SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO are capabilities of Microsoft Defender for Office 365?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Defender for Office 365 with Microsoft Defender for Endpoint or broader Microsoft 365 security features, leading them to select attack surface reduction rules (an endpoint protection feature) or device compliance policies (an Intune feature) instead of the email-specific Safe Attachments and Safe Links.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Attachments
Safe Attachments (A) is a core Microsoft Defender for Office 365 capability that detonates email attachments in a sandbox to detect malicious content before delivery. Safe Links (D) is also a Defender for Office 365 feature that rewrites and checks URLs in email and Office documents at time-of-click to block phishing and malicious destinations. Attack surface reduction rules (B) belong to Microsoft Defender for Endpoint, not Defender for Office 365. Multi-factor authentication enforcement (C) is handled by Microsoft Entra ID (Azure AD) Conditional Access, not Defender for Office 365. Device compliance policies (E) are configured in Microsoft Intune, so they are outside Defender for Office 365's scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Safe Attachments
Why this is correct
Safe Attachments is a core capability of Microsoft Defender for Office 365, providing advanced zero-day protection against unknown malware and viruses in email attachments. It detonates attachments in a secure, virtual environment before they reach the user's inbox, analyzing their behavior for malicious indicators. This proactive sandboxing prevents sophisticated threats, including ransomware and targeted attacks, from ever compromising an organization's endpoints.
- ✗
Attack surface reduction rules
Why it's wrong here
Attack surface reduction (ASR) rules are a critical component of Microsoft Defender for Endpoint, not Defender for Office 365. These rules are designed to prevent actions and apps commonly exploited by malware to compromise devices, such as blocking executable content from email clients or preventing untrusted processes from running. ASR rules operate at the endpoint level to reduce attack vectors on workstations and servers, distinct from email and collaboration security.
- ✗
Multi-factor authentication enforcement
Why it's wrong here
Multi-factor authentication (MFA) enforcement is a fundamental security feature provided by Microsoft Entra ID (formerly Azure Active Directory), not Microsoft Defender for Office 365. MFA requires users to provide multiple forms of verification to access resources, significantly bolstering protection against credential theft and unauthorized access. While crucial for securing access to Office 365 services, its configuration and enforcement, often via Conditional Access policies, are managed within the identity platform.
- ✓
Safe Links
Why this is correct
Safe Links is a key protection feature within Microsoft Defender for Office 365 that proactively safeguards users from malicious URLs embedded in emails, Microsoft Teams, and other Office applications. It rewrites and wraps URLs, then scans them in real-time when a user clicks, blocking access to any deemed unsafe. This prevents phishing attacks, drive-by downloads, and other web-based threats by ensuring users only access legitimate and secure destinations.
- ✗
Device compliance policies
Why it's wrong here
Device compliance policies are a core feature of Microsoft Intune, part of Microsoft Endpoint Manager, and are not a capability of Microsoft Defender for Office 365. These policies define the security standards and configurations that devices must meet to be considered compliant and gain access to organizational resources. They ensure devices have appropriate settings like encryption, minimum OS versions, and malware protection, operating at the device management layer rather than for email content.
Go deeper
Related to this question
Learn chapter
Microsoft Purview Compliance Portal
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.