SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Microsoft 365 E5 and is concerned about advanced phishing attacks that use adversary-in-the-middle (AiTM) techniques to steal session cookies and bypass multifactor authentication. Which Microsoft Defender for Office 365 feature should they configure to specifically protect against this type of attack?
⚠ Common exam trap
Many candidates confuse Safe Links (which protects against malicious URLs) with the broader anti-phishing protection needed for AiTM attacks, not realizing that AiTM attacks exploit the authentication process itself rather than just the URL, requiring advanced impersonation and proxy detection capabilities found only in anti-phishing policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anti-Phishing (advanced policies)
Advanced anti-phishing policies in Defender for Office 365 include protection against adversary-in-the-middle (AiTM) attacks by using machine learning models and impersonation detection to analyze and block phishing attempts that aim to steal session cookies and bypass multifactor authentication. This feature specifically detects and mitigates sophisticated phishing techniques that traditional anti-spam or link-checking mechanisms might miss, such as real-time credential harvesting and session hijacking via proxy servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Safe Attachments
Why it's wrong here
Safe Attachments is a feature within Microsoft Defender for Office 365 that protects against unknown malware and zero-day viruses by routing email attachments through a sandbox environment. It detonates the attachments in a virtual machine to analyze their behavior before they reach the user's inbox. While effective against malicious files, this protection mechanism does not directly address adversary-in-the-middle (AiTM) phishing attacks, which focus on stealing session cookies or credentials through spoofed login pages rather than delivering malicious attachments.
- ✗
Safe Links
Why it's wrong here
Safe Links provides time-of-click protection by rewriting URLs in emails and Office documents, then scanning them to block access to known malicious websites. When a user clicks a link, Safe Links checks its reputation in real-time and prevents navigation to unsafe destinations. However, this feature primarily defends against direct access to malicious sites and is not specifically designed to detect or prevent the sophisticated real-time proxying of authentication requests and session token theft that characterizes advanced AiTM phishing techniques.
- ✓
Anti-Phishing (advanced policies)
Why this is correct
Advanced anti-phishing policies in Microsoft Defender for Office 365 are specifically engineered to detect and mitigate sophisticated phishing attacks, including adversary-in-the-middle (AiTM) threats. These policies leverage machine learning, behavioral analysis, and real-time signal detection to identify anomalous authentication flows, suspicious login patterns, and impersonation attempts. By analyzing various indicators, these advanced controls can effectively block phishing campaigns aimed at hijacking user sessions or stealing credentials via proxying techniques.
- ✗
Campaign Views
Why it's wrong here
Campaign Views is an investigative and reporting tool within Microsoft Defender for Office 365 that provides a consolidated overview of phishing and malware campaigns targeting an organization. It aggregates data to help security teams understand the scope, impact, and attack vectors of specific threats. While invaluable for post-incident analysis and threat intelligence, Campaign Views does not offer active, real-time protection or preventative measures against ongoing AiTM attacks; its function is purely analytical and informational.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Multifactor Authentication
Multifactor Authentication (MFA) is a security method that requires you to provide two or more pieces of evidence to prove your identity before accessing an account or system.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.