SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization wants to protect against phishing attacks by verifying the sender's identity for incoming emails. Which Microsoft Defender for Office 365 feature should you configure?
⚠ Common exam trap
Many candidates confuse anti-phishing policies with Safe Links or Safe Attachments, assuming that link scanning or attachment sandboxing is the primary defense against phishing, when in fact sender verification via SPF/DKIM/DMARC is the foundational protection against identity spoofing in phishing attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anti-phishing policy with SPF/DKIM/DMARC settings
The anti-phishing policy in Microsoft Defender for Office 365 includes sender verification settings that leverage SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance). These protocols authenticate the sender's domain and verify that the email originated from an authorized server, directly addressing the requirement to protect against phishing by verifying sender identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anti-malware policy
Why it's wrong here
An anti-malware policy primarily focuses on detecting and blocking malicious software like viruses, worms, and Trojans embedded in emails or attachments. While crucial for overall email security, it does not specifically address the techniques used in phishing, such as sender impersonation or domain spoofing, which rely on tricking users rather than delivering executable malware directly. Therefore, it's insufficient on its own to protect against phishing attacks.
- ✗
Safe Links policy
Why it's wrong here
A Safe Links policy is designed to protect users from malicious URLs by rewriting and scanning them at the time of click. It checks if a link leads to a known phishing site or malware host, preventing access even if the original email passed initial scans. However, Safe Links does not verify the authenticity of the email sender or the domain itself, meaning it won't prevent a spoofed email from reaching the inbox if the embedded links are initially benign or lead to credential harvesting sites not yet identified as malicious.
- ✓
Anti-phishing policy with SPF/DKIM/DMARC settings
Why this is correct
An anti-phishing policy, especially when configured with SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) settings, is specifically designed to combat phishing attacks. These authentication mechanisms verify the sender's identity and domain legitimacy, preventing spoofed emails and impersonation attempts from reaching recipients. This comprehensive approach directly addresses the core techniques used in phishing by ensuring email authenticity and enforcing policies on unauthenticated messages.
- ✗
Safe Attachments policy
Why it's wrong here
A Safe Attachments policy provides advanced threat protection by opening email attachments in a virtual detonation chamber to analyze their behavior before delivery. This process identifies and neutralizes zero-day malware or other malicious content hidden within files. While vital for preventing malware delivery, Safe Attachments does not inspect the email's header for sender authentication or identify spoofed domains, making it ineffective against phishing attacks that primarily rely on social engineering and credential harvesting without necessarily including malicious file attachments.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
DomainKeys Identified Mail
DomainKeys Identified Mail is an email authentication method that allows a domain to cryptographically sign its outgoing messages so receiving servers can verify the sender's domain is legitimate and the message was not tampered with.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.