This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Answer the following questions to check your understanding of the concepts covered in this module.
An administrator creates a custom anti-spam policy for the finance team and sets its priority to 0, the highest possible value. The finance team is also included in the Standard preset security policy's "All recipients" scope. Which policy actually applies to the finance team's mail?
The custom anti-spam policy, because priority 0 is the highest priority value a policy can have
Both policies, with their settings merged for the finance team's mailboxes
The Standard preset security policy, because preset security policies always evaluate before any custom policy, regardless of the custom policy's priority value
A message spoofing a Woodgrove banker's display name reaches the finance team even though a custom anti-spam policy is correctly scoped and applying. Which policy and setting is designed to catch this specific threat?
Anti-malware, using the common attachments filter
Anti-spam, by lowering the bulk complaint level threshold
Anti-phishing, using impersonation protection to add the sender or domain as a protected entity
An administrator investigates a Woodgrove-related alert and moves it from New to In progress while researching it. What does updating this alert's status primarily accomplish?
It tracks the response workflow so the investigation's progress is visible and can be handed off to another analyst
It permanently deletes the alert from the queue
It automatically remediates the message referenced by the alert
An administrator needs to find one specific message by subject to confirm how it was handled. Which surface should they use?
The Threat protection status report, because it shows the most detailed information about every message
The Submissions report, because it lists every message ever received by the organization
Threat Explorer, because it's built for searching and filtering individual messages by subject, sender, and other properties
Automated investigation and response (AIR) auto-remediates a cluster of malicious phishing messages. What action does AIR typically apply?
Soft delete, a reversible action that moves the messages to a recoverable state
Hard delete, which permanently and irreversibly removes the messages
No action, since AIR only reports on malicious clusters without remediating them
An administrator assigns a Training campaign to the finance team right after a phishing incident, including members who completed similar training 30 days ago. The training threshold is still set to its default value. What happens to those recently trained members?
They receive the training, but only after completing a new phishing simulation first
They receive the training again immediately, since Training campaigns always override any previous training history
They don't receive the reassigned training, because the default 90-day training threshold excludes users who completed or were assigned the training within that window
A single attack touches the finance team's email, a compromised identity, and an endpoint at nearly the same time. Which surface shows this as one correlated incident instead of four separate, disconnected alerts?
Microsoft Defender XDR
Microsoft Secure Score
Microsoft Defender for Cloud Apps
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?