Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft 365. The security team wants to protect users from clicking malicious URLs in email messages. The solution should rewrite all links in incoming emails so that when a user clicks them, the URL is checked in real time against a dynamic list of known malicious sites. Which Microsoft Defender for Office 365 feature should they enable?

⚠ Common exam trap

Watch out — candidates often confuse Safe Links with Anti-phishing policies, but Anti-phishing policies handle impersonation and spoofing detection, not URL rewriting and real-time click verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Safe Links

Safe Links is the correct feature because it is specifically designed to protect users from malicious URLs in email messages and Office documents. It rewrites all links in incoming emails so that when a user clicks them, the URL is checked in real time against a dynamic list of known malicious sites, providing time-of-click protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Anti-phishing policies

    Why it's wrong here

    Anti-phishing policies in Microsoft Defender for Office 365 are designed to protect against impersonation attacks by detecting spoofed senders, impersonated users, and brand impersonation attempts. These policies leverage machine learning and sender intelligence to analyze email headers and content for signs of deceptive identity. Unlike Safe Links, anti-phishing policies do not perform dynamic URL rewriting or time-of-click scanning; their focus is on preventing identity-based deception before delivery.

    When this WOULD be correct

    An exam question asks: 'Which Microsoft Defender for Office 365 feature should be configured to block users from entering credentials on a fake login page that mimics a trusted site?' In that scenario, anti-phishing policies with impersonation protection would be correct.

  • Safe Attachments

    Why it's wrong here

    Safe Attachments is a feature within Microsoft Defender for Office 365 that provides advanced protection against zero-day malware in email attachments. It detonates suspicious attachments in a secure, isolated virtual environment (sandbox) to analyze their behavior for malicious activity before they reach the user's inbox. This process specifically targets file-based threats and does not extend to scanning or rewriting embedded URLs within the email body or document content.

    When this WOULD be correct

    Safe Attachments would be correct if the question asked for a feature that scans email attachments for malware by opening them in a virtual environment before delivery, or if the requirement was to block malicious files in email and SharePoint.

  • Safe Links

    Why this is correct

    Safe Links is a critical component of Microsoft Defender for Office 365 that provides time-of-click protection against malicious URLs. It dynamically rewrites URLs in emails and Office documents, then scans them in real-time when a user clicks, blocking access to known malicious sites or warning the user if the link's destination has changed to become malicious since initial delivery. This proactive scanning helps prevent users from accessing compromised websites, even if the link was initially benign.

  • Anti-spam policies

    Why it's wrong here

    Anti-spam policies primarily focus on identifying and filtering unsolicited bulk email, phishing attempts, and malware based on sender reputation, content analysis, and real-time block lists. While these policies reduce the overall volume of malicious emails reaching user inboxes, they do not perform dynamic, per-click URL scanning within emails that successfully bypass initial spam filters. Their core function is pre-delivery filtering, not post-delivery link validation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Safe LinksCorrect answer

Why this is correct

Safe Links is a critical component of Microsoft Defender for Office 365 that provides time-of-click protection against malicious URLs. It dynamically rewrites URLs in emails and Office documents, then scans them in real-time when a user clicks, blocking access to known malicious sites or warning the user if the link's destination has changed to become malicious since initial delivery. This proactive scanning helps prevent users from accessing compromised websites, even if the link was initially benign.

Anti-phishing policiesWrong answer — click to see why

Why this is wrong here

Anti-phishing policies protect against phishing attempts by analyzing email content and sender reputation, but they do not rewrite URLs or perform real-time link checking against a dynamic list of malicious sites.

★ When this WOULD be the correct answer

An exam question asks: 'Which Microsoft Defender for Office 365 feature should be configured to block users from entering credentials on a fake login page that mimics a trusted site?' In that scenario, anti-phishing policies with impersonation protection would be correct.

Why candidates choose this

Candidates may confuse anti-phishing policies with Safe Links because both deal with malicious URLs, but anti-phishing focuses on the email content and sender, not on rewriting and real-time URL scanning.

Safe AttachmentsWrong answer — click to see why

Why this is wrong here

Safe Attachments protects against malicious attachments by detonating them in a sandbox, not by rewriting and checking URLs in real time. The question specifically requires URL rewriting and real-time link checking, which is the function of Safe Links.

★ When this WOULD be the correct answer

Safe Attachments would be correct if the question asked for a feature that scans email attachments for malware by opening them in a virtual environment before delivery, or if the requirement was to block malicious files in email and SharePoint.

Why candidates choose this

Candidates may confuse Safe Attachments with Safe Links because both are part of Microsoft Defender for Office 365 and deal with malicious content, but they target different threat vectors: attachments vs. links.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.