Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A user reports receiving a phishing email in their Outlook inbox. The organization uses Microsoft Defender for Office 365. Which feature should the user use to report the email to the security team?

⚠ Common exam trap

MS-900 often tests the misconception that users should submit phishing emails through the Defender portal — the correct end-user action is the Report Message add-in, while portal submission is an admin function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Report Message add-in in Outlook

The Report Message add-in in Outlook is the user-facing tool that lets users report suspicious emails directly to the security team with a single click. Reported messages are sent to Microsoft for analysis and can be routed to the organization's security operations team via the Microsoft 365 Defender portal's user-reported settings. This is the intended workflow for phishing reports in Defender for Office 365 environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the Report Message add-in in Outlook

    Why this is correct

    The Report Message add-in submits the phishing email directly to Microsoft Defender for Office 365, letting the security team triage and tune filters. It satisfies the stem's requirement to report from within Outlook, unlike forwarding manually, which loses metadata and delays automated analysis.

  • ✗

    Block the sender in Outlook

    Why it's wrong here

    Blocking the sender stops only that address, leaving the malicious payload unreported, so Defender for Office 365 cannot analyse it, tune filters, or purge matching messages from other mailboxes. Blocking suits repeat nuisance senders; reporting a phishing email requires the Report Message add-in to submit it for analysis.

  • ✗

    Submit the email to the Microsoft 365 Defender portal

    Why it's wrong here

    Submitting via the Microsoft 365 Defender portal requires the user to manually extract and upload the message, bypassing the built-in Report Message add-in that feeds submissions directly into Defender for Office 365. The portal suits admins investigating submissions, not end users reporting a suspicious email from Outlook.

  • ✗

    Enable Safe Links in Outlook

    Why it's wrong here

    Safe Links rewrites and detonates URLs at click time; it is a preventive policy configured by administrators, not a reporting mechanism, so the security team receives no submission. Enabling it suits ongoing URL protection across the tenant, whereas reporting a specific phishing email needs the Report Message add-in.

Go deeper

Related to this question

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.