MS-102 · Question #325
You have a Microsoft 365 E5 subscription. You plan to create an anti-malware policy named Policy1. You need to ensure that Policy1 can detect malicious email messages that were already delivered to…
The correct answer is A. Enable zero-hour auto purge (ZAP). Zero-hour Auto Purge (ZAP) (A) is the correct feature. ZAP is specifically designed to retroactively identify and remove messages already delivered to user mailboxes that are later determined to be malicious - including malware, phishing, and spam. After delivery, if a new…
Question
You have a Microsoft 365 E5 subscription. You plan to create an anti-malware policy named Policy1. You need to ensure that Policy1 can detect malicious email messages that were already delivered to a user's mailbox. What should you do in the Microsoft Defender portal?
Options
- AEnable zero-hour auto purge (ZAP).
- BEnable enhanced filtering.
- CConfigure a quarantine policy.
- DModify the common attachments filter.
How the community answered
(46 responses)- A72% (33)
- B9% (4)
- C4% (2)
- D15% (7)
Explanation
Zero-hour Auto Purge (ZAP) (A) is the correct feature. ZAP is specifically designed to retroactively identify and remove messages already delivered to user mailboxes that are later determined to be malicious - including malware, phishing, and spam. After delivery, if a new threat signature matches a message already in the inbox, ZAP automatically moves it to the Junk or Quarantine folder. This directly fulfills the requirement of acting on messages 'already delivered.' The other options address different concerns: enhanced filtering optimizes inbound message evaluation, quarantine policy defines what happens to caught messages, and the common attachments filter blocks specific file types at delivery time - none retroactively act on delivered messages.
Topics
Community Discussion
No community discussion yet for this question.