Courseiva
Respond to security incidentshardMultiple ChoiceObjective-mapped

SC-200 Respond to security incidents Practice Question

You are investigating an incident where a user reported receiving a suspicious email with a malicious attachment. Microsoft Defender for Office 365 did not block it. The email originated from a known malicious sender domain. What configuration should you check first?

⚠ Common exam trap

Many candidates confuse the anti-phishing policy with Safe Attachments or SPF records, but the anti-phishing policy is the correct first check because it directly handles domain-based threats and spoofing, while Safe Attachments focuses on file analysis and SPF is a DNS record not configurable within Defender.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Anti-phishing policy in Microsoft Defender for Office 365

The anti-phishing policy in Microsoft Defender for Office 365 is the primary configuration that evaluates sender reputation, impersonation attempts, and spoof intelligence. Since the email originated from a known malicious sender domain and was not blocked, the anti-phishing policy's spoof settings or impersonation protection may be misconfigured or not applied to the affected user. This policy directly controls how Defender handles emails from malicious domains, making it the first place to check.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • User-reported message settings

    Why it's wrong here

    User-reported message settings in Microsoft Defender for Office 365 configure how users submit suspicious messages to the admin Submissions portal for analysis. They do not define any inbound filtering or block actions for email delivery, so they cannot be the policy that prevented the message from reaching the inbox. This setting only affects the reporting experience and workflow, not the actual safety of the email.

  • SPF record for the sender domain

    Why it's wrong here

    SPF (Sender Policy Framework) is an email authentication protocol that verifies that the sending server is authorized to send on behalf of the sender's domain, typically via a DNS TXT record. Even if the SPF check fails due to domain spoofing, the message may still be delivered to Junk or marked with a composite authentication result; SPF alone does not enforce a blocking action based on domain reputation. The anti-phishing policy uses threat intelligence and impersonation protection to actively block or quarantine such messages, which is beyond SPF's scope.

  • Safe Attachments policy

    Why it's wrong here

    Safe Attachments policy in Microsoft Defender for Office 365 detonates email attachments in a sandbox environment and blocks messages when malware is detected in the attachment payload. However, it does not analyze the sender domain's reputation or detect impersonation attempts where the domain name is spoofed to appear legitimate but contains no malicious attachment. Since the incident involves a phishing message that was blocked based on domain reputation, the Safe Attachments policy would not be the specific control responsible for that action.

  • Anti-phishing policy in Microsoft Defender for Office 365

    Why this is correct

    Anti-phishing policy in Microsoft Defender for Office 365 is the correct control because it provides domain impersonation protection and spoof intelligence that can identify and block messages from known malicious domains or those mimicking protected senders. It leverages threat intelligence and real-time reputation to enforce blocking, quarantine, or redirect to Junk before delivery to the user's inbox. This policy is specifically designed to combat phishing and impersonation, which aligns with the reported incident involving a suspicious email.

About these practice questions

This SC-200 question is part of Courseiva's 1,235-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.