SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Defender for Office 365. A user reports receiving a suspicious email that appears to be from their CEO asking for a wire transfer. The email passed through the spam filter. What additional protection should be enabled to detect such attacks?
⚠ Common exam trap
A common mix-up: candidates confuse the general anti-phishing policy (which includes spoof intelligence) with the specific impersonation protection setting, or they mistakenly think Safe Links or Safe Attachments can detect social engineering attacks that contain no malicious payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Impersonation protection in anti-phishing policy
The attack described is a business email compromise (BEC) or CEO fraud, which relies on impersonation rather than malicious links or attachments. Microsoft Defender for Office 365's anti-phishing policy includes impersonation protection that specifically detects and mitigates attempts where a sender spoofs a high-profile user (like the CEO) or domain. Enabling impersonation protection in the anti-phishing policy is the correct additional safeguard because the email passed the spam filter, indicating it was not a bulk or malware-based threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Safe Attachments policy
Why it's wrong here
Safe Attachments policies are specifically designed to protect against zero-day malware and unknown threats embedded within email attachments. This protection works by detonating attachments in a secure sandbox environment to analyze their behavior before delivery. However, Safe Attachments does not analyze email headers or sender identity for signs of impersonation or spoofing, focusing solely on the malicious content of files.
- ✗
Anti-spam policy
Why it's wrong here
Anti-spam policies primarily focus on identifying and filtering unsolicited bulk email, often referred to as spam, based on various characteristics like sender reputation, content analysis, and header patterns. While they can block some forms of spoofing, their core function is not to detect highly targeted impersonation attempts where a legitimate user or domain is mimicked to trick recipients, which often involves subtle display name or domain variations rather than typical spam indicators.
- ✗
Safe Links policy
Why it's wrong here
Safe Links policies provide time-of-click protection by rewriting URLs in emails and Office documents, then scanning them for malicious content when a user clicks. Its primary function is to prevent users from accessing phishing sites or malware downloads embedded in links. It does not analyze the sender's identity or the email's headers for signs of impersonation, making it ineffective against attacks that rely on tricking the recipient into believing the sender is legitimate, even if no malicious link is present.
- ✓
Impersonation protection in anti-phishing policy
Why this is correct
Impersonation protection within an anti-phishing policy is specifically engineered to identify and mitigate attacks where attackers spoof a known user's display name or email address, or a trusted domain. It analyzes various email attributes, including sender display name, sender address, and domain similarity, against configured protected users and domains to detect and act upon these highly targeted phishing attempts. This direct focus on identity spoofing makes it the correct control for preventing impersonation.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.