MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. A user reports receiving a suspicious email with a link to a known phishing site. You need to prevent other users from clicking similar links in the future. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the URL to the Tenant Allow/Block List in Microsoft 365 Defender
The Tenant Allow/Block List in Microsoft 365 Defender allows you to block specific URLs across the organization, preventing users from accessing known phishing sites. Option A is incorrect because attack simulation training is for user education, not blocking links. Option B is incorrect because Safe Attachments policies only handle email attachments, not URLs. Option C is incorrect because spam filter policies manage spam classification, not specific URLs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the attack simulation training to educate users
Why it's wrong here
Attack simulation training changes user behaviour through exercises; it does not block the URL, so other users can still click it. It is tempting because it addresses the human layer, and it would be correct for measuring and improving phishing susceptibility over time.
- ✗
Create a Safe Attachments policy to block the attachment
Why it's wrong here
Safe Attachments detonates and blocks malicious files; the scenario involves a link, not an attachment, so the URL remains reachable. It is tempting because it is the correct control when the threat vector is an attached document or executable rather than a hyperlink.
- ✗
Configure a spam filter policy to block the sender
Why it's wrong here
Blocking the sender stops that mailbox's mail but leaves the phishing URL clickable when delivered by other senders or channels. It is tempting because sender blocking is correct for a persistent nuisance address, not for neutralising a known-malicious link across the tenant.
- ✓
Add the URL to the Tenant Allow/Block List in Microsoft 365 Defender
Why this is correct
Tenant Allow/Block List entries for URLs are enforced by Defender for Office 365 at time-of-click, blocking the phishing link for every user in the tenant. This satisfies the requirement to stop others clicking similar links, unlike user-level junk or transport rules.
Go deeper
Related to this question
Learn chapter
SharePoint External Sharing and Guest Policies
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
Safe Attachments
Safe Attachments is a Microsoft Defender for Office 365 feature that opens email attachments in a virtual sandbox to detect and block malicious content before they reach your inbox.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.