Your organization wants to protect against phishing attacks by verifying the sender's identity for incoming emails. Which Microsoft Defender for Office 365 feature should you configure?
An anti-phishing policy, especially when configured with SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) settings, is specifically designed to combat phishing attacks. These authentication mechanisms verify the sender's identity and domain legitimacy, preventing spoofed emails and impersonation attempts from reaching recipients. This comprehensive approach directly addresses the core techniques used in phishing by ensuring email authenticity and enforcing policies on unauthenticated messages.
Why this answer
The anti-phishing policy in Microsoft Defender for Office 365 includes sender verification settings that leverage SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance). These protocols authenticate the sender's domain and verify that the email originated from an authorized server, directly addressing the requirement to protect against phishing by verifying sender identity.
Exam trap
The trap here is that candidates often confuse anti-phishing policies with Safe Links or Safe Attachments, assuming that link scanning or attachment sandboxing is the primary defense against phishing, when in fact sender verification via SPF/DKIM/DMARC is the foundational protection against identity spoofing in phishing attacks.
How to eliminate wrong answers
Option A is wrong because anti-malware policy is designed to detect and block malicious attachments or links in email, not to verify the sender's identity via email authentication protocols. Option B is wrong because Safe Links policy provides time-of-click protection by scanning URLs in emails and Office documents, but it does not authenticate the sender's domain or verify the email's origin. Option D is wrong because Safe Attachments policy uses detonation in a sandbox to analyze email attachments for malware, but it does not perform sender authentication checks like SPF, DKIM, or DMARC.