Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A cybersecurity administrator is setting up Microsoft Defender for Office 365. They need to configure a policy to protect against malicious URLs in email that redirect users to phishing sites, even if the URL initially appears safe. This protection should occur at the time the user clicks the link, not just at email delivery. Which policy type should the administrator configure?
- AAnti-spam policy
- BAnti-phishing policy
- CSafe Links policy
- DSafe Attachments policy
Show answer & explanationAnswer & explanation
Correct answer: C. Safe Links policy
Safe Links policies in Microsoft Defender for Office 365 provide time-of-click verification of URLs in email and other Office apps. This ensures that even if a malicious link is initially benign but later redirects to a phishing site, the user is protected.
Why the other options are wrong
- A. Anti-spam policies identify and filter unwanted bulk email, not malicious URLs within messages.
- B. Anti-phishing policies protect against impersonation and spoofing, not against malicious URLs at click-time.
- D. Safe Attachments policies protect against malicious files in email attachments, not malicious URLs.
Safe Links Policy
A Microsoft Defender for Office 365 policy that provides time-of-click verification of URLs in email messages and other Office apps to protect users from malicious websites.
- Rewrites URLs in email to Defender for Office 365 scanning links.
- Scans the destination of the link in real-time when clicked.
- Can block access to malicious sites or warn users.
Memory trick: Safe Links keeps your clicks safe, even if the URL tries to play a trick.