Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A mid-sized company, Fabrikam, uses Microsoft 365 Business Premium. The company has 500 users and wants to implement a solution to protect against phishing attacks that target user credentials. The solution must: 1. Automatically detect and block malicious links in emails and Teams messages. 2. Provide real-time protection when users click on links in emails. 3. Allow users to report suspicious emails to the security team. 4. Integrate with Microsoft Entra ID to enforce conditional access policies based on user risk. Which combination of Microsoft 365 services should Fabrikam deploy?

⚠ Common exam trap

Many exam-takers confuse Microsoft Purview (compliance/DLP) with email security, or think Intune's compliance policies can replace dedicated phishing protection, but only Defender for Office 365 provides the required link scanning and click-time protection for email and Teams.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Microsoft Defender for Office 365 and enable Microsoft Defender XDR.

Microsoft Defender for Office 365 (formerly Office 365 ATP) provides Safe Links and Safe Attachments to automatically detect and block malicious links in email and Teams messages, and offers real-time protection when users click links. Microsoft Defender XDR (Extended Detection and Response) correlates signals across Defender for Office 365, Defender for Endpoint, and Microsoft Entra ID to enforce conditional access policies based on user risk, fulfilling all four requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Microsoft Intune and enforce conditional access policies that require compliant devices.

    Why it's wrong here

    Deploying Microsoft Intune and enforcing conditional access policies that require compliant devices is a device management and access control solution, not an email threat protection mechanism. Intune ensures devices are enrolled, patched, and compliant, and conditional access can block access from compromised or non-compliant devices, but it does not inspect email messages for malicious links or attachments. Phishing protection specifically requires a security solution like Microsoft Defender for Office 365 that operates at the message transport level.

  • ✗

    Deploy Microsoft Sentinel and configure analytics rules for phishing.

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR platform that ingests logs from many sources to detect and respond to threats, but it is not the first line of defense for inbound email phishing. To use Sentinel for phishing, you would need to onboard Defender for Office 365 logs and create custom analytics rules to identify attack patterns, which is reactive and requires ongoing tuning. For direct protection of mailboxes against phishing links and attachments, the appropriate service is Microsoft Defender for Office 365.

  • ✗

    Deploy Microsoft Purview Data Loss Prevention and set up an email policy.

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) is focused on identifying and protecting sensitive data—such as credit card numbers or personally identifiable information—from being shared inappropriately in emails or documents. DLP policies can block or warn on content that matches sensitive info types, but they do not evaluate URLs against threat intelligence or quarantine messages as malicious. Phishing link protection is a separate capability provided by Microsoft Defender for Office 365's Safe Links and anti-phishing policies.

  • ✓

    Deploy Microsoft Defender for Office 365 and enable Microsoft Defender XDR.

    Why this is correct

    Microsoft Defender for Office 365 is the correct choice because it provides comprehensive, pre-delivery and post-delivery protection against phishing through Safe Links (URL detonation and block-time verification), Safe Attachments, and anti-phishing policies that detect impersonation and spoofing. Additionally, enabling Microsoft Defender XDR aggregates signals from Defender for Office 365, Defender for Endpoint, and Defender for Identity, enabling automated investigation and response across the entire kill chain. This also integrates with Microsoft Entra ID to inform conditional access and identity risk policies, closing the loop between email threat detection and access control.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.