Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization uses Microsoft Defender for Office 365. You need to design a solution to protect users from malicious links in email. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Safe Links policy

Safe Links policy (option C) is correct because it is the Defender for Office 365 feature that rewrites and time-of-click verifies URLs in email (and Teams/Office apps), blocking malicious links at delivery and after delivery. This directly addresses the requirement to protect users from malicious links in email. Anti-spam policy (A) filters spam and bulk mail but does not detonate or rewrite URLs for malicious link protection. Safe Attachments policy (B) detonates attachments in a sandbox, not links. Anti-phishing policy (D) covers impersonation and spoofing protections, not URL rewriting/blocking of malicious links.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anti-spam policy

    Why it's wrong here

    The anti-spam policy is the wrong choice because it evaluates inbound messages for bulk mail, spoofing, and spam indicators using message reputation and header analysis. It does not perform URL reputation checks or time-of-click protection on links embedded in messages. Malicious URL blocking is the distinct function of Safe Links, not anti-spam.

  • ✗

    Safe Attachments policy

    Why it's wrong here

    Safe Attachments is not the correct policy because it focuses on email attachments by routing them through a virtual sandbox to detect malware and then delivering or quarantining the message accordingly. It does not inspect every hyperlink in the email body for verdicts at delivery or rewrite URLs. A link inside a benign attachment could still escape this policy, as Safe Attachments does not scrub the message text.

  • ✓

    Safe Links policy

    Why this is correct

    The Safe Links policy is the correct answer because it provides time-of-click URL protection by rewriting links in email messages to point to Microsoft's safety checking service, and it can also scan URLs in Teams and Office apps. When a user clicks a rewritten link, the service checks the URL against real-time threat intelligence and blocks navigation if it is malicious. This ensures that even URLs that look benign at delivery are protected.

  • ✗

    Anti-phishing policy

    Why it's wrong here

    The anti-phishing policy is wrong here because it is designed to detect impersonation attempts, such as spoofed senders, lookalike domains, and fraudulent user identities, using machine learning and impersonation heuristics. While these policies can be configured to take actions on suspected phishing messages, they do not systematically protect, rewrite, or block individual URLs at point of click in the same way Safe Links does. Their primary focus is the identity and domain reputation behind a message, not the hyperlinks inside it.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.