Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A financial services company uses Microsoft Defender for Office 365. They need to ensure that all email attachments are scanned for malware and zero-day threats before delivery to user mailboxes. If a threat is detected, the attachment should be quarantined, and the email body delivered with a placeholder. Which Defender for Office 365 policy configuration should be implemented to achieve this outcome?

  1. ASafe Links policy
  2. BAnti-phishing policy
  3. CSafe Attachments policy
  4. DAnti-spam policy
Show answer & explanation

Correct answer: C. Safe Attachments policy

Safe Attachments policies in Microsoft Defender for Office 365 are specifically designed to protect against zero-day malware in email attachments by detonating them in a virtual environment before delivery. The 'Dynamic Delivery' option with quarantine for detected threats matches the requirement.

Why the other options are wrong

  • A. Safe Links protects against malicious URLs, not file attachments.
  • B. Anti-phishing policies protect against impersonation and phishing attempts, not malware in attachments directly.
  • D. Anti-spam policies primarily focus on identifying and filtering unsolicited bulk email, not advanced malware in attachments.

Defender for Office 365 - Safe Attachments

Safe Attachments is a feature in Microsoft Defender for Office 365 that provides zero-day protection to safeguard messaging systems from malicious attachments.

  • Detonates attachments in a virtual environment.
  • Can quarantine malicious attachments.
  • Supports 'Dynamic Delivery' to deliver email body while scanning attachment.

Memory trick: Attachments need a 'Safe' place to be opened, links need to be 'Safe' before clicking.

More Mitigate threats using Microsoft Defender XDR questions