MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
You are the Microsoft 365 administrator for a company with a Microsoft 365 E3 tenant. The security team requires that you reduce the attack surface for email by blocking auto-forwarding to external domains and by ensuring that any email sent from an external sender that spoofs your custom domain is rejected. You must implement the controls natively in Microsoft 365 Defender. Which two actions should you perform? (Choose two.)
⚠ Common exam trap
The trap here is mixing up domain impersonation, which targets lookalike domains, with anti-spoofing intelligence, which handles exact spoofs of domains you own.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an outbound anti-spam policy and set the Automatic forwarding rule to Off, then apply the policy to all recipients.
Blocking external auto-forwarding is done through the Automatic forwarding setting in an outbound anti-spam policy applied to all recipients. Rejecting spoofed mail that claims to be from your own domain relies on the anti-spoofing intelligence built into the default anti-phishing policy, which acts on your accepted domains, provided no allow entry in the Tenant Allow/Block List overrides the verdict.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an outbound anti-spam policy and set the Automatic forwarding rule to Off, then apply the policy to all recipients.
Why this is correct
The outbound anti-spam policy contains the Automatic forwarding setting that controls whether users can auto-forward email to external domains. Setting it to Off blocks this exfiltration path, and applying the policy to all recipients ensures the control is tenant-wide. This directly addresses the requirement to prevent automatic external forwarding.
- ✗
Create an anti-phishing policy and enable the mailbox intelligence setting for all users.
Why it's wrong here
Mailbox intelligence improves impersonation detection by learning each user's contacts and communication patterns, but it does not reject messages that spoof your own custom domain. Domain spoofing requires the anti-phishing policy's domain impersonation protection or an anti-spoofing setting, not mailbox intelligence alone.
- ✗
Configure the anti-phishing policy's Spoof intelligence by adding your custom domain as an allowed sender so that internal spoofing is permitted.
Why it's wrong here
Adding a domain as an allowed sender in spoof intelligence permits spoofed messages rather than rejecting them, which is the opposite of the requirement. Spoof intelligence is used to review and override verdicts for senders that fail authentication, and allowing your own domain would let attackers bypass the protection.
- ✓
Ensure the default anti-phishing policy's anti-spoofing protection is enabled and that no allowed sender entry exists for your custom domain in the Tenant Allow/Block List.
Why this is correct
Anti-spoofing protection in the default anti-phishing policy evaluates unauthenticated inbound mail that uses your owned domains and marks it as spoofing, which causes it to be rejected or quarantined based on the verdict. Confirming that no allow entry for your domain exists in the Tenant Allow/Block List prevents an override from letting spoofed messages through.
- ✗
Add your custom domain to the Domain impersonation section of the anti-phishing policy and set the action to Quarantine the message.
Why it's wrong here
Domain impersonation protects against lookalike domains, not exact spoofs of your own domain. When someone sends mail that claims to be from your exact domain but fails authentication, the correct control is the anti-spoofing intelligence in the default anti-phishing policy, which already handles your owned domains. Configuring your own domain as an impersonation target is not the supported approach.
Go deeper
Related to this question
Learn chapter
Anti-Spam and Anti-Malware Policies
Key term
Anti-spam policy
An anti-spam policy is a set of rules and filters used by email systems to automatically detect and block unwanted, unsolicited, or harmful messages before they reach a user's inbox.
Key term
Custom domain
A custom domain is a personalized internet address (like contoso.com) that you can use with cloud services instead of the default domain provided by the service provider.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.