SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization uses Microsoft Defender for Office 365 to protect against phishing attacks. The security team wants to implement a custom advanced phishing threshold policy that blocks suspicious emails more aggressively. Which policy type should they modify?
⚠ Common exam trap
A common mix-up: candidates confuse the outdated 'ATP policy' term with the modern anti-phishing policy, or they mistakenly think Safe Attachments or Safe Links control phishing thresholds, when in fact only the anti-phishing policy contains the Advanced Phishing Threshold settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anti-phishing policy
The Anti-phishing policy in Microsoft Defender for Office 365 includes the Advanced Phishing Threshold (APT) settings that allow administrators to control the aggressiveness of phishing detection. By modifying the anti-phishing policy, you can set the phishing threshold to 'Aggressive' or 'Most Aggressive,' which applies more stringent machine learning models to block suspicious emails earlier. This is the correct policy type because it directly governs the phishing threshold level, not attachment or link scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ATP policy
Why it's wrong here
The term 'ATP policy' is an outdated reference to the Advanced Threat Protection feature set now branded as Microsoft Defender for Office 365. The portal does not expose a policy object named ATP; instead, the specific policies are anti-phishing, anti-malware, anti-spam, Safe Links, and Safe Attachments. Configuring phishing threshold levels requires selecting the anti-phishing policy, not a generic ATP policy.
- ✗
Safe Attachments policy
Why it's wrong here
Safe Attachments Policy governs the detonation and inspection of email attachments in a sandboxed environment, protecting against malware payloads. It does not control the overall signal that determines whether a message is categorized as phishing, nor does it expose threshold settings for phishing confidence levels. The advanced phishing threshold is a separate setting within anti-phishing policies, so selecting Safe Attachments would be incorrect for this requirement.
- ✗
Safe Links policy
Why it's wrong here
Safe Links policy provides time-of-click URL scanning and rewriting to block malicious links at the moment a user clicks, but it is not the mechanism that evaluates an email's risk as phishing. The phishing threshold setting that adjusts how aggressively the filtering engine flags emails as phishing is exclusively configured in anti-phishing policies. Therefore, Safe Links does not offer the required overall phishing sensitivity adjustment.
- ✓
Anti-phishing policy
Why this is correct
Anti-phishing policies in Microsoft Defender for Office 365 contain the 'Phishing email threshold' setting, which adjusts the sensitivity of the machine-learning models that detect phishing attempts. These policies also include features like impersonation protection, mailbox intelligence, and spoof intelligence, all relevant to phishing defense. This is the correct policy selection because it directly modifies the advanced threshold that controls how many phishing candidates are flagged.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.