MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Office 365. You need to ensure that malicious links in email messages are blocked at the time of click by checking the link reputation in real time. What should you enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Links policy.
Safe Links policy in Defender for Office 365 provides real-time link reputation checking at the time of click. It rewrites URLs and checks them against a dynamic list of known malicious links when users click them. Option A is incorrect because anti-spam policies filter spam emails, not malicious links. Option B is incorrect because Safe Attachments scans email attachments for malware, not links. Option D is incorrect because anti-phishing policies protect against phishing attempts but do not perform real-time link checking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anti-spam policy.
Why it's wrong here
Anti-spam policies filter message content and sender reputation at delivery, not link destinations when a user clicks. Safe Links rewrites URLs and validates reputation at click time. Spam filtering is tempting because it blocks malicious mail, but it cannot evaluate a link after delivery.
- ✗
Safe Attachments policy.
Why it's wrong here
Safe Attachments detonates attachments in a sandbox to detect malicious payloads; it does not rewrite and inspect URLs at click time. Safe Links performs that real-time reputation check. Attachment scanning is tempting because both features sit in Defender for Office 365, but the requirement concerns links, not files.
- ✓
Safe Links policy.
Why this is correct
A Safe Links policy in Microsoft Defender for Office 365 rewrites URLs and verifies link reputation at click time, blocking malicious destinations in real time. This satisfies the time-of-click requirement, unlike Safe Attachments, which detonates attachments rather than evaluating links.
- ✗
Anti-phishing policy.
Why it's wrong here
Anti-phishing policies govern spoofing, impersonation and mailbox intelligence thresholds, not click-time URL reputation. Safe Links provides that real-time link inspection. Anti-phishing is tempting because phishing emails carry malicious links, but its controls operate on sender and message characteristics rather than the URL at click.
Go deeper
Related to this question
Learn chapter
Attack Simulation Training in Defender
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.