MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your organization has a Microsoft 365 E5 subscription. You want to enable Microsoft Defender for Office 365 to protect against malicious attachments in email. Which policy should you configure?
⚠ Common exam trap
Watch out — candidates often confuse the basic Anti-malware policy (which uses signature-based detection) with the advanced Safe Attachments policy (which uses sandbox detonation), leading them to select Option B incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Attachments policy
Safe Attachments policy is the correct choice because Microsoft Defender for Office 365's Safe Attachments feature specifically protects against malicious attachments in email by detonating them in a virtual sandbox environment before delivery. This policy allows you to configure actions for detected malware, such as blocking, replacing, or dynamically delivering attachments based on threat analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anti-phishing policy
Why it's wrong here
Anti-phishing policy in Microsoft 365 uses impersonation protection, spoof intelligence, and mailbox intelligence to detect social-engineering and identity-based attacks, but it does not inspect the binary payload of email attachments. It is focused on the sender domain, display name, and message context, not on file content or behavior. Therefore, while a phishing email may carry a malicious attachment, the anti-phishing policy is not the mechanism that would scan and detonate that attachment.
- ✗
Anti-malware policy
Why it's wrong here
The anti-malware policy in Exchange Online Protection provides baseline signature-based and heuristic malware detection, blocking known malware families and matching file patterns, but it does not perform the advanced sandbox detonation that Safe Attachments does. Unknown or polymorphic attachments that exhibit malicious behavior only during execution can slip past this legacy engine. In Defender for Office 365, Safe Attachments is the layer designed to analyze those suspicious attachment payloads in a virtual environment.
- ✓
Safe Attachments policy
Why this is correct
Safe Attachments policy is the correct answer because it routes each email attachment to an isolated Microsoft detonation chamber, where the file is opened and executed in a virtualized environment to observe its run-time behavior. It can block or replace the attachment if unknown malware or zero-day exploit activity is detected, and it can also redirect the message for admin review. This is the Defender for Office 365 mechanism specifically built to protect against malicious attachments that evade classic signature-based scanning.
- ✗
Safe Links policy
Why it's wrong here
Safe Links policy protects end users by wrapping and time-of-click checking URLs inside email messages, Teams, and supported Office documents, but it never examines the attachment file itself as a block of content. If an email attachment is a PDF or executable containing an exploit, Safe Links has no role in scanning that file; the threat is inside the payload, not in a clickable link. Thus Safe Links addresses URL-based vectors, not malicious attachments.
Go deeper
Related to this question
Learn chapter
Attack Simulation Training in Defender
Key term
Safe Attachments
Safe Attachments is a Microsoft Defender for Office 365 feature that opens email attachments in a virtual sandbox to detect and block malicious content before they reach your inbox.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.