SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization is implementing Microsoft Defender for Office 365 to protect against phishing attacks. You need to ensure that when a user clicks a malicious link in an email, the user is warned and the action is blocked. Which policy should you configure?
⚠ Common exam trap
The trap is confusing Safe Links with Safe Attachments or anti-phishing; candidates must remember that Safe Links is specifically for URL click-time protection, while Safe Attachments handles attachments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Links policy
Safe Links in Microsoft Defender for Office 365 specifically protects users from malicious URLs in email messages and Office documents. When a user clicks a link, Safe Links checks the URL against a list of known malicious sites and applies policies that can block the click and display a warning page. This directly addresses the requirement to warn and block the action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Safe Attachments policy
Why it's wrong here
A Safe Attachments policy in Microsoft Defender for Office 365 provides a detonation chamber environment to analyze email attachments for malicious content before they reach the user's inbox. This sandbox analysis identifies zero-day malware and other threats embedded within files. While crucial for file-based threats, this policy does not provide protection against malicious URLs or links embedded within the email body or attachments themselves, as its focus is on file integrity.
- ✓
Safe Links policy
Why this is correct
A Safe Links policy is designed to protect users from malicious URLs by providing time-of-click verification of web addresses in email and other Microsoft 365 apps. When a user clicks a link, Safe Links rewrites the URL and checks it against a list of known malicious sites, blocking access or warning the user if the destination is deemed unsafe. This proactive defense is specifically engineered to counter threats delivered via embedded links, making it the appropriate solution for protecting against malicious URLs.
- ✗
Anti-spam policy
Why it's wrong here
An anti-spam policy primarily focuses on identifying and filtering unsolicited bulk email (spam) based on various characteristics like sender reputation, content patterns, and headers. Its main objective is to reduce inbox clutter and prevent users from receiving unwanted messages. While it can block emails containing certain types of suspicious content, its core function is not to provide real-time, time-of-click protection against malicious URLs embedded within emails that might otherwise pass initial spam filters.
- ✗
Anti-phishing policy
Why it's wrong here
An anti-phishing policy in Microsoft Defender for Office 365 is specifically engineered to protect against impersonation and spoofing attacks, where attackers attempt to mimic legitimate senders or domains. It uses machine learning models and advanced algorithms to detect and block emails that try to trick recipients into believing they are from a trusted source. While phishing emails often contain malicious links, the anti-phishing policy's primary mechanism targets the *identity* of the sender rather than providing direct, time-of-click scanning and rewriting of URLs.
Go deeper
Related to this question
Learn chapter
Azure Policy for Compliance
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.