MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
You are implementing Microsoft Defender for Office 365. You need to configure anti-phishing policies to protect against user impersonation. Which THREE settings should you configure?
⚠ Common exam trap
Test-takers frequently confuse anti-phishing settings with anti-spam or spoof intelligence settings, mistakenly selecting bulk email threshold or spoof intelligence when the question explicitly targets user impersonation protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable impersonation protection for domains you own.
Enabling impersonation protection for domains you own allows Defender for Office 365 to detect and act on attempts to spoof your organization's domain in the From address. This setting ensures that emails claiming to be from your domain are inspected for impersonation patterns, such as lookalike domains or display name spoofing, and can be automatically quarantined or have safety tips applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable impersonation protection for domains you own.
Why this is correct
Enabling impersonation protection for domains you own directly instructs Defender for Office 365 to inspect messages where the sender address visually mimics any domain associated with your tenant. In the anti-phishing policy, toggling on this setting and optionally listing additional domains subjects such forged domain messages to the configured action (quarantine, redirect, or mailbox rule). Because the requirement centers on defending against attackers who abuse your own domain as the sender, this is the primary and correct configuration to implement.
- ✓
Enable mailbox intelligence to detect impersonation based on user behavior.
Why this is correct
Mailbox intelligence is an AI-driven capability that learns each user's regular communication patterns—such as whom they email, how frequently, and from which senders—and uses this behavioral baseline to flag anomalous impersonation attempts against that user. It augments impersonation detection by catching look-alike attacks that may not rely on a protected domain, strengthening the overall anti-phishing posture. While this is a correct companion setting, it complements rather than replaces explicit domain impersonation protection.
- ✗
Set the bulk email threshold.
Why it's wrong here
The bulk email threshold is configured in the anti-spam policy, not the anti-phishing policy, and determines the Bulk Complaint Level (BCL) at which messages are treated as bulk or junk email. Adjusting this threshold may help manage spam volume but does nothing to detect or block a message that falsifies your organization's domain as the sender. Therefore, it is incorrect for an implementation focused on impersonation protection.
- ✓
Enable impersonation protection for users who are defined as protected users.
Why this is correct
Enabling impersonation protection for defined protected users is a targeted control that applies stronger identity checks when an incoming message appears to originate from a specific high-value user, such as an executive or IT administrator. You select these users in the anti-phishing policy and assign an action, which defends against user impersonation. This is a correct secondary measure, but it protects only the named individuals, so it does not substitute for protecting your entire domain namespace.
- ✗
Configure spoof intelligence to allow or block senders.
Why it's wrong here
Spoof intelligence is a separate anti-phishing mechanism that analyzes email headers to identify when an external sender is spoofing a domain that has authenticated mail, then lets you allow or block those sender/domain pairs. It does not detect impersonation of individual users or newly registered look-alike domains, and configuring it is not equivalent to enabling impersonation protection for your tenant's own domains. This distinction is a common misconception, making spoof intelligence an incorrect answer for this impersonation-focused scenario.
Go deeper
Related to this question
Learn chapter
Conditional Access Policies
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.