exam questions

Exam MS-900 All Questions

View all questions & answers for the MS-900 exam

Exam MS-900 topic 1 question 189 discussion

Actual exam question from Microsoft's MS-900
Question #: 189
Topic #: 1
[All MS-900 Questions]

You are a Microsoft 365 administrator for a company.
Several users report that they receive emails which have a PDF attachment. The PDF attachment launches malicious code.
You need to remove the message from inboxes and disable the PDF threat if an affected document is opened.
Which feature should you implement?

  • A. Microsoft Exchange Admin Center block lists
  • B. Sender Policy Framework
  • C. Advanced Threat Protection anti-phishing
  • D. zero-hour auto purge
  • E. DKIM signed messages with mail flow rules
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
An_u01
Highly Voted 4 years, 5 months ago
For the purpose of clearing exam: 'Advanced Threat Protection anti-phishing' is the answer I gave zero-hour auto purge and got it wrong!!!
upvoted 52 times
wando5000
2 years, 3 months ago
None of the answers are able to 'disable the PDF threat if an affected document is opened' So I will take your advise for the exam even though I think that D is a 'better' answer
upvoted 1 times
wando5000
2 years, 2 months ago
Sorry I am wrong. Answer given is correct. This is taken from MS website; "In Microsoft 365 organizations with mailboxes in Exchange Online, zero-hour auto purge (ZAP) is an email protection feature that retroactively detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to Exchange Online mailboxes." https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto-purge?view=o365-worldwide
upvoted 3 times
...
...
...
tvb
Highly Voted 4 years, 10 months ago
D is correct: https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto-purge
upvoted 22 times
...
Sergio_G_S
Most Recent 5 months, 3 weeks ago
Selected Answer: D
To address the issue of malicious PDF attachments, you should implement zero-hour auto purge (ZAP). ZAP is a feature in Microsoft 365 that automatically detects and removes malicious emails from user inboxes after they have been delivered. This helps to mitigate the threat by removing harmful messages even after they have been received.
upvoted 1 times
...
Genichiro
8 months, 1 week ago
Selected Answer: D
It is D ''imilarly, while zero-hour auto purge can help in quickly removing malicious emails, it's more reactive than preventive. Advanced Threat Protection, on the other hand, is specifically designed to handle such threats and provide proactive protection against them.'' In this question the users are already pointing out they recieve these mails. So in this specific question ZAP would be the best option imo.
upvoted 1 times
...
Nazz1977
10 months, 3 weeks ago
To address the issue of malicious PDF attachments in emails, you should implement the following features: C. Advanced Threat Protection anti-phishing Microsoft 365's Advanced Threat Protection (ATP) anti-phishing features are designed to help protect against malicious content, including harmful attachments in emails. ATP uses advanced algorithms and machine learning to detect and block phishing attempts, malware, and other threats. In this case, the anti-phishing feature would be particularly relevant for identifying and blocking emails with malicious PDF attachments. Options A (Microsoft Exchange Admin Center block lists), B (Sender Policy Framework), D (zero-hour auto purge), and E (DKIM signed messages with mail flow rules) are not specifically designed to address the issue of malicious attachments or phishing threats in emails. While these features may have their own security benefits, they are not the most direct solution for the described problem.
upvoted 1 times
...
[Removed]
1 year, 6 months ago
Selected Answer: C
correct answer is c for the purpose of this exam
upvoted 2 times
...
JayLearn2022
1 year, 8 months ago
Answer: C To address the reported issue of malicious PDF attachments, you should implement Advanced Threat Protection (ATP) anti-phishing in Microsoft 365. This feature provides protection against various types of advanced threats, including phishing emails with malicious attachments. In this scenario, ATP anti-phishing can help to remove the message from the inboxes of affected users and disable the PDF threat if an affected document is opened. It uses machine learning and other advanced techniques to detect and prevent phishing attacks, including those with malicious attachments like PDFs.
upvoted 1 times
JayLearn2022
1 year, 8 months ago
Option A, Microsoft Exchange Admin Center block lists, can be used to block specific senders or domains, but it may not be effective against sophisticated phishing attacks with spoofed or compromised sender addresses. Option B, Sender Policy Framework (SPF), is an email authentication method that validates the sender's domain, but it does not provide protection against phishing attacks with malicious attachments. Option D, zero-hour auto purge, is a feature that deletes messages that match certain criteria, but it does not prevent users from receiving or opening the messages in the first place. Option E, DKIM signed messages with mail flow rules, is another email authentication method that verifies the integrity of the message content, but it does not protect against phishing attacks with malicious attachments.
upvoted 1 times
...
...
Ashwin28
2 years, 6 months ago
Selected Answer: D
D is the answer
upvoted 1 times
...
Armpenu
2 years, 7 months ago
Selected Answer: D
Zap is right
upvoted 1 times
...
nikhil9860
2 years, 9 months ago
Selected Answer: D
D is the correct answer Zero-hour auto purge (ZAP) for phishing For read or unread messages that are identified as phishing after delivery, the ZAP outcome depends on the action that's configured for a Phishing email filtering verdict in the applicable anti-spam policy Ref :- https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto-purge?view=o365-worldwide
upvoted 1 times
...
Sam1990
2 years, 10 months ago
Selected Answer: C
C is correct
upvoted 1 times
...
ShakeShakeShake
3 years, 3 months ago
100% sure it is C because the question says - IF an affected document is opened. Means if an affected document is not opened, it does not do anything. Option D will remove even if the affected document is not opened.
upvoted 4 times
...
romer0
3 years, 5 months ago
Correct answer is D see for yourself: Question says: "You need to remove the message from inboxes" CTRL+F "remove" in https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto-purge?view=o365-worldwide
upvoted 1 times
...
PatrickH
3 years, 5 months ago
Basic features of ZAP In Microsoft 365 organizations with mailboxes in Exchange Online, zero-hour auto purge (ZAP) is an email protection feature that retroactively detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to Exchange Online mailboxes. Its D!
upvoted 1 times
...
syu31svc
3 years, 5 months ago
https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto-purge?view=o365-worldwide: "In Microsoft 365 organizations with mailboxes in Exchange Online, zero-hour auto purge (ZAP) is an email protection feature that retroactively detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to Exchange Online mailboxes." D is the answer
upvoted 3 times
...
Lyonel
3 years, 8 months ago
The answer is D: the 'key' to the question is "... several Users reported..."; means the infected PDF with the malicious code had "slipped past" ATP already, and the action being performed by the Admin (YOU) is retroactive. "In Microsoft 365 organizations with mailboxes in Exchange Online, zero-hour auto purge (ZAP) is an email protection feature that retroactively detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to Exchange Online mailboxes." Info found here: https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto-purge?view=o365-worldwide
upvoted 4 times
...
xoe123
3 years, 8 months ago
https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/remediate-malicious-email-delivered-office-365?view=o365-worldwide ZAP which is option D
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...