Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

An organization wants to protect against spear-phishing attacks where attackers impersonate the company's CEO or other trusted domains to trick employees into transferring funds. They need a security solution that uses machine learning to detect and prevent such impersonation attempts in incoming emails. Which Microsoft 365 protection feature should they enable?

⚠ Common exam trap

Microsoft often tests the distinction between anti-phishing policies (which include impersonation protection) and anti-spam policies, leading candidates to mistakenly choose anti-spam when the question explicitly mentions targeted impersonation rather than generic spam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Anti-phishing policy (impersonation protection)

Anti-phishing policy with impersonation protection uses machine learning models to detect and block attempts to impersonate specific users (like the CEO) or trusted domains in incoming emails. This directly addresses the scenario of spear-phishing attacks that trick employees into transferring funds by mimicking trusted senders.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Anti-spam policy

    Why it's wrong here

    Anti-spam policies are primarily designed to identify and filter unsolicited bulk email, known spam patterns, and high-volume malicious campaigns based on reputation and content analysis. While effective at reducing general junk mail, they lack the sophisticated detection capabilities required for targeted spear phishing attacks. These attacks often involve low-volume, highly personalized emails that impersonate trusted senders or domains, bypassing the signature-based or volume-based detection methods common in anti-spam filters, thus failing to protect against specific impersonation attempts.

  • Anti-phishing policy (impersonation protection)

    Why this is correct

    Anti-phishing policies, particularly those with impersonation protection in Microsoft Defender for Office 365, are specifically engineered to combat spear phishing by detecting sender impersonation. They leverage advanced machine learning models to analyze various email attributes, including sender address, display name, and domain reputation, to identify attempts to spoof trusted users within an organization or external legitimate domains. This targeted protection identifies and blocks emails where attackers spoof identities to trick recipients, directly addressing the core mechanism of spear phishing.

  • Safe Links

    Why it's wrong here

    Safe Links is a security feature designed to protect users from malicious URLs embedded within emails, Microsoft Teams, and other applications. It operates by rewriting URLs and scanning them in real-time at the moment a user clicks, blocking access to known malicious sites or those identified as suspicious. However, Safe Links does not analyze the sender's identity or detect impersonation attempts within the email's header or body itself. Its function is reactive to link clicks, not proactive in identifying spoofed senders.

  • Safe Attachments

    Why it's wrong here

    Safe Attachments provides advanced protection against zero-day malware and unknown threats delivered via email attachments. It uses a detonation chamber to open attachments in a virtual environment, analyzing their behavior for malicious activity before they reach the user's inbox. While crucial for preventing malware infections, Safe Attachments does not analyze the sender's identity or the email's content for signs of impersonation, which is the primary vector for spear phishing attacks. Its scope is limited to the security of attached files, not the authenticity of the sender.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.