Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Your company wants to run a phishing simulation to test employee awareness. Which Microsoft 365 tool can you use to create and launch a simulated phishing campaign?

⚠ Common exam trap

MS-900 often tests the confusion between Microsoft 365 security and compliance tools, expecting candidates to know that Attack Simulation Training is a feature of Defender for Office 365, not a standalone product or part of Purview or Intune.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Office 365 Attack Simulation Training

Microsoft Defender for Office 365 includes Attack Simulation Training, a feature specifically designed to create and launch simulated phishing campaigns. It provides realistic phishing emails, landing pages, and training assignments to educate users. This tool is part of the Threat Protection suite and is accessible via the Microsoft 365 Defender portal. It allows administrators to select payloads, target users, and schedule simulations, then review results and assign training.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Defender for Cloud Apps governs SaaS usage and detects threats via Cloud Discovery and anomaly policies; it cannot author simulated phishing emails. Attack simulation training in Microsoft Defender for Office 365 builds and launches those campaigns, so this option addresses the wrong workload entirely.

  • ✓

    Microsoft Defender for Office 365 Attack Simulation Training

    Why this is correct

    Attack Simulation Training, part of Microsoft Defender for Office 365, provides built-in phishing payloads, landing pages and training assignments, letting administrators launch simulated campaigns and track employee interaction. This directly satisfies the requirement to create and launch a phishing simulation.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Intune performs device enrolment, configuration profiles and compliance policy enforcement; it has no campaign authoring or phishing telemetry. It is tempting because Intune genuinely manages endpoint security settings, which is adjacent to awareness training but a different workload.

  • ✗

    Microsoft Purview Compliance Manager

    Why it's wrong here

    Compliance Manager assesses and tracks regulatory compliance posture through assessments and improvement actions; it cannot generate simulated phishing emails or capture user click reporting. It is tempting because it genuinely belongs to the same Microsoft Purview suite that hosts the Attack simulation training capability.

Go deeper

Related to this question

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.