MS-102 Microsoft 365 Administrator Expert Managing Defender for Office 5 — Questions and Answers
Question 1: An administrator needs to allow a legitimate marketing vendor's emails to bypass Defender for Office 365 anti-phishing checks temporarily. Which is the most targeted approach?
- Add the vendor's sending IP to the connection filter allow list
- Add the vendor's domain to the Tenant Allow/Block List as an allowed sender (Correct answer)
- Create a mail flow rule to set the phish confidence level to -1
- Disable anti-phishing policies tenant-wide during the campaign
Correct answer: Add the vendor's domain to the Tenant Allow/Block List as an allowed sender
Adding the vendor's domain to the Tenant Allow/Block List as an allowed sender is the most targeted method, scoped to that specific domain without affecting other policies globally.
Question 2: Which Defender for Office 365 report shows the top targeted users in impersonation attacks over a selected time period?
- Threat protection status report
- Top senders and recipients report
- Impersonation insight report (Correct answer)
- URL threat protection report
Correct answer: Impersonation insight report
The Impersonation insight report in the Microsoft Defender portal shows which users and domains are most frequently targeted by impersonation-based phishing attempts.
Question 3: What happens to a message when the Safe Attachments policy action is set to 'Dynamic Delivery'?
- The email is held until the attachment scan completes, then both are released together
- The email body is delivered immediately to the recipient while the attachment is scanned in parallel and re-attached after scanning (Correct answer)
- The attachment is deleted and the email is delivered with a warning
- The email is sent to quarantine while the attachment is scanned
Correct answer: The email body is delivered immediately to the recipient while the attachment is scanned in parallel and re-attached after scanning
Dynamic Delivery delivers the email body immediately while simultaneously scanning the attachment, then re-attaches the clean file once scanning is complete, minimizing delivery delays.
Question 4: An organization's Defender for Office 365 tenant is generating too many false positives for bulk email from a legitimate newsletter service. Which setting should be adjusted first?
- Increase the Bulk Complaint Level (BCL) threshold in the anti-spam policy (Correct answer)
- Decrease the Spam Confidence Level (SCL) threshold to 1
- Add the newsletter domain to the Safe Senders list in each user's mailbox
- Disable the high confidence spam action in the anti-spam policy
Correct answer: Increase the Bulk Complaint Level (BCL) threshold in the anti-spam policy
Raising the BCL threshold in the anti-spam inbound policy allows bulk email with higher BCL scores to pass through, reducing false positives from legitimate newsletter services.
Question 5: A security admin wants to configure Defender for Office 365 so that end users receive a weekly digest of their quarantined messages. Where is this configured?
- Anti-spam policy end-user spam notifications settings
- Quarantine policy end-user notification settings (Correct answer)
- Alert policy notification frequency
- Safe Attachments policy user notification settings
Correct answer: Quarantine policy end-user notification settings
Quarantine policies include end-user notification settings where admins can configure the frequency (daily, twice per day, or weekly) of quarantine digest emails sent to users.
Question 6: Which pre-built security policy in Defender for Office 365 applies the most aggressive protection settings and is recommended for high-risk users like executives?
- Standard protection preset security policy
- Strict protection preset security policy (Correct answer)
- Built-in protection preset security policy
- Custom high-priority policy
Correct answer: Strict protection preset security policy
The Strict preset security policy applies the most aggressive Defender for Office 365 protection settings and is recommended for high-value or high-risk users such as executives and privileged accounts.
Question 7: An admin observes in the Threat protection status report that many messages are being delivered despite having a phish verdict due to an ETR override. What does 'ETR' stand for in this context?
- External Threat Response
- Exchange Transport Rule (Correct answer)
- Enhanced Threat Remediation
- Email Tenant Record
Correct answer: Exchange Transport Rule
ETR stands for Exchange Transport Rule; when a transport rule is configured to bypass filtering (e.g., setting SCL to -1), it can override phishing verdicts and force message delivery.
An administrator needs to allow a legitimate marketing vendor's emails to bypass Defender for Office 365 anti-phishing checks temporarily.
Which is the most targeted approach?