Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization uses Microsoft Defender for Office 365 to protect against phishing attacks. The security team wants to implement a custom advanced phishing threshold policy that blocks suspicious emails more aggressively. Which policy type should they modify?

⚠ Common exam trap

A common mix-up: candidates confuse the outdated 'ATP policy' term with the modern anti-phishing policy, or they mistakenly think Safe Attachments or Safe Links control phishing thresholds, when in fact only the anti-phishing policy contains the Advanced Phishing Threshold settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anti-phishing policy

The Anti-phishing policy in Microsoft Defender for Office 365 includes the Advanced Phishing Threshold (APT) settings that allow administrators to control the aggressiveness of phishing detection. By modifying the anti-phishing policy, you can set the phishing threshold to 'Aggressive' or 'Most Aggressive,' which applies more stringent machine learning models to block suspicious emails earlier. This is the correct policy type because it directly governs the phishing threshold level, not attachment or link scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ATP policy

    Why it's wrong here

    The term 'ATP policy' is an outdated reference to the Advanced Threat Protection feature set now branded as Microsoft Defender for Office 365. The portal does not expose a policy object named ATP; instead, the specific policies are anti-phishing, anti-malware, anti-spam, Safe Links, and Safe Attachments. Configuring phishing threshold levels requires selecting the anti-phishing policy, not a generic ATP policy.

  • ✗

    Safe Attachments policy

    Why it's wrong here

    Safe Attachments Policy governs the detonation and inspection of email attachments in a sandboxed environment, protecting against malware payloads. It does not control the overall signal that determines whether a message is categorized as phishing, nor does it expose threshold settings for phishing confidence levels. The advanced phishing threshold is a separate setting within anti-phishing policies, so selecting Safe Attachments would be incorrect for this requirement.

  • ✗

    Safe Links policy

    Why it's wrong here

    Safe Links policy provides time-of-click URL scanning and rewriting to block malicious links at the moment a user clicks, but it is not the mechanism that evaluates an email's risk as phishing. The phishing threshold setting that adjusts how aggressively the filtering engine flags emails as phishing is exclusively configured in anti-phishing policies. Therefore, Safe Links does not offer the required overall phishing sensitivity adjustment.

  • ✓

    Anti-phishing policy

    Why this is correct

    Anti-phishing policies in Microsoft Defender for Office 365 contain the 'Phishing email threshold' setting, which adjusts the sensitivity of the machine-learning models that detect phishing attempts. These policies also include features like impersonation protection, mailbox intelligence, and spoof intelligence, all relevant to phishing defense. This is the correct policy selection because it directly modifies the advanced threshold that controls how many phishing candidates are flagged.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.