Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A financial institution uses Microsoft Defender for Office 365. They need to ensure that all email attachments are detonated in a sandbox environment before delivery to users, even if the attachments are from trusted senders or appear benign. This is crucial for protecting against zero-day malware embedded in documents. Which policy should be configured to achieve this stringent level of protection?

  1. AAnti-spam policy
  2. BSafe Attachments policy
  3. CSafe Links policy
  4. DAnti-phishing policy
Show answer & explanation

Correct answer: B. Safe Attachments policy

The Safe Attachments policy in Microsoft Defender for Office 365 is designed to protect against zero-day malware by opening email attachments in a virtual sandboxed environment before they reach the user's inbox. This ensures that even unknown threats are caught.

Why the other options are wrong

  • A. Anti-spam policies identify and filter unwanted bulk email, not advanced malware in attachments.
  • C. Safe Links policies rewrite URLs to scan them at the time of click, protecting against malicious links, not attachments.
  • D. Anti-phishing policies detect and prevent phishing attempts, not specifically malware in attachments.

Safe Attachments Policy

A feature of Microsoft Defender for Office 365 that provides zero-day protection by detonating email attachments in a virtual sandboxed environment before they reach recipients.

  • Protects against unknown and zero-day malware.
  • Detonates attachments in a sandbox.
  • Can be configured to block or redirect suspicious attachments.

Memory trick: Attachments need a sandbox before they can play.

More Mitigate threats using Microsoft Defender XDR questions