Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization uses Microsoft 365 Defender for Office 365. You need to ensure that phishing emails reported by users are automatically submitted for analysis in Microsoft Defender XDR. What should you configure?

⚠ Common exam trap

Candidates often confuse the anti-phishing policy (which handles detection settings) with the User-reported messages settings (which handles submission of user-reported emails), leading them to incorrectly select Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the User-reported messages settings in the Microsoft 365 Defender portal.

The User-reported messages settings in the Microsoft 365 Defender portal allow you to configure how user-reported phishing emails are handled. By enabling automatic submission to Microsoft for analysis, you ensure that reported messages are sent directly to the Microsoft security team for threat intelligence and policy tuning. This is the correct setting because it specifically controls the submission behavior for user-reported messages in Defender for Office 365.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the anti-phishing policy to include user-reported submissions.

    Why it's wrong here

    Anti-phishing policies in Defender for Office 365 govern email protection features such as spoof intelligence, impersonation detection, mailbox intelligence, and advanced phishing thresholds; they do not include any section for user-reported message submissions. User-reported message handling is configured separately under Settings > Email & collaboration > User-reported messages in the Microsoft 365 Defender portal, where you designate where reports are sent for analysis. Therefore, modifying the anti-phishing policy would not expose or affect submission settings.

  • ✗

    Use the Attack simulation training to collect user reports.

    Why it's wrong here

    Attack simulation training is designed to create and launch simulated phishing attacks to assess user susceptibility and deliver training content; it does not collect or process real user-reported emails. Actual user reports of suspected phishing or junk are captured through the User-reported messages settings, which route submissions to Microsoft or an internal mailbox for analysis. Using Attack simulation training for collecting user reports would be incorrect because it generates synthetic attack data rather than handling genuine user submissions.

  • ✗

    Enable Safe Attachments policy to automatically submit reported messages.

    Why it's wrong here

    A Safe Attachments policy controls the scanning and detonation of email attachments to detect malicious payloads, with verdicts ranging from Allow to Block, but it has no capability to automatically submit user-reported messages for analysis. User-reported submissions are governed by the User-reported messages settings in the Defender portal, which determine the destination and handling of each report independent of Safe Attachments. Merely enabling Safe Attachments would not redirect or process user-reported messages through the submission pipeline.

  • ✓

    Configure the User-reported messages settings in the Microsoft 365 Defender portal.

    Why this is correct

    Configuring the User-reported messages settings in the Microsoft 365 Defender portal is the correct approach because this setting controls the end-user reporting experience and how reported messages are submitted: to Microsoft for automated analysis, to a designated internal mailbox for manual triage, or to both. It also integrates with the Submission portal, enabling admins to view, analyze, and take action on user-reported messages. This is the sole central configuration point that governs user-reported submissions for analysis in Defender for Office 365.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.