SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Defender for Office 365 and wants to block malicious links in email messages in real time. Which policy should you configure?
⚠ Common exam trap
It's easy for candidates to confuse Safe Links with Safe Attachments, mistakenly thinking that attachment scanning covers embedded links, but Safe Attachments only handles file payloads, not URLs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Links policy
Safe Links policy in Microsoft Defender for Office 365 provides real-time URL scanning and rewriting at the time of click, enabling the blocking of malicious links in email messages. This policy wraps URLs to route clicks through Microsoft's threat intelligence service, which checks the link against current threat data and blocks access if malicious content is detected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anti-phishing policy
Why it's wrong here
An anti-phishing policy in Defender for Office 365 focuses on impersonation and spoofing protection, using mailbox intelligence and domain impersonation checks. It can influence phishing detection, but it does not directly inspect or block URLs at click time. Any link-blocking capability is delegated to the Safe Links engine, not the anti-phishing policy itself. Therefore, selecting this policy would not provide the real-time malicious link blocking the scenario requires.
- ✗
Safe Attachments policy
Why it's wrong here
A Safe Attachments policy protects against malware carried in email attachments by routing those files through a detonation sandbox to observe behavior before delivery. It only evaluates binary file content, not hyperlinks or embedded URLs within the message body. Since the attack vector described involves clicking a malicious link rather than opening an infected file, this policy would leave the user exposed.
- ✓
Safe Links policy
Why this is correct
The Safe Links policy is the correct control because it directly handles malicious URLs by rewriting every link in email at the time of delivery and then performing a verdict check at the moment of click using Microsoft's threat intelligence. This time-of-click protection means that even if a URL was previously benign, it can be re-evaluated and blocked as soon as the user clicks. Safe Links extends beyond email to Teams, Office documents, and other supported workloads, making it the dedicated mechanism for URL-based threats.
- ✗
Anti-spam policy
Why it's wrong here
An anti-spam policy is designed to filter unsolicited commercial email by applying scoring based on content filters, blocklists, and allowlists; it may flag phishing-like spam but does not perform per-URL or per-link malicious URL inspection. Its primary purpose is to classify messages as spam, bulk, or high-confidence spam and route them to the Junk Email folder, not to provide a click-time safety mechanism for links. Relying on this policy alone would not stop a malicious link from being delivered and clicked.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.