Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A financial institution uses Microsoft Defender for Office 365. They need to ensure that all email attachments are detonated in a sandbox environment before delivery to users, even if the attachments are from trusted senders or appear benign. This is crucial for protecting against zero-day malware embedded in documents. Which policy should be configured to achieve this stringent level of protection?
- AAnti-spam policy
- BSafe Attachments policy
- CSafe Links policy
- DAnti-phishing policy
Show answer & explanationAnswer & explanation
Correct answer: B. Safe Attachments policy
The Safe Attachments policy in Microsoft Defender for Office 365 is designed to protect against zero-day malware by opening email attachments in a virtual sandboxed environment before they reach the user's inbox. This ensures that even unknown threats are caught.
Why the other options are wrong
- A. Anti-spam policies identify and filter unwanted bulk email, not advanced malware in attachments.
- C. Safe Links policies rewrite URLs to scan them at the time of click, protecting against malicious links, not attachments.
- D. Anti-phishing policies detect and prevent phishing attempts, not specifically malware in attachments.
Safe Attachments Policy
A feature of Microsoft Defender for Office 365 that provides zero-day protection by detonating email attachments in a virtual sandboxed environment before they reach recipients.
- Protects against unknown and zero-day malware.
- Detonates attachments in a sandbox.
- Can be configured to block or redirect suspicious attachments.
Memory trick: Attachments need a sandbox before they can play.