SC-200 Respond to security incidents Practice Question
Your company uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the default policy. The email contains an external link to a credential harvesting site. You need to block similar emails in the future. What should you do?
⚠ Common exam trap
Candidates often confuse the Tenant Allow/Block List (which is for sender/domain/IP blocking) with the Safe Links blocked URLs list (which is for URL-level blocking), leading them to choose option D instead of B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Safe Links policy and add the malicious domain to the blocked URLs list.
The phishing email contains a link to a credential harvesting site, so the most direct way to block similar emails in the future is to use a Safe Links policy. Safe Links proactively scans and blocks URLs at time of click, and you can add the malicious domain to the blocked URLs list to prevent users from accessing that site. This addresses the specific threat vector (malicious URL) rather than the sender's domain or attachment type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an anti-spam policy to block the sender's domain.
Why it's wrong here
Anti-spam policies in Exchange Online Protection evaluate message characteristics such as sender reputation, content, bulk-mail settings, and sending patterns to assign a spam verdict. Blocking the sender's domain through such a policy only affects mail originating from that specific domain; it does nothing to neutralize a malicious URL embedded in the message, and attackers can simply pivot to another sending domain or a compromised legitimate domain. URL-level protection requires a policy that inspects hyperlinks at click time, which Safe Links provides.
- ✓
Create a Safe Links policy and add the malicious domain to the blocked URLs list.
Why this is correct
Safe Links policies are specifically designed to protect users from malicious hyperlinks by rewriting URLs and checking them against Microsoft's threat intelligence plus your custom block list. Adding the malicious domain to the blocked URLs list causes any link containing that domain to be blocked or to trigger a warning when clicked, even if the email's sender appears benign. This directly addresses the attack vector—the embedded URL—rather than the email's origin, making it the correct control.
- ✗
Create an anti-malware policy to block the attachment type.
Why it's wrong here
Anti-malware policies in Defender for Office 365 scan email attachments for file-based threats, including known malware signatures and behavior during detonation, but they cannot inspect or act on hyperlinks embedded directly in the message body. Because a malicious URL is not an attachment, the anti-malware engine never evaluates it, so this policy would leave the user fully exposed to the link. Safe Links is the feature that provides URL reputation and click-time protection.
- ✗
Add the sender's domain to the Tenant Allow/Block List.
Why it's wrong here
The Tenant Allow/Block List is a transport-level allow/deny mechanism that governs mail flow based on sender, domain, or spoofed identity; adding the sender's domain there would block or suppress all mail from that domain. However, the attack is the malicious link itself, which could originate from an unlisted domain or a legitimate but compromised sender, so the block list entry would not remove the dangerous URL from messages that do arrive. Safe Links is the right control because it evaluates the URL object, not the sender identity, and can enforce protection on every link regardless of where the mail came from.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.