Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

An organization wants to protect against business email compromise (BEC) attacks where attackers impersonate the CEO to trick employees into transferring funds. Which Microsoft Defender for Office 365 capability should they configure to detect such impersonation?

⚠ Common exam trap

Test-takers frequently confuse impersonation protection (user-level) with spoof intelligence (domain-level), assuming both handle the same type of attack, but impersonation protection is the only one that detects CEO fraud by analyzing sender identity rather than just domain authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Impersonation protection

Impersonation protection in Defender for Office 365 is specifically designed to detect and block business email compromise (BEC) attacks where an attacker spoofs a trusted sender, such as a CEO or CFO. It uses machine learning and sender intelligence to analyze email patterns and flag messages that impersonate internal or external high-value targets, making it the correct capability for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Safe Attachments

    Why it's wrong here

    Safe Attachments is a feature within Microsoft Defender for Office 365 that detonates email attachments in a virtual sandbox environment to identify and neutralize zero-day malware before it reaches user inboxes. While crucial for preventing malware delivery, it does not analyze email sender identity or content for social engineering cues related to impersonation. Therefore, it cannot directly protect against Business Email Compromise (BEC) attacks that rely on tricking recipients through sender identity manipulation rather than malicious files.

  • Safe Links

    Why it's wrong here

    Safe Links, another component of Microsoft Defender for Office 365, provides time-of-click verification of URLs in emails and Office documents by rewriting them and scanning for malicious content. This protection is vital for preventing users from navigating to phishing sites or malware downloads embedded in legitimate-looking emails. However, Safe Links primarily addresses malicious URLs and does not evaluate the legitimacy of the sender's identity or detect attempts to impersonate trusted individuals or domains, which is the core of BEC attacks.

  • Impersonation protection

    Why this is correct

    Impersonation protection is a critical feature within anti-phishing policies in Microsoft Defender for Office 365 specifically designed to combat Business Email Compromise (BEC) attacks. It allows administrators to define specific high-value users (e.g., executives, financial personnel) and trusted domains to monitor for impersonation attempts. The system analyzes various email headers and content attributes, such as display name, reply-to address, and sender address, to detect subtle variations that indicate an attempt to spoof a protected identity. When an impersonation is detected, the email can be quarantined, moved to junk, or have a safety tip added, directly mitigating BEC threats.

  • Spoof intelligence

    Why it's wrong here

    Spoof intelligence, a feature within Exchange Online Protection (EOP) and Microsoft Defender for Office 365, primarily identifies and blocks emails where the sender's domain (P1 or P2 sender) is being forged or 'spoofed' by an unauthorized source. It analyzes authentication records like SPF, DKIM, and DMARC to determine if the sending server is legitimate for the claimed domain. While effective against direct domain spoofing, it does not specifically protect against sophisticated impersonation attacks where an attacker uses a legitimate-looking but slightly different domain or manipulates the display name to mimic a specific individual, which is characteristic of BEC.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.