Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A financial services company uses Microsoft Defender for Office 365. They need to ensure that all email attachments are scanned for malware and zero-day threats before delivery to user mailboxes. If a threat is detected, the attachment should be quarantined, and the email body delivered with a placeholder. Which Defender for Office 365 policy configuration should be implemented to achieve this outcome?
- ASafe Links policy
- BAnti-phishing policy
- CSafe Attachments policy
- DAnti-spam policy
Show answer & explanationAnswer & explanation
Correct answer: C. Safe Attachments policy
Safe Attachments policies in Microsoft Defender for Office 365 are specifically designed to protect against zero-day malware in email attachments by detonating them in a virtual environment before delivery. The 'Dynamic Delivery' option with quarantine for detected threats matches the requirement.
Why the other options are wrong
- A. Safe Links protects against malicious URLs, not file attachments.
- B. Anti-phishing policies protect against impersonation and phishing attempts, not malware in attachments directly.
- D. Anti-spam policies primarily focus on identifying and filtering unsolicited bulk email, not advanced malware in attachments.
Defender for Office 365 - Safe Attachments
Safe Attachments is a feature in Microsoft Defender for Office 365 that provides zero-day protection to safeguard messaging systems from malicious attachments.
- Detonates attachments in a virtual environment.
- Can quarantine malicious attachments.
- Supports 'Dynamic Delivery' to deliver email body while scanning attachment.
Memory trick: Attachments need a 'Safe' place to be opened, links need to be 'Safe' before clicking.