MS-102 Microsoft 365 Administrator Expert Managing Defender for Office 2 — Questions and Answers
Question 1: An administrator notices that Safe Links is not rewriting URLs in emails sent between internal users. What is the most likely cause?
- The Safe Links policy is scoped only to external recipients
- Safe Links does not support internal email scanning by default and requires enabling 'Apply Safe Links to email sent within the organization' (Correct answer)
- The MX record is not pointing to Exchange Online
- The anti-spam policy is blocking Safe Links processing
Correct answer: Safe Links does not support internal email scanning by default and requires enabling 'Apply Safe Links to email sent within the organization'
Safe Links must be explicitly configured to scan internal email by enabling the 'Apply Safe Links to email sent within the organization' setting in the policy.
Question 2: Which Defender for Office 365 feature provides a detonation-based analysis of email attachments in an isolated environment before delivery?
- Safe Links
- Safe Attachments (Correct answer)
- Zero-hour auto purge (ZAP)
- Anti-phishing impersonation protection
Correct answer: Safe Attachments
Safe Attachments detonates suspicious attachments in a sandboxed virtual environment to detect malware before the email is delivered to the recipient.
Question 3: A user reports that clicking a URL in an Outlook desktop client is not being checked by Safe Links. Which setting must be enabled in the Safe Links policy?
- Apply Safe Links to email messages
- Apply Safe Links to Microsoft Teams
- Apply Safe Links to supported Office apps (Correct answer)
- Enable click-through protection
Correct answer: Apply Safe Links to supported Office apps
The 'Apply Safe Links to supported Office apps' setting must be enabled to protect URLs clicked within Office desktop applications like Word, Excel, and Outlook.
Question 4: Which report in the Microsoft Defender portal shows the volume of messages identified as malware, phish, spam, and bulk over time?
- Threat Explorer
- Mail flow status summary report (Correct answer)
- Email security report
- Attack simulation report
Correct answer: Mail flow status summary report
The Mail flow status summary report displays aggregated counts of messages categorized as malware, phish, spam, and bulk for a selected time range.
Question 5: An organization wants to ensure that emails failing SPF, DKIM, or DMARC checks are automatically moved to quarantine. Which policy controls this behavior?
- Safe Attachments policy
- Anti-phishing policy with spoof intelligence settings (Correct answer)
- Anti-spam inbound policy with bulk complaint level threshold
- Safe Links policy
Correct answer: Anti-phishing policy with spoof intelligence settings
The anti-phishing policy's spoof intelligence settings control how messages that fail composite authentication (SPF/DKIM/DMARC) are handled, including moving them to quarantine.
Question 6: What is the purpose of the 'Restricted entities' page in the Microsoft Defender portal?
- It lists all blocked URLs discovered by Safe Links
- It shows user accounts blocked from sending email due to sending suspicious or high-volume messages (Correct answer)
- It displays quarantined files from SharePoint Online
- It lists IP addresses blocked by the tenant allow/block list
Correct answer: It shows user accounts blocked from sending email due to sending suspicious or high-volume messages
The Restricted entities page shows user accounts that have been blocked from sending email after being flagged for suspicious outbound sending behavior.
Question 7: Which Defender for Office 365 capability allows an administrator to submit a false-positive quarantined message directly to Microsoft for analysis?
- Threat Explorer bulk actions
- Admin submission via the Submissions page (Correct answer)
- ZAP remediation
- Alert policy trigger
Correct answer: Admin submission via the Submissions page
The Submissions page in the Microsoft Defender portal allows admins to submit quarantined messages, URLs, or email attachments to Microsoft as false positives or false negatives for analysis.
An administrator notices that Safe Links is not rewriting URLs in emails sent between internal users.
What is the most likely cause?