Does a Standard Preset Security Policy Meet a Balanced Baseline Goal?
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware. Solution: You create a Standard preset security policy. Does this meet the goal?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the difference between Defender for Office 365 Standard and Strict preset security policies, and the trap is treating the phrase 'balanced baseline protection' as an undefined custom policy instead of the Standard preset.
This MS-102 scenario asks whether creating a Standard preset security policy in Microsoft Defender for Office 365 satisfies a requirement for a balanced baseline profile against spam, phishing, and malware. Yes — Standard is the built-in balanced profile, while Strict is the more aggressive quarantine-heavy option.
Answering No because 'balanced baseline' sounds like a custom anti-spam or anti-phishing policy that must be built by hand, or mixing up Standard (junk folder) with Strict (quarantine) preset security policies.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for Office 365 ships two preset security policies — Standard and Strict — that bundle Exchange Online Protection plus Defender for Office 365 Protection settings without any manual tuning. The Standard preset is explicitly documented as the balanced baseline profile: it filters spam, bulk mail, phishing, spoofing, and malware at default-but-solid thresholds for the users or groups the policy targets. The requirement in this scenario asks only for a balanced baseline against spam, phishing, and malware, which is exactly what selecting Standard delivers. Because the solution creates that Standard preset security policy, it satisfies the stated goal, so the answer is Yes.Why the Other Options Are Wrong
Option B (No) is incorrect because it assumes the Standard preset is insufficient or that a bespoke policy is required; no such requirement exists in the scenario, which asks for baseline rather than maximum protection. A common hesitation is that 'balanced' is vague, but Microsoft's own naming convention pairs Standard with balanced protection and Strict with the most aggressive protection. Strict would exceed the goal by quarantining more aggressively rather than delivering a balanced baseline. Custom anti-spam, anti-phishing, anti-malware, and Safe Attachments/Safe Links policies are also valid, but they are not needed when the ask maps directly onto the Standard preset.Community Comment Notes
Krayzr summarised Ody's guidance that "Preset Security Policies are either Standard (balanced) or Strict" and that the question simply worded this comparison poorly. jakubczcz raised a fair learner doubt about whether "balanced baseline" really maps to the Standard preset, noting that Standard sends problematic email to junk while Strict quarantines it — that behaviour difference is precisely why Standard is the balanced profile. KoenJas answered plainly "A. Yes", matching the consensus in the vote distribution. The whole thread converges on the built-in preset policies rather than custom policy construction.Official Reference
Exam Strategy
These case-set questions cannot be revisited, so decode the wording fast: 'balanced' or 'baseline' maps to the Standard preset security policy, while 'strict' or 'most aggressive' maps to Strict. Both are applied to users, groups, or domains as a single preconfigured policy, so no custom anti-spam or anti-phishing policy is needed to meet a baseline goal.
Frequently Asked Questions
Does 'balanced baseline protection' really mean the Standard preset security policy?
Yes. Standard is the preconfigured balanced profile in Defender for Office 365 preset security policies; Strict is the more aggressive profile that quarantines more.
Why not choose Strict preset security policy for spam, phishing, and malware?
The scenario asks for a balanced baseline, not maximum protection. Strict delivers stronger, quarantine-heavy settings, exceeding the stated requirement.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →