SC-100 Design security solutions for infrastructure Practice Question
Your organization uses Microsoft Defender for Office 365. You need to design a solution to protect users from malicious links in email. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Links policy
Safe Links policy (option C) is correct because it is the Defender for Office 365 feature that rewrites and time-of-click verifies URLs in email (and Teams/Office apps), blocking malicious links at delivery and after delivery. This directly addresses the requirement to protect users from malicious links in email. Anti-spam policy (A) filters spam and bulk mail but does not detonate or rewrite URLs for malicious link protection. Safe Attachments policy (B) detonates attachments in a sandbox, not links. Anti-phishing policy (D) covers impersonation and spoofing protections, not URL rewriting/blocking of malicious links.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anti-spam policy
Why it's wrong here
The anti-spam policy is the wrong choice because it evaluates inbound messages for bulk mail, spoofing, and spam indicators using message reputation and header analysis. It does not perform URL reputation checks or time-of-click protection on links embedded in messages. Malicious URL blocking is the distinct function of Safe Links, not anti-spam.
- ✗
Safe Attachments policy
Why it's wrong here
Safe Attachments is not the correct policy because it focuses on email attachments by routing them through a virtual sandbox to detect malware and then delivering or quarantining the message accordingly. It does not inspect every hyperlink in the email body for verdicts at delivery or rewrite URLs. A link inside a benign attachment could still escape this policy, as Safe Attachments does not scrub the message text.
- ✓
Safe Links policy
Why this is correct
The Safe Links policy is the correct answer because it provides time-of-click URL protection by rewriting links in email messages to point to Microsoft's safety checking service, and it can also scan URLs in Teams and Office apps. When a user clicks a rewritten link, the service checks the URL against real-time threat intelligence and blocks navigation if it is malicious. This ensures that even URLs that look benign at delivery are protected.
- ✗
Anti-phishing policy
Why it's wrong here
The anti-phishing policy is wrong here because it is designed to detect impersonation attempts, such as spoofed senders, lookalike domains, and fraudulent user identities, using machine learning and impersonation heuristics. While these policies can be configured to take actions on suspected phishing messages, they do not systematically protect, rewrite, or block individual URLs at point of click in the same way Safe Links does. Their primary focus is the identity and domain reputation behind a message, not the hyperlinks inside it.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.