MS-102 Microsoft 365 Administrator Expert Managing Defender for Office 3 — Questions and Answers
Question 1: An administrator wants to prevent end users from releasing their own quarantined messages that were identified as high-confidence phishing. Which quarantine policy setting achieves this?
- Set the quarantine retention period to 1 day
- Assign a quarantine policy that grants NoAccess permissions to end users (Correct answer)
- Enable zero-hour auto purge on the anti-phishing policy
- Disable end-user spam notifications globally
Correct answer: Assign a quarantine policy that grants NoAccess permissions to end users
Assigning a quarantine policy with NoAccess permissions prevents end users from viewing or releasing their quarantined messages, keeping admin control over high-confidence phishing verdicts.
Question 2: Which action in Threat Explorer allows an admin to move a set of malicious emails already delivered to user inboxes into quarantine?
- Soft delete
- Hard delete
- Move to Junk
- Move to Quarantine (Correct answer)
Correct answer: Move to Quarantine
The 'Move to Quarantine' remediation action in Threat Explorer allows admins to move delivered malicious messages from user mailboxes directly into quarantine.
Question 3: An organization enables DMARC enforcement with a policy of 'reject'. Which Defender for Office 365 feature can override this and still deliver the email based on implicit trust?
- Spoof intelligence allow list
- Tenant Allow/Block List (TABL) spoofed senders (Correct answer)
- First contact safety tip
- Anti-malware bypass rule
Correct answer: Tenant Allow/Block List (TABL) spoofed senders
Adding a spoofed sender entry to the Tenant Allow/Block List allows messages from that sender to bypass DMARC rejection and be delivered to inboxes.
Question 4: What does the 'Apply real-time URL detonation' option in Safe Attachments do?
- Rewrites all URLs in messages before delivery
- Detonates URLs embedded within Safe Attachments-scanned files at time of click (Correct answer)
- Enables Safe Links on all outbound messages
- Forces URL scanning on Teams messages
Correct answer: Detonates URLs embedded within Safe Attachments-scanned files at time of click
The real-time URL detonation option in Safe Attachments causes URLs found inside scanned attachment files to be detonated at click time for additional protection.
Question 5: An administrator needs to identify all emails sent from a specific domain in the last 7 days that were delivered to inboxes but contain URLs flagged as malicious post-delivery. Which tool is best suited?
- Message trace in Exchange admin center
- Threat Explorer with URL clicks view filtered by verdict (Correct answer)
- Safe Links report in Defender portal
- Audit log search in Compliance portal
Correct answer: Threat Explorer with URL clicks view filtered by verdict
Threat Explorer's URL clicks view can be filtered by domain, time range, and URL verdict to identify post-delivery malicious URL detections in delivered messages.
Question 6: Which Defender for Office 365 Plan 2 feature automates the investigation of alerts and correlates related artifacts like emails, users, and URLs into a single incident?
- Safe Attachments dynamic delivery
- Automated investigation and response (AIR) (Correct answer)
- Attack simulation training
- Threat analytics
Correct answer: Automated investigation and response (AIR)
Automated investigation and response (AIR) in Defender for Office 365 Plan 2 automatically investigates triggered alerts, correlates related evidence, and recommends or takes remediation actions.
Question 7: An admin wants to allow a third-party bulk mailer's IP address to bypass spam filtering without disabling anti-malware checks. Which configuration achieves this?
- Add the IP to the connection filter policy's IP Allow List
- Add the IP to a mail flow rule that sets SCL to -1 (Correct answer)
- Add the sender domain to the Tenant Allow/Block List
- Create an anti-spam bypass rule in the Safe Senders list
Correct answer: Add the IP to a mail flow rule that sets SCL to -1
A mail flow (transport) rule that sets the Spam Confidence Level (SCL) to -1 for messages from the IP bypasses spam filtering while leaving anti-malware checks intact.
An administrator wants to prevent end users from releasing their own quarantined messages that were identified as high-confidence phishing.
Which quarantine policy setting achieves this?