Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Defender for Office 365. You need to protect users from malicious links in emails. What should you configure?

⚠ Common exam trap

Watch out — candidates often confuse Safe Links with Safe Attachments, but Safe Attachments handles file payloads (attachments) while Safe Links handles URL payloads (links) — a common misconception that leads to selecting the wrong policy for link protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Safe Links policy

Safe Links policy is the correct answer because it specifically protects users from malicious links in emails by scanning URLs at the time of click, checking against Microsoft's threat intelligence, and optionally rewriting links to route clicks through the Safe Links service. This is the dedicated Defender for Office 365 feature designed to mitigate link-based attacks in email messages.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anti-malware policy

    Why it's wrong here

    Anti-malware policies in Defender for Office 365 scan email bodies and attachments for known malware signatures and heuristics, using engines like the Malware Engine. They do not inspect or rewrite URLs within the message, and they lack the click-time verdict capability that Safe Links provides. As a result, an email containing a malicious link would not be blocked by an anti-malware policy, because the policy never evaluates the link's target.

  • ✓

    Safe Links policy

    Why this is correct

    Safe Links is the dedicated protection feature for URLs, automatically applying URL rewriting and time-of-click checks in Microsoft 365. When a user clicks a link, Safe Links verifies the destination against the latest threat intelligence and blocks or warns if it leads to a malicious site, even if the link initially looked benign. This is precisely the control that fulfills a requirement for malicious link protection at click time.

  • ✗

    Anti-phishing policy

    Why it's wrong here

    Anti-phishing policies are designed to detect phishing attempts through sender spoofing, user impersonation, and mailbox intelligence, but they do not perform link scanning or rewriting. They may flag a message as phishing based on its content and sender reputation, yet they lack the ability to analyze the URL at the moment of click. Therefore, while they provide complementary email security, they are not the technical solution for protecting users from clicking malicious links.

  • ✗

    Safe Attachments policy

    Why it's wrong here

    Safe Attachments protects against malware delivered via email attachments by detonating files in a high-fidelity sandbox and inspecting their behavior. It does not inspect Uniform Resource Locators (URLs) inside the email text, nor does it perform any click-time evaluation. Since the requirement is specifically about links and not attachments, this policy is an incorrect choice for the stated protection.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.