exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 2 question 26 discussion

Actual exam question from Microsoft's MS-101
Question #: 26
Topic #: 2
[All MS-101 Questions]

HOTSPOT -
Your company has a Microsoft 365 subscription.
You need to configure Microsoft 365 to meet the following requirements:
✑ Malware found in email attachments must be quarantined for 20 days.
✑ The email address of senders to your company must be verified.
Which two options should you configure in the Security & Compliance admin center? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
donathon
Highly Voted 3 years, 11 months ago
Anti-Phishing & Anti-Spam. Safe attachments: 15 days only cannot be changed. Safe links: does not scan attachments but URLs. DKIM: is for validation of others that you own the domain and hence is outbound. Anti-malware: 15 days only cannot be changed.
upvoted 31 times
Alien1981
3 years, 10 months ago
agreed , tested in my tenant https://security.microsoft.com/threatpolicy
upvoted 3 times
...
JT19760106
3 years, 3 months ago
Out of Anti-Phishing and Anti-Spam, what's flagging Malware? Reading the document, yes, only Anti-Phishing and Anti-Spam can have a custom quarantine period, but I didn't settings for either of those catching malware? https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/quarantine-email-messages?view=o365-worldwide
upvoted 3 times
...
LK4723
2 years, 8 months ago
I agree with this and below is article that has table for my reasoning. 1) Anti-spam and anti-phishing have customizable retention periods. 2) All other services for email filtering is retention of 30 days and is not customizable. 3) The question requires a 20 day retention not "at least" 20 days of retention. 4) Malware is a type of spam and commonly includes .vbscript and javascript which his detected with anti-spam policies. 5) DKIM is a technology to detect a valid sender but the services that actually picks it up is anti-spam that is what is verifying SPF and DKIM records. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/quarantine-email-messages?view=o365-worldwide
upvoted 4 times
LK4723
2 years, 8 months ago
Update to number 5. 5) DKIM is a technology to detect a valid sender but the services that actually pick it up is anti-phishing and anti-spam when verifying SPF and DKIM records. Anti-phishing can also pickup impersonation in forged headers.
upvoted 2 times
...
...
Bulldozzer
3 years, 2 months ago
I don't agree. The anti-spam setting does not apply to malware. So for me, the correct answers are Anti-Phishing and Anti-Malware even though so far there are no settings to customize the quarantine retention period.
upvoted 6 times
...
...
Luckyson
Highly Voted 4 years, 1 month ago
Antispam + DKIM
upvoted 12 times
themrcox
3 years, 11 months ago
DKIM is a digital signature added to outbound traffic so no, not DKIM.
upvoted 8 times
...
PersonT
4 years, 1 month ago
Agree...DKIM, offcourse
upvoted 3 times
potpal
4 years ago
DKIM is very wrong
upvoted 12 times
...
...
lucidgreen
3 years, 9 months ago
DKIM is for email sent from you, not to you. It's so people can't impersonate you. Anti-Phishing/Spoofing is to keep you from getting messages from impersonators/spoofers.
upvoted 4 times
...
...
LeGluten
Most Recent 2 years, 2 months ago
How long quarantined messages are held in quarantine before they expire is controlled by the Retain spam in quarantine for this many days (QuarantineRetentionPeriod) in anti-spam policies. For more information, see Configure anti-spam policies in EOP. Link: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/quarantine-policies?view=o365-worldwide
upvoted 1 times
...
lfbservices
2 years, 6 months ago
-The email address of senders to your company must be verified: I think it should be Anti Spam to verify and filter junk email from legitimate email
upvoted 1 times
...
Durden871
2 years, 9 months ago
I'm surprised, but I think it's ATP Anti-Phishing (this one is obvious) Anti-Spam How long quarantined messages are held in quarantine before they expire is controlled by the Retain spam in quarantine for this many days (QuarantineRetentionPeriod) in anti-spam policies. For more information, see Configure anti-spam policies in EOP. If you change the quarantine policy that's assigned to a supported protection feature, the change affects messages that are quarantined after you make the change. Messages that were previously quarantined by that protection feature are not affected by the settings of the new quarantine policy assignment. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/quarantine-policies?view=o365-worldwide
upvoted 2 times
...
stealthster
3 years, 3 months ago
I think it's anti-phishing and Anti-malware https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/safe-attachments?view=o365-worldwide "Attachments aren't scanned for malware by Safe Attachments. Messages are still scanned for malware by anti-malware protection in EOP." https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/manage-quarantined-messages-and-files?view=o365-worldwide Anti-malware can quarantine messages that contain malware and a quarantine policy can be configured to expire the quarantined message from 1-30 days
upvoted 7 times
...
FreddyLao
3 years, 4 months ago
if 20days of quarantine is a must. only Anti-spam can do. Anti-spam did mention can block malware. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/quarantine-email-messages?view=o365-worldwide Quarantine reason: Messages quarantined by anti-spam policies: spam, high confidence spam, phishing, high confidence phishing, or bulk. Default retention period: 15 days: In the default anti-spam policy. In anti-spam policies that you create in PowerShell. 30 days in anti-spam policies that you create in the Microsoft 365 Defender portal. Customizable? Yes https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-spam-protection?view=o365-worldwide EOP anti-spam and anti-phishing technology is applied across our email platforms to provide users with the latest anti-spam and anti-phishing tools and innovations throughout the network. The goal for EOP is to offer a comprehensive and usable email service that helps detect and protect users from junk email, fraudulent email threats (phishing), and malware.
upvoted 1 times
...
jodtzz
3 years, 5 months ago
This is a touch question, but it's Anti-Phishing and Anti-Spam. Here is the article that tells you: https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/quarantine-policies?view=o365-worldwide "How long quarantined messages are held in quarantine before they expire is controlled by the Retain spam in quarantine for this many days (QuarantineRetentionPeriod) in anti-spam policies. For more information, see Configure anti-spam policies in EOP. If you change the quarantine policy that's assigned to a supported protection feature, the change affects messages that are quarantined after you make the change. Messages that were previously quarantined by that protection feature are not affected by the settings of the new quarantine policy assignment." So, you have to setup a quarantine policy in anti-spam (or PS) and assign it to the Safe Attachments feature.
upvoted 3 times
...
zakyntos
3 years, 10 months ago
Anti-Phishing + Anti-Spam
upvoted 4 times
...
zakyntos
3 years, 10 months ago
Anti-Phishing + Anti-Spam
upvoted 3 times
...
LoremanReturns
3 years, 10 months ago
The question is not right. The only way to configure quarantine for messages containing a malware is Safe Attachments. Anti-Spam has no options for malware. The default retention period (cannot be modified) for messages quarantined for malware is 15 days. There're no additional options on this, so the answer is wrong.
upvoted 3 times
...
AnoniMouse
3 years, 11 months ago
Malware found in email attachments must be quarantined for 20 days == SAFE ATTACHMENT Read the required info carefully [The email address of senders TO your company must be verified]. They key here is the word TO and not FROM. DKIM will add a digital signature to your outgoing emails as a proof of identity, but the question wants the others to prove their identity, hence ANTI-PHISHING, which is the mechanism by which your incoming mail server verifies that the sender is coming from where it should be and not from somewhere else
upvoted 6 times
potpal
3 years, 11 months ago
15 days for files quarantined by Safe Attachments for SharePoint, OneDrive, and Microsoft Teams in Defender for Office 365. Does not meet the requirement.
upvoted 1 times
...
...
MiZi
3 years, 11 months ago
I would choose Anti-Phishing & Anti-Spam. However, in Anti-Spam couldn't find a malware detection rule. There is ZAP (Zero hour auto-purge) which is far from quarantine but affects malware messages that have already been delivered to Exchange Online mailboxes and purge them. But those 20 days... haven't found the option to adjust it elswhere
upvoted 3 times
...
potpal
4 years ago
I had this on test it is Anti-phishing and Anti Spam. Here's the homework : The email address of senders to your company must be verified. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/set-up-anti-phishing-policies?view=o365-worldwide#impersonation-settings-in-anti-phishing-policies-in-microsoft-defender-for-office-365 ✑ Malware found in email attachments must be quarantined for 20 days https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/safe-attachments?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/manage-quarantined-messages-and-files?view=o365-worldwide 15 days for files quarantined by Safe Attachments for SharePoint, OneDrive, and Microsoft Teams in Defender for Office 365.
upvoted 9 times
potpal
4 years ago
Anti-spam will allow you to adjust the quarantine to 20 days
upvoted 3 times
...
...
365admin
4 years ago
Malware found in email attachments must be quarantined for 20 days- ATP Safe attachments. Agreed the quarantine period is 15 days and there seems to be no way to change it, this solution looks the closest to meet the requirement. Anti-pam does not scan for malware in attachments.
upvoted 1 times
...
MSGrady
4 years ago
ATP Safe attachments policy does block malware n attachments and the message is sent to Quarantine https://www.imaginet.com/2018/office-365-advanced-threat-protection-101-atp-safe-attachments-policies/#:~:text=Creating%20Your%20First%20ATP%20Safe%20Attachments%20Policy&text=Applies%20to%20the%20imaginet.com,send%20it%20to%20the%20quarantine.
upvoted 2 times
...
Eltooth
4 years ago
Anti-phishing and Anti-Spam - checked on tenant and confirmed 30 days is only possible via Anti-Spam policy.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago