A company wants to protect against ransomware by detecting and blocking malicious files in email attachments. Which Microsoft security solution should be used?
Microsoft Defender for Office 365 is the dedicated security service engineered to protect an organization's email, collaboration, and productivity tools within Microsoft 365 from advanced threats. It employs robust capabilities like Safe Attachments, which detonates suspicious attachments in a sandbox environment, and Safe Links, which rewrites and scans URLs at the time of click. This comprehensive protection specifically targets ransomware, phishing, business email compromise, and other sophisticated malware delivered via email or Microsoft Teams, making it the correct solution for detecting email-borne ransomware.
Why this answer
Microsoft Defender for Office 365 includes Safe Attachments and Safe Links features that scan email attachments in real-time using detonation chambers and machine learning to detect and block ransomware and other malicious files. This solution is specifically designed to protect Exchange Online and SharePoint Online from threats delivered via email, making it the correct choice for blocking malicious attachments.
Exam trap
The trap here is that candidates often confuse endpoint protection (Defender for Endpoint) with email security, forgetting that Defender for Office 365 is the dedicated solution for email-borne threats like malicious attachments in ransomware attacks.
How to eliminate wrong answers
Option A is wrong because Microsoft Defender for Identity focuses on detecting identity-based threats like Kerberos attacks, pass-the-hash, and lateral movement using Active Directory signals, not on scanning email attachments. Option B is wrong because Microsoft Defender for Cloud Apps is a CASB that provides visibility and control over cloud app usage, including shadow IT and data exfiltration, but does not perform inline email attachment scanning for ransomware. Option D is wrong because Microsoft Defender for Endpoint protects endpoints (workstations, servers) from malware and ransomware via behavioral sensors and antivirus, but it does not scan email attachments within Exchange Online or SharePoint.