Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

You are a security architect for a large enterprise that is migrating to Microsoft 365. The organization has 50,000 users across multiple regions. They have recently experienced a ransomware attack that encrypted files on SharePoint Online and OneDrive for Business. The security team wants to implement a comprehensive protection strategy. Requirements: 1. Automatically detect and block ransomware-like behavior in real-time. 2. Provide users with self-service recovery of files encrypted by ransomware. 3. Ensure that all files in SharePoint and OneDrive are scanned for malware upon upload. 4. Minimize administrative overhead. Which combination of Microsoft 365 security features should you recommend?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Defender for Office 365 with Microsoft Defender for Cloud Apps or Microsoft Purview, but only Defender for Office 365 provides both upload scanning and native version history/recycle bin recovery for SharePoint and OneDrive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Defender for Office 365 to scan files on upload and use version history and recycle bin for recovery.

Microsoft Defender for Office 365 provides real-time scanning of files uploaded to SharePoint and OneDrive, detecting and blocking known malware. Combined with version history and the recycle bin, users can self-recover files encrypted by ransomware without administrative intervention, satisfying all requirements with minimal overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft Entra ID Protection to detect compromised accounts and automatically block access.

    Why it's wrong here

    Microsoft Entra ID Protection only evaluates sign-in risk and user risk; it can challenge or block authentication for compromised accounts, but it has no file-level or malware-scanning capability. Ransomware typically arrives as an email attachment or via a direct upload from an already-authenticated user, so a healthy identity session won't stop the initial infection. Therefore, while it reduces the attack surface, it does not provide ransomware detection or file recovery.

  • ✗

    Enable Microsoft Endpoint DLP and configure file policies to block encrypted files.

    Why it's wrong here

    Microsoft Endpoint DLP is a data classification engine that inspects content for sensitive information types and can restrict actions like copy, paste, or upload, but it does not inspect for malware or detect encryption as a malicious event. If you block all encrypted files, you would break legitimate use cases like BitLocker-protected documents or user-applied encryption, and ransomware that encrypts files inside SharePoint would not be blocked because a DLP policy would never be triggered. Its purpose is data loss prevention, not endpoint protection or recovery from ransomware.

  • ✓

    Enable Microsoft Defender for Office 365 to scan files on upload and use version history and recycle bin for recovery.

    Why this is correct

    Defender for Office 365 runs anti-malware and detonation-in-sandbox scanning on files uploaded to SharePoint, OneDrive, and Microsoft Teams, immediately removing known malicious files. It also continuously monitors for ransomware activity with heuristic and machine-learning rules, then alerts you to impacted files. Version history and the recycle bin act as a self-service recovery mechanism, letting you restore a previous unencrypted version of a file with a few clicks, even after mass encryption. This combines prevention, detection, and remediation—exactly what the question asks for.

  • ✗

    Configure Microsoft Purview auto-labeling to apply a 'Ransomware' label and then block all labeled files.

    Why it's wrong here

    Microsoft Purview auto-labeling applies classification labels based on rules such as sensitive info types, keywords, or trainable classifiers, and those labels can invoke protection like encryption or external-sharing block. It does not perform malware scanning, and it cannot distinguish between a file encrypted by ransomware and a file that is simply formatted in a compressed or encrypted container (for example, a .zip or a PDF). Blocking every file that carries a 'Ransomware' label would cause broad business disruption and still fail to stop an attack, because ransomware does not modify data classification labels.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.