SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization is implementing Microsoft Defender for Office 365 to protect against phishing attacks. You need to ensure that when a user clicks a malicious link in an email, the user is warned and the action is blocked. Which policy should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Links policy
Safe Links in Defender for Office 365 provides real-time time-of-click protection against malicious links. Option A is wrong because Safe Attachments scans attachments, not links. Option C is wrong because anti-phishing policies protect against spoofing and impersonation but do not block links at click time. Option D is wrong because anti-spam policies filter spam, not malicious links.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Safe Attachments policy
Why it's wrong here
A Safe Attachments policy in Microsoft Defender for Office 365 provides a detonation chamber environment to analyze email attachments for malicious content before they reach the user's inbox. This sandbox analysis identifies zero-day malware and other threats embedded within files. While crucial for file-based threats, this policy does not provide protection against malicious URLs or links embedded within the email body or attachments themselves, as its focus is on file integrity.
- ✓
Safe Links policy
Why this is correct
A Safe Links policy is designed to protect users from malicious URLs by providing time-of-click verification of web addresses in email and other Microsoft 365 apps. When a user clicks a link, Safe Links rewrites the URL and checks it against a list of known malicious sites, blocking access or warning the user if the destination is deemed unsafe. This proactive defense is specifically engineered to counter threats delivered via embedded links, making it the appropriate solution for protecting against malicious URLs.
- ✗
Anti-spam policy
Why it's wrong here
An anti-spam policy primarily focuses on identifying and filtering unsolicited bulk email (spam) based on various characteristics like sender reputation, content patterns, and headers. Its main objective is to reduce inbox clutter and prevent users from receiving unwanted messages. While it can block emails containing certain types of suspicious content, its core function is not to provide real-time, time-of-click protection against malicious URLs embedded within emails that might otherwise pass initial spam filters.
- ✗
Anti-phishing policy
Why it's wrong here
An anti-phishing policy in Microsoft Defender for Office 365 is specifically engineered to protect against impersonation and spoofing attacks, where attackers attempt to mimic legitimate senders or domains. It uses machine learning models and advanced algorithms to detect and block emails that try to trick recipients into believing they are from a trusted source. While phishing emails often contain malicious links, the anti-phishing policy's primary mechanism targets the *identity* of the sender rather than providing direct, time-of-click scanning and rewriting of URLs.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.