Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization has Microsoft Defender for Office 365 Plan 2. You need to ensure that when a user reports a phishing email using the Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the result. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a submission policy in the Microsoft 365 Defender portal

Configuring a submission policy in the Microsoft 365 Defender portal defines the behavior for user-reported messages using the Report Message add-in, including automatic submission to Microsoft for analysis and notification of results. Option A is incorrect because Safe Links policies protect users from malicious links, not handle user submissions. Option B is incorrect because anti-phishing policies detect and mitigate phishing attempts but do not control the submission process. Option C is incorrect because mail flow rules (transport rules) manage message routing and cannot submit messages to Microsoft for analysis or notify users of results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a Safe Links policy to block the reported email

    Why it's wrong here

    Safe Links policies protect users from malicious links in messages, but they do not handle user-reported messages or submissions.

  • Configure an anti-phishing policy to automatically submit reported emails

    Why it's wrong here

    Anti-phishing policies configure protection settings for phishing attempts, not the submission and analysis process for user-reported messages.

  • Use a mail flow rule to send reported emails to a custom mailbox

    Why it's wrong here

    Mail flow rules can route messages to a custom mailbox, but they do not automatically submit to Microsoft for analysis or notify users of results.

  • Configure a submission policy in the Microsoft 365 Defender portal

    Why this is correct

    A submission policy in the Microsoft 365 Defender portal controls how user-reported messages are handled, including automatic submission for analysis and notification to the user.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.