sc-900 Practice Question 1795

Exam: sc-900
Domain: Describe the capabilities of Microsoft security solutions
Topic: Describe Microsoft Defender and Sentinel
Difficulty: medium
Contoso Ltd is experiencing an increase in phishing attacks on their Microsoft 365 environment. You need to configure Microsoft Defender for Office 365 to detect and block suspicious emails. Which of the following actions should you take to achieve this? Explain your choice and why the other options are not suitable.

Answer Options

A
Enable Advanced Threat Protection (ATP) for Exchange Online.
B
Configure Phishing Protection policies in Microsoft Defender for Office 365.
C
Set up email content filters to block suspicious content.
D
Create security groups to manage user permissions.

Correct Answer

B: Configure Phishing Protection policies in Microsoft Defender for Office 365.

Explanation

The correct answer is B. Configure the Phishing Protection policies in Microsoft Defender for Office 365 to block suspicious emails. This can be done through the Microsoft 365 admin center under Security & Compliance > Threat management > Phishing protection policies. Other options like enabling Advanced Threat Protection (ATP) for Exchange Online or setting up email content filtering might help but do not specifically address the need to block suspicious emails as effectively as configuring Phishing Protection policies. Option C is incorrect because it involves setting up email content filters which are more general and not specifically designed for phishing detection. Option D is incorrect as it refers to setting up security groups which does not directly address the phishing threat.