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure anti-phishing policies to protect users from impersonation of custom domains.
Anti-phishing policies in Microsoft Defender for Office 365 include impersonation settings that specifically protect against spoofing of custom domains the organization owns, using domain impersonation protection with actions like quarantining or moving messages to the Junk folder. Option D is also correct because the same anti-phishing policy provides user impersonation protection, which detects messages where the display name matches an internal user (such as executives or key staff) and applies the configured action. These two settings directly address phishing attacks that rely on impersonating trusted domains and internal users. Option A is not correct because DLP policies govern sensitive information sharing, not impersonation-based phishing. Option B is not correct because raising the spam confidence level (SCL) affects bulk/spam filtering, not impersonation detection. Option E is not correct because Safe Attachments for SharePoint, OneDrive, and Teams protects against malicious files in those workloads, not impersonation phishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a data loss prevention (DLP) policy to prevent sharing of credentials.
Why it's wrong here
DLP policies are designed to identify, monitor, and restrict sensitive data such as credit card numbers or personal data, not to analyze the sender's identity or intent. While a DLP rule could block outbound messages containing credential strings, it does not inspect SMTP headers for spoofed display names, lookalike domains, or known impersonators, so it cannot stop a domain-impersonation phishing attack.
- ✗
Configure anti-spam policies to increase the spam confidence level.
Why it's wrong here
Anti-spam policies determine whether a message is bulk/spam by assigning a spam confidence level based on content, reputation, and heuristics; increasing the SCL threshold merely changes what is classified as spam. This filtering has no awareness of display-name spoofing or lookalike custom domains, and it neither detects nor prevents impersonation-based phishing. Adjusting SCL can even cause legitimate mail to be quarantined while an impersonating message with innocuous content passes.
- ✓
Configure anti-phishing policies to protect users from impersonation of custom domains.
Why this is correct
In Defender for Office 365, an anti-phishing policy's impersonation settings let you specify custom domains to protect, and the service uses heuristics and machine learning to flag messages whose sending domain appears visually or logically similar to that protected domain. This mitigates attacks where an external sender uses a lookalike domain (e.g., typo-squatted or punycode variants) to trick users into thinking the mail originates from your organization. Because this is an identity-based detection, it is the correct policy category for the stated threat.
- ✓
Configure anti-phishing policies to protect users from impersonation of internal users.
Why this is correct
Anti-phishing policies also include mailbox intelligence and a 'users to protect' list that learns typical communication patterns and flags senders who impersonate specific internal individuals, such as executives or administrators. When an external message appears to use an internal user's display name or an altered variant of their email address, the policy can apply configured actions like redirecting the message or prepending a warning. This addresses the user-impersonation variant of the attack, which is distinct from protecting an entire domain.
- ✗
Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.
Why it's wrong here
Safe Attachments for SharePoint, OneDrive, and Microsoft Teams proactively detonates files in a virtual sandbox and blocks known malicious files after they are shared or uploaded. It operates on file content and binary behavior, not on message-level identity metadata such as the sender's display name, email envelope, or domain similarity. Since impersonation of a custom domain is a message-source problem, this malware-focused scanning cannot mitigate the described phishing threat.
Go deeper
Related to this question
Learn chapter
Teams Compliance: Recording and Archiving
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.