nerdexam
Microsoft

MS-900 · Question #143

You are a Microsoft 365 administrator for a company. You need to identify security vulnerabilities by using the Office 365 Attack Simulator. Which three attack simulations are available? Each…

The correct answer is A. Brute-force password C. Password-spray E. Display name spear-phishing. The Office 365 Attack Simulator (part of Microsoft Defender for Office 365) provides specific pre-built attack simulation types focused on credential and phishing attacks. Only three of the listed options are actual simulations available in the tool.

Submitted by yaw92· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

You are a Microsoft 365 administrator for a company. You need to identify security vulnerabilities by using the Office 365 Attack Simulator. Which three attack simulations are available? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • ABrute-force password
  • BCross-site scripting
  • CPassword-spray
  • DDenial-of-service
  • EDisplay name spear-phishing

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    7% (3)
  • D
    2% (1)

Why each option

The Office 365 Attack Simulator (part of Microsoft Defender for Office 365) provides specific pre-built attack simulation types focused on credential and phishing attacks. Only three of the listed options are actual simulations available in the tool.

ABrute-force passwordCorrect

Brute-force password attack is a built-in simulation in Attack Simulator that attempts to crack user passwords by systematically trying a large number of password combinations, helping administrators identify accounts with weak passwords.

BCross-site scripting

Cross-site scripting (XSS) is a web application vulnerability testing technique and is not one of the attack simulation types offered in the Office 365 Attack Simulator.

CPassword-sprayCorrect

Password-spray attack is a built-in simulation that attempts a single commonly used password against many accounts simultaneously, which helps identify accounts vulnerable to this low-and-slow credential attack technique.

DDenial-of-service

Denial-of-service (DoS) simulation is not available in the Office 365 Attack Simulator, as the tool focuses on credential and phishing-based attacks rather than network availability attacks.

EDisplay name spear-phishingCorrect

Display name spear-phishing is a built-in phishing simulation in Attack Simulator that spoofs a trusted sender's display name to trick targeted users into clicking malicious links, testing user susceptibility to social engineering attacks.

Concept tested: Office 365 Attack Simulator available simulation types

Source: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training-simulations?view=o365-worldwide

Topics

#Attack Simulator#password attack#phishing#security awareness training

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice