Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium
A global manufacturing company uses Microsoft 365 and has recently experienced several sophisticated phishing attacks targeting their supply chain partners. These attacks often involve highly personalized emails with malicious URLs embedded. The security team wants to implement a robust solution within Microsoft Defender for Office 365 that specifically protects users from clicking on unsafe links in emails, even if the links are initially deemed safe but later become malicious. Which feature should the administrator configure?
- AAnti-spam policy with increased spam confidence levels
- BSafe Attachments policy
- CMail flow rules (transport rules)
- DSafe Links policy
Show answer & explanationAnswer & explanation
Correct answer: D. Safe Links policy
Safe Links in Microsoft Defender for Office 365 provides time-of-click verification of URLs in email messages and other Microsoft 365 apps, protecting users even if a link is initially safe but later changes to malicious content.
Why the other options are wrong
- A. Anti-spam policies primarily filter bulk unsolicited email and do not specifically provide time-of-click protection for URLs.
- B. Safe Attachments policies scan email attachments for malware in a sandbox environment, not URLs in the email body.
- C. Mail flow rules can block or modify emails based on content or sender, but they do not offer dynamic, time-of-click protection for URLs.
Defender for O365 Safe Links
Safe Links is a feature of Microsoft Defender for Office 365 that provides time-of-click verification of URLs in email messages and other Microsoft 365 apps, protecting users from malicious links even if they change after delivery.
- Rewrites URLs in emails and Office documents.
- Checks URLs in real-time at the time of click.
- Blocks access to malicious sites.
- Protects against changing malicious content.
Memory trick: Links can be tricky; make sure they're safe when clicked, not just when seen.