Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A user receives a phishing email that bypasses the spam filter. The security team wants to report the email to Microsoft for analysis. Which Microsoft 365 Defender portal should they use?

⚠ Common exam trap

Many exam-takers confuse the Microsoft 365 Defender portal with the Exchange admin center, thinking email-related tasks must be done in EAC, but Microsoft 365 Defender is the dedicated security hub for threat submission and analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft 365 Defender portal

The Microsoft 365 Defender portal (security.microsoft.com) is the correct destination for submitting user-reported phishing emails for analysis. It provides the Submissions page under Email & collaboration, where security teams can send suspicious messages directly to Microsoft for review, bypassing the spam filter's failure. This portal consolidates threat intelligence and automated investigation capabilities for email threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft 365 Defender portal

    Why this is correct

    Correct. The Microsoft 365 Defender portal is the unified security operations center for Microsoft 365, and its Email & collaboration > Submissions page is explicitly designed for admins to submit suspicious emails (including phishing that bypassed filters) to Microsoft for in-depth analysis. Submitting a sample triggers automated detonation and feeds threat intelligence back into Microsoft's filtering stack, which is the correct remediation workflow for a phish that evaded existing protections.

  • ✗

    Exchange admin center

    Why it's wrong here

    Incorrect. The Exchange admin center (EAC) is used to configure mail flow, mailboxes, and anti-spam/anti-malware policies, but it has no user-facing or admin-facing workflow for reporting a phishing email that bypassed the filter. While you can adjust anti-spam settings or create transport rules in the EAC, doing so only manages local policy; it does not submit the raw email message to Microsoft for threat analysis and filter updates, which is what a bypassed phish requires.

  • ✗

    Azure portal

    Why it's wrong here

    Incorrect. The Azure portal is the management plane for Azure subscriptions, virtual machines, PaaS services, and Entra ID (Azure AD), not for Microsoft 365 workload security. It contains Microsoft Defender for Cloud (formerly Azure Security Center), which focuses on securing cloud infrastructure and VM workloads, not on reporting phishing email that bypassed Exchange Online's spam filter. Phishing submissions for Exchange Online live in the Microsoft 365 Defender portal, not in the Azure portal.

  • ✗

    Microsoft Purview compliance portal

    Why it's wrong here

    Incorrect. The Microsoft Purview compliance portal is designed for compliance-related activities such as data loss prevention, eDiscovery, audit, insider risk management, and records management. Although the Defender portal and Purview portal are both part of the Microsoft 365 admin ecosystem, Purview lacks any security threat reporting capability and has no flow for submitting a phishing email sample to Microsoft for analysis. Reporting a bypassed phish is a security operation, so it belongs in the Defender portal under Email & collaboration, not in Purview.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.