MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A user reports receiving a phishing email in their Outlook inbox. The organization uses Microsoft Defender for Office 365. Which feature should the user use to report the email to the security team?
⚠ Common exam trap
MS-900 often tests the misconception that users should submit phishing emails through the Defender portal — the correct end-user action is the Report Message add-in, while portal submission is an admin function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Report Message add-in in Outlook
The Report Message add-in in Outlook is the user-facing tool that lets users report suspicious emails directly to the security team with a single click. Reported messages are sent to Microsoft for analysis and can be routed to the organization's security operations team via the Microsoft 365 Defender portal's user-reported settings. This is the intended workflow for phishing reports in Defender for Office 365 environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the Report Message add-in in Outlook
Why this is correct
The Report Message add-in submits the phishing email directly to Microsoft Defender for Office 365, letting the security team triage and tune filters. It satisfies the stem's requirement to report from within Outlook, unlike forwarding manually, which loses metadata and delays automated analysis.
- ✗
Block the sender in Outlook
Why it's wrong here
Blocking the sender stops only that address, leaving the malicious payload unreported, so Defender for Office 365 cannot analyse it, tune filters, or purge matching messages from other mailboxes. Blocking suits repeat nuisance senders; reporting a phishing email requires the Report Message add-in to submit it for analysis.
- ✗
Submit the email to the Microsoft 365 Defender portal
Why it's wrong here
Submitting via the Microsoft 365 Defender portal requires the user to manually extract and upload the message, bypassing the built-in Report Message add-in that feeds submissions directly into Defender for Office 365. The portal suits admins investigating submissions, not end users reporting a suspicious email from Outlook.
- ✗
Enable Safe Links in Outlook
Why it's wrong here
Safe Links rewrites and detonates URLs at click time; it is a preventive policy configured by administrators, not a reporting mechanism, so the security team receives no submission. Enabling it suits ongoing URL protection across the tenant, whereas reporting a specific phishing email needs the Report Message add-in.
Go deeper
Related to this question
Learn chapter
Microsoft 365 vs Office 365: What Changed
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.