SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your company uses Microsoft 365 E5 licenses and has deployed Microsoft Defender for Office 365. The security team wants to be alerted when a user reports a phishing email using the built-in report message button in Outlook. The alert should be sent to the security team's email address. You need to configure this in the Microsoft 365 Defender portal. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the User reported messages settings to send alerts to the security team.
The correct option is B: configure the User reported messages settings to send alerts to the security team. In the Microsoft 365 Defender portal, under Email & collaboration > Policies & rules > Threat policies > User reported messages, you can specify a reporting mailbox and enable notifications so that when a user reports a phishing message via the built-in Report Message/Report Phishing add-in, the security team is alerted. This directly addresses the requirement to alert the security team when a user reports a phishing email. Options A, C, and D do not fit: anti-phishing policies control impersonation and spoofing protections and user tips, while Safe Attachments and Safe Links policies detonate attachments and rewrite/scan URLs at delivery and click time, respectively, and none of them trigger an alert based on a user's manual report.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an anti-phishing policy that notifies users about phishing.
Why it's wrong here
Anti-phishing policies in Defender for Office 365 are designed to detect and mitigate phishing threats before delivery, using features such as spoof intelligence, impersonation protection, and mailbox intelligence. They do not intercept or process user-reported messages; their notification capabilities are not tied to the user submission workflow. Therefore, creating such a policy would not route end-user reports to the security team.
- ✓
Configure the User reported messages settings to send alerts to the security team.
Why this is correct
The User reported messages settings in the Microsoft 365 Defender portal (under Email & collaboration > Policies & rules > Threat policies) let you specify where messages reported by users via Outlook, Outlook on the web, or the built-in Report Message button are sent. You can direct these submissions to an internal mailbox, Microsoft, or both, and configure alert notifications so the security team is immediately informed when a user submits a message. This directly satisfies the requirement to make reports visible and actionable.
- ✗
Create a Safe Attachments policy to detect phishing attachments.
Why it's wrong here
Safe Attachments is a pre-delivery sandboxing feature that detonates email attachments in a virtual environment to detect malicious content before delivery. It operates at the transport level and does not capture or route messages after a user has already submitted a report. Thus, enabling Safe Attachments would not help the security team receive or process user-reported phishing messages.
- ✗
Create a Safe Links policy that alerts on phishing URLs.
Why it's wrong here
Safe Links protects users from phishing by scanning URLs in email messages and Office documents, blocking malicious links at click time. It exclusively inspects hyperlinks and does not offer a channel for end users to submit suspicious messages they have already encountered, nor does it generate alerts specifically when a user reports a message. Therefore, it is not the correct control for this scenario.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.