MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Office 365. Users report that legitimate emails from a specific partner domain are being moved to Junk Email folder. You verify that the partner's SPF, DKIM, and DMARC records are correctly configured. Which two actions should you take to resolve this issue?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the Anti-Phishing policy's spoof intelligence settings.
Legitimate emails from a partner domain are being moved to Junk Email folder despite correct SPF, DKIM, and DMARC records. This typically indicates that the emails are being misclassified as spoofed or phishing. Reviewing the Anti-Phishing policy's spoof intelligence settings (Option B) allows you to check if the partner domain is being incorrectly treated as a spoof sender and adjust the settings accordingly. Additionally, adding the partner domain to the Tenant Allow/Block List as an allowed domain (Option E) explicitly permits emails from that domain, overriding any false positive filtering. Option A (increasing spam threshold) may reduce spam filtering effectiveness and does not address the root cause. Option C (Outbound spam filter policy) affects outgoing emails, not inbound. Option D (disabling spam filter) is too aggressive and removes protection for the affected users. Therefore, the correct actions are B and E.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the Anti-Spam policy to increase the spam threshold.
Why it's wrong here
Increasing the spam threshold is not appropriate because the issue is not about spam filtering but about the domain being incorrectly classified as spoofed or phishing. This action could also allow more spam into the organization.
- ✓
Review the Anti-Phishing policy's spoof intelligence settings.
Why this is correct
Spoof intelligence settings can flag the partner domain as intra-organisation or impersonating a trusted sender, overriding correct SPF, DKIM and DMARC. Reviewing them identifies why legitimate mail is treated as spoofed and routed to Junk Email.
- ✗
Configure the Outbound spam filter policy.
Why it's wrong here
The outbound spam filter policy governs mail leaving the organisation, so it cannot influence inbound partner messages being classified as junk. It would be the correct control when outbound messages are being blocked or marked, whereas this scenario requires adjusting inbound anti-spam settings such as the allowed senders list.
- ✗
Disable the Spam filter for the affected users.
Why it's wrong here
Disabling spam filtering removes all junk-mail protection tenant-wide for those users, so phishing and bulk mail reach their inboxes; it does not address why a correctly authenticated partner domain is being classified. Spam filter exceptions or tenant allow lists target the specific sender instead. Disabling filtering suits troubleshooting only when filtering itself is proven faulty.
- ✓
Add the partner domain to the Tenant Allow/Block List as an allowed domain.
Why this is correct
Adding the partner domain to the Tenant Allow/Block List as allowed overrides Defender for Office 365 filtering decisions, ensuring mail bypasses Junk Email. This directly satisfies the requirement to restore delivery of legitimate partner messages despite correct authentication records.
Visual reference
Go deeper
Related to this question
Learn chapter
Tenant-Wide Settings and Org Profile
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.