MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are configuring Microsoft Defender for Office 365. Which TWO actions should you take to protect users from phishing attacks that use impersonation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure anti-phishing policies to protect users from impersonation of custom domains.
Options C and D are correct because anti-phishing policies can be configured to protect against impersonation of custom domains and internal users. Option A is wrong because DLP policies prevent sharing of sensitive data, not phishing. Option B is wrong because anti-spam policies handle spam, not impersonation. Option E is wrong because Safe Attachments scans files for malware, not phishing impersonation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a data loss prevention (DLP) policy to prevent sharing of credentials.
Why it's wrong here
DLP policies are designed to identify, monitor, and restrict sensitive data such as credit card numbers or personal data, not to analyze the sender's identity or intent. While a DLP rule could block outbound messages containing credential strings, it does not inspect SMTP headers for spoofed display names, lookalike domains, or known impersonators, so it cannot stop a domain-impersonation phishing attack.
- ✗
Configure anti-spam policies to increase the spam confidence level.
Why it's wrong here
Anti-spam policies determine whether a message is bulk/spam by assigning a spam confidence level based on content, reputation, and heuristics; increasing the SCL threshold merely changes what is classified as spam. This filtering has no awareness of display-name spoofing or lookalike custom domains, and it neither detects nor prevents impersonation-based phishing. Adjusting SCL can even cause legitimate mail to be quarantined while an impersonating message with innocuous content passes.
- ✓
Configure anti-phishing policies to protect users from impersonation of custom domains.
Why this is correct
In Defender for Office 365, an anti-phishing policy's impersonation settings let you specify custom domains to protect, and the service uses heuristics and machine learning to flag messages whose sending domain appears visually or logically similar to that protected domain. This mitigates attacks where an external sender uses a lookalike domain (e.g., typo-squatted or punycode variants) to trick users into thinking the mail originates from your organization. Because this is an identity-based detection, it is the correct policy category for the stated threat.
- ✓
Configure anti-phishing policies to protect users from impersonation of internal users.
Why this is correct
Anti-phishing policies also include mailbox intelligence and a 'users to protect' list that learns typical communication patterns and flags senders who impersonate specific internal individuals, such as executives or administrators. When an external message appears to use an internal user's display name or an altered variant of their email address, the policy can apply configured actions like redirecting the message or prepending a warning. This addresses the user-impersonation variant of the attack, which is distinct from protecting an entire domain.
- ✗
Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.
Why it's wrong here
Safe Attachments for SharePoint, OneDrive, and Microsoft Teams proactively detonates files in a virtual sandbox and blocks known malicious files after they are shared or uploaded. It operates on file content and binary behavior, not on message-level identity metadata such as the sender's display name, email envelope, or domain similarity. Since impersonation of a custom domain is a message-source problem, this malware-focused scanning cannot mitigate the described phishing threat.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.