Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization is migrating to Microsoft 365 and wants to implement a defense-in-depth strategy for email security. Which combination of Microsoft services should you use?

⚠ Common exam trap

A common mix-up: candidates confuse compliance or identity services with email security layers, forgetting that defense-in-depth for email specifically requires both transport-level (EOP) and post-delivery (Defender for Office 365) protections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Office 365 and Exchange Online Protection

Defense-in-depth for email security requires layered protection at the transport, filtering, and post-delivery stages. Exchange Online Protection (EOP) provides baseline anti-malware, anti-spam, and transport rules, while Microsoft Defender for Office 365 adds advanced threat protection like Safe Attachments, Safe Links, and anti-phishing policies that inspect URLs and attachments in real time. Together, they cover the full email threat chain from ingress to user interaction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Office 365 and Exchange Online Protection

    Why this is correct

    Exchange Online Protection (EOP) provides the always-on baseline filtering for all Exchange Online mailboxes, including spam, bulk mail, malware, and spoof intelligence before a message reaches the user. Microsoft Defender for Office 365 (MDO) layers on top with Safe Attachments, Safe Links, and advanced anti-phishing policy that checks URLs and attachments in real time, plus impersonation and domain-based protection. Together they form the native email security stack, with EOP as the foundation and MDO handling zero-day or social-engineering threats that basic filters miss.

  • Microsoft Purview Compliance Manager and Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Purview Compliance Manager is a risk-assessment dashboard that maps your tenant against regulations like GDPR or HIPAA and suggests control improvements; it does not inspect or filter email traffic. Microsoft Defender for Cloud Apps acts as a cloud access security broker (CASB) that discovers cloud app usage, enforces conditional access policies, and can label or quarantine files in SaaS apps, but it does not block malicious links in email inbound from the internet. Selecting these would leave your Exchange Online mailboxes without anti-spam or anti-malware protection for the actual message transport path.

  • Microsoft Intune and Microsoft Entra ID

    Why it's wrong here

    Microsoft Intune is a mobile device and application management service that enforces compliance policies, deploys configurations, and manages certificates, but it never scans email attachments or inspects message content. Microsoft Entra ID (formerly Azure AD) provides identity authentication, single sign-on, and conditional access, which controls who can sign in but does not evaluate the threat level of an inbound email. These components secure the device and the user session, but the email itself and its payloads flow untouched through the gateway, making them the wrong answer for email security.

  • Microsoft Sentinel and Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM that ingests logs from many sources and uses KQL queries to hunt for incidents, requiring email telemetry to be connected before any email-specific detection can occur. Microsoft Defender for Identity monitors on-premises Active Directory for attacks such as pass-the-hash, Kerberos abuse, and privilege escalation using domain controller traffic, not SMTP messages. Neither product is a deliverable email gateway; at best, they are downstream analytic observability tools, whereas the customer needs the inline filtering from MDO and EOP.

About these practice questions

Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.