Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. A user reports receiving a suspicious email with a link to a known phishing site. You need to prevent other users from clicking similar links in the future. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the URL to the Tenant Allow/Block List in Microsoft 365 Defender

The Tenant Allow/Block List in Microsoft 365 Defender allows you to block specific URLs across the organization, preventing users from accessing known phishing sites. Option A is incorrect because attack simulation training is for user education, not blocking links. Option B is incorrect because Safe Attachments policies only handle email attachments, not URLs. Option C is incorrect because spam filter policies manage spam classification, not specific URLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the attack simulation training to educate users

    Why it's wrong here

    Attack simulation training changes user behaviour through exercises; it does not block the URL, so other users can still click it. It is tempting because it addresses the human layer, and it would be correct for measuring and improving phishing susceptibility over time.

  • ✗

    Create a Safe Attachments policy to block the attachment

    Why it's wrong here

    Safe Attachments detonates and blocks malicious files; the scenario involves a link, not an attachment, so the URL remains reachable. It is tempting because it is the correct control when the threat vector is an attached document or executable rather than a hyperlink.

  • ✗

    Configure a spam filter policy to block the sender

    Why it's wrong here

    Blocking the sender stops that mailbox's mail but leaves the phishing URL clickable when delivered by other senders or channels. It is tempting because sender blocking is correct for a persistent nuisance address, not for neutralising a known-malicious link across the tenant.

  • ✓

    Add the URL to the Tenant Allow/Block List in Microsoft 365 Defender

    Why this is correct

    Tenant Allow/Block List entries for URLs are enforced by Defender for Office 365 at time-of-click, blocking the phishing link for every user in the tenant. This satisfies the requirement to stop others clicking similar links, unlike user-level junk or transport rules.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.