Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A company uses Microsoft Defender for Office 365. The security team has observed a new, highly sophisticated phishing campaign where attackers are using zero-day exploits embedded in PDF attachments to bypass traditional signature-based detection. These attachments are disguised as legitimate financial statements. The team needs to implement a policy to detonate and analyze all suspicious attachments in a sandbox environment before they reach user mailboxes, specifically targeting this new threat vector. Which policy type should the administrator configure?
- AAnti-phishing policy
- BAnti-spam policy
- CSafe Links policy
- DSafe Attachments policy
Show answer & explanationAnswer & explanation
Correct answer: D. Safe Attachments policy
Safe Attachments policies in Microsoft Defender for Office 365 are designed to protect against unknown malware and zero-day exploits by opening attachments in a sandbox environment to analyze their behavior before delivering them to recipients. This directly addresses the need to detonate suspicious PDF attachments.
Why the other options are wrong
- A. Anti-phishing policies focus on detecting and preventing impersonation and spoofing, not analyzing attachments.
- B. Anti-spam policies primarily filter bulk unsolicited email, not zero-day exploits in attachments.
- C. Safe Links policies protect against malicious URLs at the time of click, not malicious attachments.
Safe Attachments Policy
A Microsoft Defender for Office 365 policy that detonates and analyzes email attachments in a virtual sandbox environment to detect unknown malware and zero-day exploits before they reach user inboxes.
- Protects against unknown malware and zero-day threats.
- Scans attachments in a separate, isolated environment.
- Can block, replace, or monitor attachments based on policy.
Memory trick: Safe Attachments gives suspicious files a 'safe' place to explode.