Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization wants to protect against phishing attacks by verifying the sender's identity for incoming emails. Which Microsoft Defender for Office 365 feature should you configure?

⚠ Common exam trap

Many candidates confuse anti-phishing policies with Safe Links or Safe Attachments, assuming that link scanning or attachment sandboxing is the primary defense against phishing, when in fact sender verification via SPF/DKIM/DMARC is the foundational protection against identity spoofing in phishing attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Anti-phishing policy with SPF/DKIM/DMARC settings

The anti-phishing policy in Microsoft Defender for Office 365 includes sender verification settings that leverage SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance). These protocols authenticate the sender's domain and verify that the email originated from an authorized server, directly addressing the requirement to protect against phishing by verifying sender identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Anti-malware policy

    Why it's wrong here

    An anti-malware policy primarily focuses on detecting and blocking malicious software like viruses, worms, and Trojans embedded in emails or attachments. While crucial for overall email security, it does not specifically address the techniques used in phishing, such as sender impersonation or domain spoofing, which rely on tricking users rather than delivering executable malware directly. Therefore, it's insufficient on its own to protect against phishing attacks.

  • Safe Links policy

    Why it's wrong here

    A Safe Links policy is designed to protect users from malicious URLs by rewriting and scanning them at the time of click. It checks if a link leads to a known phishing site or malware host, preventing access even if the original email passed initial scans. However, Safe Links does not verify the authenticity of the email sender or the domain itself, meaning it won't prevent a spoofed email from reaching the inbox if the embedded links are initially benign or lead to credential harvesting sites not yet identified as malicious.

  • Anti-phishing policy with SPF/DKIM/DMARC settings

    Why this is correct

    An anti-phishing policy, especially when configured with SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) settings, is specifically designed to combat phishing attacks. These authentication mechanisms verify the sender's identity and domain legitimacy, preventing spoofed emails and impersonation attempts from reaching recipients. This comprehensive approach directly addresses the core techniques used in phishing by ensuring email authenticity and enforcing policies on unauthenticated messages.

  • Safe Attachments policy

    Why it's wrong here

    A Safe Attachments policy provides advanced threat protection by opening email attachments in a virtual detonation chamber to analyze their behavior before delivery. This process identifies and neutralizes zero-day malware or other malicious content hidden within files. While vital for preventing malware delivery, Safe Attachments does not inspect the email's header for sender authentication or identify spoofed domains, making it ineffective against phishing attacks that primarily rely on social engineering and credential harvesting without necessarily including malicious file attachments.

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.