SC-400 Data Loss Prevention & Threat Protection 3 — Questions and Answers
Question 1: A company wants to use Microsoft Defender for Office 365 to protect against phishing emails that use lookalike domains. Which feature should be configured?
- Safe Attachments policy
- Anti-spam policy
- Anti-phishing policy with impersonation protection (Correct answer)
- Safe Links policy
Correct answer: Anti-phishing policy with impersonation protection
Anti-phishing policies with impersonation protection detect and block emails from lookalike domains that mimic trusted senders or organizations.
Question 2: What does Microsoft Defender for Office 365 Safe Links do when a user clicks a URL in an email?
- Scans the URL at time-of-click against a list of known malicious sites (Correct answer)
- Blocks all URLs in emails by default until whitelisted
- Converts all URLs to plain text to prevent clicking
- Quarantines the email if any URL is detected
Correct answer: Scans the URL at time-of-click against a list of known malicious sites
Safe Links rewrites URLs and checks them at time-of-click in real time, protecting against URLs that become malicious after delivery.
Question 3: An administrator needs to configure Safe Attachments to deliver email immediately while scanning attachments asynchronously. Which delivery option should be selected?
- Block
- Replace
- Dynamic Delivery (Correct answer)
- Monitor
Correct answer: Dynamic Delivery
Dynamic Delivery sends the email body immediately with a placeholder attachment and replaces it once scanning is complete, minimizing delays.
Question 4: Which Microsoft Defender for Office 365 plan (Plan 1 vs Plan 2) includes Threat Trackers and Attack Simulator?
- Plan 1 only
- Plan 2 only (Correct answer)
- Both Plan 1 and Plan 2
- Neither; these require Microsoft 365 Defender
Correct answer: Plan 2 only
Threat Trackers, Attack Simulator, and automated investigation and response (AIR) are Plan 2 features not included in Plan 1.
Question 5: A security team wants to run a simulated phishing campaign to measure employee susceptibility. Which Microsoft tool should they use?
- Microsoft Secure Score
- Microsoft Defender Attack Simulation Training (Correct answer)
- Microsoft Compliance Manager
- Microsoft Defender for Identity
Correct answer: Microsoft Defender Attack Simulation Training
Attack Simulation Training in Microsoft Defender for Office 365 Plan 2 allows organizations to run simulated phishing campaigns and track user responses.
Question 6: What is the purpose of the 'Spoof Intelligence' feature in Microsoft Defender for Office 365?
- It detects malware hidden inside image attachments
- It identifies and manages senders who are spoofing your organization's domains (Correct answer)
- It scans outbound emails for data exfiltration
- It blocks all emails from external senders by default
Correct answer: It identifies and manages senders who are spoofing your organization's domains
Spoof Intelligence identifies senders who spoof your organization's domain and allows admins to allow or block specific spoofing pairs.
Question 7: An admin reviews the Threat Protection Status report and notices a spike in 'Phish delivered due to tenant or user override.' What is the most likely cause?
- Safe Links policies are not configured correctly
- A user or admin has added the sender to an allow list, overriding phishing detection (Correct answer)
- The anti-malware policy has expired
- The organization's MX record is misconfigured
Correct answer: A user or admin has added the sender to an allow list, overriding phishing detection
When phish is delivered due to overrides, it means an allow list entry (tenant or user level) bypassed the phishing detection verdict.
A company wants to use Microsoft Defender for Office 365 to protect against phishing emails that use lookalike domains.
Which feature should be configured?