MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
While preparing a Microsoft 365 adoption plan, a consultant is asked to let users report suspicious phishing messages from Outlook for investigation. Microsoft security, identity, or compliance capability should it use?
⚠ Common exam trap
Many candidates confuse Microsoft Forms (a generic survey tool) with a legitimate reporting mechanism, overlooking that Microsoft 365 provides a dedicated, integrated security solution (Defender for Office 365) for phishing submissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365 user submissions
Microsoft Defender for Office 365 user submissions (Option A) is the correct capability because it allows users to report suspicious phishing messages directly from Outlook, which are then routed to the Microsoft 365 Defender portal for investigation and analysis. This feature integrates with the built-in Report Message or Report Phishing add-ins, enabling security teams to review and act on user-reported threats within the unified security operations framework.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Office 365 user submissions
Why this is correct
Microsoft Defender for Office 365 user submissions is the correct service because it provides a supported workflow for end users to report suspicious emails directly from Outlook or Outlook on the web. These submissions are surfaced in the Microsoft 365 Defender portal, where admins can review them, send them to Microsoft for detonation and analysis, or use them to update tenant policies. This capability aligns with a security element in an adoption plan by actively involving users in threat reporting and incident response workflows.
- ✗
Microsoft Planner
Why it's wrong here
Microsoft Planner is a task and project management tool that organizes work through Kanban-style boards, buckets, and assignments within Microsoft 365 groups. It has no mechanism to receive, analyze, or forward email messages, and it lacks a security portal, threat intelligence feeds, or submission APIs for handling suspicious mail. Thus Planner cannot satisfy a requirement for user-driven email security reporting.
- ✗
Microsoft Forms
Why it's wrong here
Microsoft Forms is used to build surveys, quizzes, and data-collection forms whose responses are typically stored in tables or SharePoint lists. Although a form could theoretically ask a user to describe a suspicious email, it cannot ingest the actual email message, integrate with the Microsoft Defender for Office 365 investigation workflows, or trigger automated remediation. This option is therefore not a valid substitute for the built-in user submissions capability.
- ✗
Microsoft Stream
Why it's wrong here
Microsoft Stream is an enterprise video hosting and streaming solution designed for recorded meetings, training, and organizational communications. It does not accept email message input, expose a submission queue to security administrators, or participate in threat analysis pipelines. Because it is purely a media platform, it offers none of the phishing-reporting or compliance controls required for this security-focused need.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Message Centre and Change Management
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.