SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Office 365. You need to configure a policy that automatically moves emails detected as 'Bulk' to the user's Junk Email folder. However, users must be able to override this by adding the sender to their Safe Senders list. What should you configure?
⚠ Common exam trap
Candidates often confuse anti-spam policies with anti-phishing policies, assuming phishing protection handles bulk email, but only anti-spam policies contain the Bulk email threshold setting that interacts with the user's Safe Senders list.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anti-spam policy with Bulk email threshold set to a value that triggers junk action
The Bulk email threshold setting in an anti-spam policy allows you to specify a Bulk Complaint Level (BCL) value that, when exceeded, triggers a specific action such as moving the email to the Junk Email folder. This action respects the user's Safe Senders list, meaning if the sender is added to that list, the email will bypass the junk folder and be delivered to the inbox. Other policy types like anti-phishing, malware filter, or connection filter do not provide this granular control over bulk email classification and user override behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Anti-spam policy with Bulk email threshold set to a value that triggers junk action
Why this is correct
This is the correct control because sender complaint data produces a Bulk Complaint Level (BCL) from 0 to 9 for each inbound message, and the anti-spam policy's bulk email threshold routes messages that exceed that BCL to the Junk Email folder. A lower threshold value, such as 6, classifies more senders as bulk and makes the action increasingly aggressive. Safe Senders and Safe Lists can override this action for trusted senders, but no other policy in Microsoft Defender for Office 365 applies BCL thresholds.
- ✗
Anti-phishing policy
Why it's wrong here
Anti-phishing policies are purpose-built for different threats: spoofing, display-name impersonation, domain impersonation, and mailbox intelligence. They do not inspect or act on bulk complaint levels, and a phishing message is typically a single, targeted attack that does not carry a bulk sender reputation. Adjusting an anti-phishing policy will therefore have zero effect on how marketing or bulk email is classified, so it cannot meet the requirement.
- ✗
Malware filter policy
Why it's wrong here
The malware filter (anti-malware) policy examines attachments, links, and file signatures, then applies quarantine or block actions for known and zero-day malware. Bulk email classification depends on complaint-rate statistics, not on payload analysis, and most bulk messages contain no malicious content at all. Since the anti-malware policy has no BCL setting and does not evaluate bulk sender reputation, it is the wrong policy to change.
- ✗
Connection filter policy
Why it's wrong here
The connection filter policy makes allow and deny decisions based on IP address reputation using Microsoft's connection filter list and per-sender IP entries. It operates at the transport edge before message content is analyzed, and it never calculates or reads BCL values. Because it acts only at the network connection layer, it cannot set any threshold that would trigger a junk action for bulk email.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.