Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization is implementing Microsoft Defender for Office 365 to protect against phishing attacks. You need to ensure that when a user clicks a malicious link in an email, the user is warned and the action is blocked. Which policy should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Safe Links policy

Safe Links in Defender for Office 365 provides real-time time-of-click protection against malicious links. Option A is wrong because Safe Attachments scans attachments, not links. Option C is wrong because anti-phishing policies protect against spoofing and impersonation but do not block links at click time. Option D is wrong because anti-spam policies filter spam, not malicious links.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Safe Attachments policy

    Why it's wrong here

    A Safe Attachments policy in Microsoft Defender for Office 365 provides a detonation chamber environment to analyze email attachments for malicious content before they reach the user's inbox. This sandbox analysis identifies zero-day malware and other threats embedded within files. While crucial for file-based threats, this policy does not provide protection against malicious URLs or links embedded within the email body or attachments themselves, as its focus is on file integrity.

  • Safe Links policy

    Why this is correct

    A Safe Links policy is designed to protect users from malicious URLs by providing time-of-click verification of web addresses in email and other Microsoft 365 apps. When a user clicks a link, Safe Links rewrites the URL and checks it against a list of known malicious sites, blocking access or warning the user if the destination is deemed unsafe. This proactive defense is specifically engineered to counter threats delivered via embedded links, making it the appropriate solution for protecting against malicious URLs.

  • Anti-spam policy

    Why it's wrong here

    An anti-spam policy primarily focuses on identifying and filtering unsolicited bulk email (spam) based on various characteristics like sender reputation, content patterns, and headers. Its main objective is to reduce inbox clutter and prevent users from receiving unwanted messages. While it can block emails containing certain types of suspicious content, its core function is not to provide real-time, time-of-click protection against malicious URLs embedded within emails that might otherwise pass initial spam filters.

  • Anti-phishing policy

    Why it's wrong here

    An anti-phishing policy in Microsoft Defender for Office 365 is specifically engineered to protect against impersonation and spoofing attacks, where attackers attempt to mimic legitimate senders or domains. It uses machine learning models and advanced algorithms to detect and block emails that try to trick recipients into believing they are from a trusted source. While phishing emails often contain malicious links, the anti-phishing policy's primary mechanism targets the *identity* of the sender rather than providing direct, time-of-click scanning and rewriting of URLs.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.