Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft 365 E5 and is concerned about advanced phishing attacks that use adversary-in-the-middle (AiTM) techniques to steal session cookies and bypass multifactor authentication. Which Microsoft Defender for Office 365 feature should they configure to specifically protect against this type of attack?

⚠ Common exam trap

Many candidates confuse Safe Links (which protects against malicious URLs) with the broader anti-phishing protection needed for AiTM attacks, not realizing that AiTM attacks exploit the authentication process itself rather than just the URL, requiring advanced impersonation and proxy detection capabilities found only in anti-phishing policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Anti-Phishing (advanced policies)

Advanced anti-phishing policies in Defender for Office 365 include protection against adversary-in-the-middle (AiTM) attacks by using machine learning models and impersonation detection to analyze and block phishing attempts that aim to steal session cookies and bypass multifactor authentication. This feature specifically detects and mitigates sophisticated phishing techniques that traditional anti-spam or link-checking mechanisms might miss, such as real-time credential harvesting and session hijacking via proxy servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Safe Attachments

    Why it's wrong here

    Safe Attachments is a feature within Microsoft Defender for Office 365 that protects against unknown malware and zero-day viruses by routing email attachments through a sandbox environment. It detonates the attachments in a virtual machine to analyze their behavior before they reach the user's inbox. While effective against malicious files, this protection mechanism does not directly address adversary-in-the-middle (AiTM) phishing attacks, which focus on stealing session cookies or credentials through spoofed login pages rather than delivering malicious attachments.

  • Safe Links

    Why it's wrong here

    Safe Links provides time-of-click protection by rewriting URLs in emails and Office documents, then scanning them to block access to known malicious websites. When a user clicks a link, Safe Links checks its reputation in real-time and prevents navigation to unsafe destinations. However, this feature primarily defends against direct access to malicious sites and is not specifically designed to detect or prevent the sophisticated real-time proxying of authentication requests and session token theft that characterizes advanced AiTM phishing techniques.

  • Anti-Phishing (advanced policies)

    Why this is correct

    Advanced anti-phishing policies in Microsoft Defender for Office 365 are specifically engineered to detect and mitigate sophisticated phishing attacks, including adversary-in-the-middle (AiTM) threats. These policies leverage machine learning, behavioral analysis, and real-time signal detection to identify anomalous authentication flows, suspicious login patterns, and impersonation attempts. By analyzing various indicators, these advanced controls can effectively block phishing campaigns aimed at hijacking user sessions or stealing credentials via proxying techniques.

  • Campaign Views

    Why it's wrong here

    Campaign Views is an investigative and reporting tool within Microsoft Defender for Office 365 that provides a consolidated overview of phishing and malware campaigns targeting an organization. It aggregates data to help security teams understand the scope, impact, and attack vectors of specific threats. While invaluable for post-incident analysis and threat intelligence, Campaign Views does not offer active, real-time protection or preventative measures against ongoing AiTM attacks; its function is purely analytical and informational.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.