Courseiva
Deploy and manage a Microsoft 365 tenanthardMultiple ChoiceObjective-mapped

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization uses Microsoft Defender for Office 365. You have configured a safe attachment policy that should automatically detonate attachments in a sandbox before delivery. However, some users still receive malicious attachments. What should you check first?

⚠ Common exam trap

The trap here is that candidates often overlook the difference between 'Monitor' and 'Replace'/'Dynamic Delivery' actions, assuming any Safe Attachments policy will automatically detonate before delivery, when in fact 'Monitor' delivers first and only logs the result.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify that the Safe Attachments policy is applied to the affected users and that the action is set to 'Dynamic Delivery' or 'Replace' (not 'Monitor').

Safe Attachments policies can be configured with actions like 'Dynamic Delivery' or 'Replace' to actively block or detonate attachments before delivery. If the action is set to 'Monitor', attachments are delivered first and only monitored, which can allow malicious attachments to reach users. Therefore, verifying the policy action is the first step to ensure detonation occurs before delivery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Check whether a mail flow rule (transport rule) is bypassing Safe Attachments.

    Why it's wrong here

    Although possible, you should first check the Safe Attachments policy itself.

  • Check the Safe Links policy configuration.

    Why it's wrong here

    Safe Links protects against malicious URLs, not attachments.

  • Review the mailbox audit log for each affected user.

    Why it's wrong here

    The audit log may show when emails were delivered but not why the policy didn't apply.

  • Verify that the Safe Attachments policy is applied to the affected users and that the action is set to 'Dynamic Delivery' or 'Replace' (not 'Monitor').

    Why this is correct

    The policy must be applied and set to detonate attachments.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.