SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Microsoft 365. The security team wants to protect users from clicking malicious URLs in email messages. The solution should rewrite all links in incoming emails so that when a user clicks them, the URL is checked in real time against a dynamic list of known malicious sites. Which Microsoft Defender for Office 365 feature should they enable?
⚠ Common exam trap
Watch out — candidates often confuse Safe Links with Anti-phishing policies, but Anti-phishing policies handle impersonation and spoofing detection, not URL rewriting and real-time click verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Links
Safe Links is the correct feature because it is specifically designed to protect users from malicious URLs in email messages and Office documents. It rewrites all links in incoming emails so that when a user clicks them, the URL is checked in real time against a dynamic list of known malicious sites, providing time-of-click protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anti-phishing policies
Why it's wrong here
Anti-phishing policies in Microsoft Defender for Office 365 are designed to protect against impersonation attacks by detecting spoofed senders, impersonated users, and brand impersonation attempts. These policies leverage machine learning and sender intelligence to analyze email headers and content for signs of deceptive identity. Unlike Safe Links, anti-phishing policies do not perform dynamic URL rewriting or time-of-click scanning; their focus is on preventing identity-based deception before delivery.
When this WOULD be correct
An exam question asks: 'Which Microsoft Defender for Office 365 feature should be configured to block users from entering credentials on a fake login page that mimics a trusted site?' In that scenario, anti-phishing policies with impersonation protection would be correct.
- ✗
Safe Attachments
Why it's wrong here
Safe Attachments is a feature within Microsoft Defender for Office 365 that provides advanced protection against zero-day malware in email attachments. It detonates suspicious attachments in a secure, isolated virtual environment (sandbox) to analyze their behavior for malicious activity before they reach the user's inbox. This process specifically targets file-based threats and does not extend to scanning or rewriting embedded URLs within the email body or document content.
When this WOULD be correct
Safe Attachments would be correct if the question asked for a feature that scans email attachments for malware by opening them in a virtual environment before delivery, or if the requirement was to block malicious files in email and SharePoint.
- ✓
Safe Links
Why this is correct
Safe Links is a critical component of Microsoft Defender for Office 365 that provides time-of-click protection against malicious URLs. It dynamically rewrites URLs in emails and Office documents, then scans them in real-time when a user clicks, blocking access to known malicious sites or warning the user if the link's destination has changed to become malicious since initial delivery. This proactive scanning helps prevent users from accessing compromised websites, even if the link was initially benign.
- ✗
Anti-spam policies
Why it's wrong here
Anti-spam policies primarily focus on identifying and filtering unsolicited bulk email, phishing attempts, and malware based on sender reputation, content analysis, and real-time block lists. While these policies reduce the overall volume of malicious emails reaching user inboxes, they do not perform dynamic, per-click URL scanning within emails that successfully bypass initial spam filters. Their core function is pre-delivery filtering, not post-delivery link validation.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Safe LinksCorrect answer▾
Why this is correct
Safe Links is a critical component of Microsoft Defender for Office 365 that provides time-of-click protection against malicious URLs. It dynamically rewrites URLs in emails and Office documents, then scans them in real-time when a user clicks, blocking access to known malicious sites or warning the user if the link's destination has changed to become malicious since initial delivery. This proactive scanning helps prevent users from accessing compromised websites, even if the link was initially benign.
✗Anti-phishing policiesWrong answer — click to see why▾
Why this is wrong here
Anti-phishing policies protect against phishing attempts by analyzing email content and sender reputation, but they do not rewrite URLs or perform real-time link checking against a dynamic list of malicious sites.
★ When this WOULD be the correct answer
An exam question asks: 'Which Microsoft Defender for Office 365 feature should be configured to block users from entering credentials on a fake login page that mimics a trusted site?' In that scenario, anti-phishing policies with impersonation protection would be correct.
Why candidates choose this
Candidates may confuse anti-phishing policies with Safe Links because both deal with malicious URLs, but anti-phishing focuses on the email content and sender, not on rewriting and real-time URL scanning.
✗Safe AttachmentsWrong answer — click to see why▾
Why this is wrong here
Safe Attachments protects against malicious attachments by detonating them in a sandbox, not by rewriting and checking URLs in real time. The question specifically requires URL rewriting and real-time link checking, which is the function of Safe Links.
★ When this WOULD be the correct answer
Safe Attachments would be correct if the question asked for a feature that scans email attachments for malware by opening them in a virtual environment before delivery, or if the requirement was to block malicious files in email and SharePoint.
Why candidates choose this
Candidates may confuse Safe Attachments with Safe Links because both are part of Microsoft Defender for Office 365 and deal with malicious content, but they target different threat vectors: attachments vs. links.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
Key term
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email and collaboration security service that protects organizations against malicious threats like phishing, malware, and spam in email messages and Office 365 apps.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.