MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your organization uses Microsoft Defender for Office 365. You need to configure a policy that automatically redirects emails containing malicious attachments to a quarantine folder for admin review. What type of policy should you create?
⚠ Common exam trap
Microsoft often tests the distinction between Anti-malware (for attachment malware) and Safe Attachments (for advanced sandbox analysis), leading candidates to mistakenly choose Safe Attachments when the core requirement is simply redirecting known malicious attachments to quarantine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anti-malware policy.
B is correct because the Anti-malware policy in Microsoft Defender for Office 365 is specifically designed to handle malware detected in email messages, including attachments. When configured, it can automatically redirect messages containing malicious attachments to a quarantine folder for admin review, providing a controlled remediation workflow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Safe Attachments policy.
Why it's wrong here
Safe Attachments policies are focused on detonating email attachments in a sandboxed environment before delivery, using threat intelligence and machine learning to identify malicious content. While this policy can block or replace suspicious attachments, it does not provide a direct quarantine action for messages found to contain malware; quarantine settings for malware are defined in the anti-malware policy. Therefore, Safe Attachments is related but not the correct policy for quarantining malware-infected messages.
- ✓
Anti-malware policy.
Why this is correct
The anti-malware policy in Microsoft Defender for Office 365 is the correct place to configure how messages containing malware are handled. It uses heuristics and signature-based detection to identify malicious attachments, and when malware is found, the policy can be set to quarantine the entire message. This policy also allows admins to specify the quarantine retention period and enable/disable malware filters, making it the definitive control for malware-induced quarantine.
- ✗
Anti-spam policy.
Why it's wrong here
Anti-spam policies are designed to filter unsolicited bulk email and phishing attempts using content filtering, IP reputation, and advanced spam filters. They do not scan for malware attachments; malware detection is performed by the anti-malware engine, which is configured independently. Although spam messages can also be quarantined, the anti-spam policy's quarantine actions apply only to spam verdicts, not to malware verdicts, so it is the wrong choice for this scenario.
- ✗
Safe Links policy.
Why it's wrong here
Safe Links policies protect users from malicious URLs embedded in email messages and Microsoft Teams by checking every link at click time and blocking access to known malicious destinations. This policy does not inspect or quarantine the email attachment itself; attachment-level malware detection and quarantine are handled by the anti-malware pipeline. Because the question concerns messages with malware in attachments, Safe Links is not the correct policy.
Go deeper
Related to this question
Learn chapter
Microsoft Loop Admin Controls
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Anti-malware policy
An anti-malware policy is a set of rules and procedures that an organization enforces to prevent, detect, and remove malicious software from its computers and networks.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.