SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Defender for Office 365. You need to protect users from malicious links in emails. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse Safe Links with Safe Attachments, but Safe Attachments handles file payloads (attachments) while Safe Links handles URL payloads (links) — a common misconception that leads to selecting the wrong policy for link protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Links policy
Safe Links policy is the correct answer because it specifically protects users from malicious links in emails by scanning URLs at the time of click, checking against Microsoft's threat intelligence, and optionally rewriting links to route clicks through the Safe Links service. This is the dedicated Defender for Office 365 feature designed to mitigate link-based attacks in email messages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anti-malware policy
Why it's wrong here
Anti-malware policies in Defender for Office 365 scan email bodies and attachments for known malware signatures and heuristics, using engines like the Malware Engine. They do not inspect or rewrite URLs within the message, and they lack the click-time verdict capability that Safe Links provides. As a result, an email containing a malicious link would not be blocked by an anti-malware policy, because the policy never evaluates the link's target.
- ✓
Safe Links policy
Why this is correct
Safe Links is the dedicated protection feature for URLs, automatically applying URL rewriting and time-of-click checks in Microsoft 365. When a user clicks a link, Safe Links verifies the destination against the latest threat intelligence and blocks or warns if it leads to a malicious site, even if the link initially looked benign. This is precisely the control that fulfills a requirement for malicious link protection at click time.
- ✗
Anti-phishing policy
Why it's wrong here
Anti-phishing policies are designed to detect phishing attempts through sender spoofing, user impersonation, and mailbox intelligence, but they do not perform link scanning or rewriting. They may flag a message as phishing based on its content and sender reputation, yet they lack the ability to analyze the URL at the moment of click. Therefore, while they provide complementary email security, they are not the technical solution for protecting users from clicking malicious links.
- ✗
Safe Attachments policy
Why it's wrong here
Safe Attachments protects against malware delivered via email attachments by detonating files in a high-fidelity sandbox and inspecting their behavior. It does not inspect Uniform Resource Locators (URLs) inside the email text, nor does it perform any click-time evaluation. Since the requirement is specifically about links and not attachments, this policy is an incorrect choice for the stated protection.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.