Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC uses Microsoft Defender for Office 365. You need to configure a policy that automatically moves malicious email attachments to quarantine before they reach user mailboxes. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse anti-malware policies (which use static signatures) with Safe Attachments (which uses dynamic sandbox analysis), leading them to select Option C instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Safe Attachments policy in the Microsoft 365 Defender portal.

Safe Attachments is a Microsoft Defender for Office 365 feature specifically designed to detonate email attachments in a virtual sandbox environment before delivery. By creating a Safe Attachments policy in the Microsoft 365 Defender portal, you can automatically quarantine malicious attachments, preventing them from reaching user mailboxes. This directly addresses the requirement to handle malicious attachments, not phishing or spam.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an anti-phishing policy to detect phishing attempts.

    Why it's wrong here

    An anti-phishing policy in Defender for Office 365 is designed to detect and mitigate phishing attempts by analyzing URL reputation, sender spoofing (e.g., domain impersonation), and user impersonation patterns. Although phishing emails often contain malicious attachments, this policy component does not perform attachment detonation or file-level malware analysis. It may block or rewrite phishing URLs, but the actual attachment is not scrutinized in a sandbox environment. Since the requirement is to handle malicious attachments specifically, an anti-phishing policy alone is insufficient.

  • ✗

    Create an anti-spam policy with a high confidence spam filter.

    Why it's wrong here

    An anti-spam policy with a high confidence spam filter primarily focuses on classifying messages as spam based on message reputation, content patterns, and sender or domain characteristics. It can quarantine bulk email, phishing-like spam, or messages with a high spam confidence level, but it does not detonate or deeply inspect attachments for malware or zero-day threats. The filter evaluates the overall message classification, not the file contents, so malicious files attached to a non-spam email would likely pass through. Therefore, this policy is not the correct mechanism for attachment-level malicious content detection.

  • ✗

    Create an anti-malware policy in the Microsoft 365 Defender portal.

    Why it's wrong here

    A standard anti-malware policy in Microsoft 365 Defender applies signature-based and heuristic scanning to email attachments, identifying known malware by matching file hashes or structural characteristics. However, it lacks the dynamic detonation capability that Safe Attachments provides for analyzing unknown, zero-day malware in a isolated sandbox environment. Anti-malware policies may also allow administrator-defined rules for malware types, but they do not trigger file-level detonation or deep behavioral analysis. For robust protection against sophisticated attachments that evade static signatures, a Safe Attachments policy is required.

  • ✓

    Create a Safe Attachments policy in the Microsoft 365 Defender portal.

    Why this is correct

    A Safe Attachments policy in the Microsoft 365 Defender portal is the correct solution because it is specifically designed to handle email attachments by routing them through a detonation sandbox. When an email has an attachment that matches policy conditions, the attachment is opened in a virtualized environment to observe its behavior, and the verdict (malicious or benign) determines whether the message is delivered or quarantined. Safe Attachments provides zero-day protection against malware that traditional signature-based scanning misses, and it integrates with other Defender for Office 365 features like time-of-click protection. This policy directly addresses the requirement to quarantine malicious attachments.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.