SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
An organization wants to protect against business email compromise (BEC) attacks where attackers impersonate the CEO to trick employees into transferring funds. Which Microsoft Defender for Office 365 capability should they configure to detect such impersonation?
⚠ Common exam trap
Test-takers frequently confuse impersonation protection (user-level) with spoof intelligence (domain-level), assuming both handle the same type of attack, but impersonation protection is the only one that detects CEO fraud by analyzing sender identity rather than just domain authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Impersonation protection
Impersonation protection in Defender for Office 365 is specifically designed to detect and block business email compromise (BEC) attacks where an attacker spoofs a trusted sender, such as a CEO or CFO. It uses machine learning and sender intelligence to analyze email patterns and flag messages that impersonate internal or external high-value targets, making it the correct capability for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Safe Attachments
Why it's wrong here
Safe Attachments is a feature within Microsoft Defender for Office 365 that detonates email attachments in a virtual sandbox environment to identify and neutralize zero-day malware before it reaches user inboxes. While crucial for preventing malware delivery, it does not analyze email sender identity or content for social engineering cues related to impersonation. Therefore, it cannot directly protect against Business Email Compromise (BEC) attacks that rely on tricking recipients through sender identity manipulation rather than malicious files.
- ✗
Safe Links
Why it's wrong here
Safe Links, another component of Microsoft Defender for Office 365, provides time-of-click verification of URLs in emails and Office documents by rewriting them and scanning for malicious content. This protection is vital for preventing users from navigating to phishing sites or malware downloads embedded in legitimate-looking emails. However, Safe Links primarily addresses malicious URLs and does not evaluate the legitimacy of the sender's identity or detect attempts to impersonate trusted individuals or domains, which is the core of BEC attacks.
- ✓
Impersonation protection
Why this is correct
Impersonation protection is a critical feature within anti-phishing policies in Microsoft Defender for Office 365 specifically designed to combat Business Email Compromise (BEC) attacks. It allows administrators to define specific high-value users (e.g., executives, financial personnel) and trusted domains to monitor for impersonation attempts. The system analyzes various email headers and content attributes, such as display name, reply-to address, and sender address, to detect subtle variations that indicate an attempt to spoof a protected identity. When an impersonation is detected, the email can be quarantined, moved to junk, or have a safety tip added, directly mitigating BEC threats.
- ✗
Spoof intelligence
Why it's wrong here
Spoof intelligence, a feature within Exchange Online Protection (EOP) and Microsoft Defender for Office 365, primarily identifies and blocks emails where the sender's domain (P1 or P2 sender) is being forged or 'spoofed' by an unauthorized source. It analyzes authentication records like SPF, DKIM, and DMARC to determine if the sending server is legitimate for the claimed domain. While effective against direct domain spoofing, it does not specifically protect against sophisticated impersonation attacks where an attacker uses a legitimate-looking but slightly different domain or manipulates the display name to mimic a specific individual, which is characteristic of BEC.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.