Does a Strict Preset Security Policy Meet the Balanced Baseline Goal?

Implement and manage email and collaboration protection by using Microsoft Defender for Office 365
Answer Correct answer: B — The Strict preset applies aggressive protection for high-value users; the Standard preset provides the balanced baseline profile required.

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware. Solution: You create a Strict preset security policy. Does this meet the goal?

  1. Yes
  2. No Correct Answer

Community Votes

B
83%
A
17%

83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you can map a stated protection intent (balanced baseline for most users) onto the correct preset profile, and the trap is treating "Strict" as simply "better" rather than as a narrower, more aggressive profile built for high-value targets.

In Microsoft Defender for Office 365, preset security policies come in two flavors — Standard and Strict — and only the Standard preset delivers the balanced baseline protection profile described in the scenario. Because the solution creates a Strict preset policy instead, it does not meet the stated goal.

The most common wrong answer is A (Yes), because candidates assume a stricter policy automatically satisfies a generic "protect against spam, phishing, and malware" requirement — but Strict is scoped to priority/high-value users, not the general baseline.

Community Discussion (6 comments)

JohnDoe47 👍 6
Correct, relevant link for this and the next two questions: https://learn.microsoft.com/en-us/defender-office-365/preset-security-policies#profiles-in-preset-security-policies
justITtopics 👍 1 Selected: B
In the link provided by JohnDoe47 Standard protection: A baseline profile that's suitable for most users. Strict protection: A more aggressive profile for selected users (high value targets or priority users).
BigO76 👍 1 Selected: B
B. Standard Protection: Balanced baseline profile suitable for most users. Strict Protection: Aggressive protection for high-risk or priority users.
sbermejor 👍 1
Standard protection (recommended for most businesses) Standard protection uses a baseline profile that's suitable for most users. Standard protection includes anti-spam, anti-malware, anti-phishing, spoof settings, impersonation settings, Safe Links, and Safe Attachments policies. Strict protection Strict protection includes the same kinds of policies as standard protection, but with more stringent settings. If your business must meet extra security requirements or regulations, consider applying strict protection to at least your priority users or high value targets. https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-protect-against-malware-cyberthreats?view=o365-worldwide
udaras 👍 3 Selected: B
https://learn.microsoft.com/en-us/defender-office-365/preset-security-policies Sorry the correct answer is B
udaras 👍 1 Selected: A
https://learn.microsoft.com/en-us/defender-office-365/preset-security-policies

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario asks for a threat policy that applies a balanced baseline protection profile to protect against spam, phishing, and malware. Microsoft's own preset security policy documentation describes Standard protection as the baseline profile suitable for most users, bundling anti-spam, anti-malware, anti-phishing, spoof and impersonation settings, Safe Links, and Safe Attachments. Strict protection contains the same kinds of policies but with more aggressive settings intended for a limited set of high-value or priority users. Since the requested profile is explicitly the balanced baseline, creating a Strict preset does not meet the goal — the answer is B (No).

Why the Other Options Are Wrong

Option A (Yes) fails because Strict protection is not the balanced baseline; it is an aggressive profile that can generate more friction for everyday users and is designed for targeted, high-risk accounts. It is tempting to think "Strict" is a superset that automatically satisfies the requirement, but preset security policies are mutually distinct profiles in terms of intended audience and tuning, not simply stronger or weaker versions of each other. The scenario's wording — "balanced baseline" — is the discriminator that rules A out. The correct implementation would be to apply the Standard preset security policy (and, if needed, the built-in protection for all recipients who are not covered by Standard or Strict).

Community Comment Notes

Community consensus aligns with B, and the reasoning is consistent: as justITtopics summarized from the Microsoft article, "Standard protection: A baseline profile that's suitable for most users. Strict protection: A more aggressive profile for selected users" and BigO76 restated the same distinction for high-risk or priority users. JohnDoe47 pointed to the canonical Microsoft Learn preset security policies page, and udaras linked the same page while concluding "Sorry the correct answer is B." One comment (udaras) later flipped to A, which illustrates how easily the Strict-is-better heuristic misleads — but the documentation text quoted by multiple learners, not the vote tally, is the decisive evidence here.

Official Reference

Exam Strategy

In MS-102 scenario "does this meet the goal" questions, translate the requirement keywords literally before judging the solution: "balanced baseline" maps to Standard protection, while "aggressive," "high-value targets," or "priority users" maps to Strict protection. If the solution name and the requirement keyword disagree, the answer is No — regardless of which policy sounds stronger.

Frequently Asked Questions

Why is the Strict preset security policy wrong when the goal is protecting against spam, phishing, and malware?

Strict protection does cover those workloads, but it is tuned aggressively for high-value or priority users, not as a balanced baseline. The scenario asks for the baseline profile, which is Standard protection.

What should I apply instead to get a balanced baseline for most users?

Apply the Standard preset security policy, which Microsoft defines as the baseline profile suitable for most users and includes anti-spam, anti-phishing, anti-malware, Safe Links, and Safe Attachments.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide