An organization uses Microsoft Defender for Office 365. The security team wants to automatically remove from all user mailboxes any messages that were already delivered but are later identified as malicious. Which feature should they enable?
Zero-hour auto purge (ZAP) is a Defender for Office 365 feature that retroactively identifies and acts on messages already delivered to a user's mailbox when they are later found to be phishing, malware, or spam. It automatically moves those messages to quarantine or the junk email folder, or deletes them, depending on the configured policy, effectively closing the gap when detection occurs post-delivery.
Why this answer
Zero-hour auto purge (ZAP) is the correct feature because it automatically detects and removes malicious messages that have already been delivered to user mailboxes, including messages retroactively identified as threats after delivery. ZAP acts on phishing, malware, and spam verdicts by querying the mailbox for the original message and moving it to the Junk Email folder or deleting it, based on the configured policy. This directly meets the requirement to remove already-delivered malicious messages without manual intervention.
Exam trap
The trap here is that candidates confuse ZAP with Safe Attachments or Safe Links, mistakenly thinking those features can retroactively remove delivered messages, when in fact they only protect at the time of delivery or click, respectively.
How to eliminate wrong answers
Option A is wrong because Automated investigation and response (AIR) is a broader incident response capability that orchestrates playbooks across multiple workloads, but it does not automatically remove already-delivered messages from mailboxes; it focuses on investigating and remediating threats at the mailbox or device level after an alert is triggered. Option C is wrong because Safe Attachments is a time-of-delivery protection feature that detonates email attachments in a sandbox before delivery, but it does not retroactively remove messages that were already delivered and later found malicious. Option D is wrong because Safe Links is a time-of-click protection feature that scans URLs in messages and Office documents at the moment a user clicks, but it does not remove already-delivered messages from mailboxes.