MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization has Microsoft Defender for Office 365 Plan 2. You need to ensure that when a user reports a phishing email using the Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the result. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a submission policy in the Microsoft 365 Defender portal
Configuring a submission policy in the Microsoft 365 Defender portal defines the behavior for user-reported messages using the Report Message add-in, including automatic submission to Microsoft for analysis and notification of results. Option A is incorrect because Safe Links policies protect users from malicious links, not handle user submissions. Option B is incorrect because anti-phishing policies detect and mitigate phishing attempts but do not control the submission process. Option C is incorrect because mail flow rules (transport rules) manage message routing and cannot submit messages to Microsoft for analysis or notify users of results.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Safe Links policy to block the reported email
Why it's wrong here
Safe Links policies protect users from malicious links in messages, but they do not handle user-reported messages or submissions.
- ✗
Configure an anti-phishing policy to automatically submit reported emails
Why it's wrong here
Anti-phishing policies configure protection settings for phishing attempts, not the submission and analysis process for user-reported messages.
- ✗
Use a mail flow rule to send reported emails to a custom mailbox
Why it's wrong here
Mail flow rules can route messages to a custom mailbox, but they do not automatically submit to Microsoft for analysis or notify users of results.
- ✓
Configure a submission policy in the Microsoft 365 Defender portal
Why this is correct
A submission policy in the Microsoft 365 Defender portal controls how user-reported messages are handled, including automatic submission for analysis and notification to the user.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.