Which Defender for Office 365 Policy Quarantines .apk and .appx Attachments?
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to create a policy that will quarantine messages containing attachments that match .apk and .appx extensions. Which type of policy should you configure?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you know that file-extension matching (.apk, .appx) belongs to the Common attachment types filter in anti-malware policies, not to Safe Attachments detonation or anti-spam filtering.
In Microsoft Defender for Office 365, extension-based attachment blocking and quarantine is controlled by the Common attachment types filter, which lives inside an anti-malware policy. This page confirms that anti-malware is the policy type to configure for quarantining messages with .apk and .appx attachments.
The most common wrong pick is Safe Attachments, because candidates assume any 'attachment' requirement means sandbox detonation — but Safe Attachments evaluates behaviour and malware verdicts, not a configurable list of file extensions.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Anti-malware policies in Defender for Office 365 (and Exchange Online Protection) contain the Common attachment types filter, which is the one control that matches incoming mail by file extension and can be set to Quarantine. The scenario names two concrete extensions,.apk and.appx, which is exactly the input the filter expects: you add the custom file types and choose the action (Block, or Quarantine for the recipient to review). No other policy type in Defender for Office 365 lets you specify.apk or.appx as the matching condition. Because the required outcome is quarantine of messages carrying those attachment types, configuring an anti-malware policy is the only correct answer, which also matches the source key.Why the Other Options Are Wrong
Anti-phishing policies (B) cover spoof intelligence, user and domain impersonation protection, mailbox intelligence and safety tips — they have no concept of attachment extensions. Safe Attachments (C) is tempting because its name mentions attachments, but it works by detonating files in a sandbox, applying dynamic delivery and blocking on an unknown-malware verdict; it cannot quarantine 'messages containing.apk and.appx' because it exposes no extension list. Anti-spam policies (D) govern spam, high-confidence spam, bulk mail thresholds and sender allow/block lists, and again provide no extension-based attachment control. Each distractor fails on the same point: none of them can be keyed to.apk or.appx.Community Comment Notes
The community is unanimous here, with all 100 votes on the same option. TechGuys explained the reasoning plainly, stating "The correct answer is: A. Anti-malware" and noting that file extensions are handled by anti-malware policy. pxeboot questioned whether the answer should be anti-malware, and Newb007 replied "yes malware I think", while SeijuroSGD simply confirmed anti-malware. The learner comments therefore reinforce the vendor-documented behaviour rather than merely echoing the key, and no commenter proposed a credible argument for Safe Attachments or anti-spam.Official Reference
Exam Strategy
When an MS-102 scenario names specific file extensions, stop scanning the options for 'attachment' keywords and go straight to the Common attachment types filter in anti-malware policies. Reserve Safe Attachments for questions about detonation, unknown malware or dynamic delivery, and anti-spam for sender filtering and bulk mail thresholds.
Frequently Asked Questions
Why is a Safe Attachments policy wrong when the requirement is about attachments?
Safe Attachments detonates files in a sandbox and acts on malware verdicts or unknown-malware timeouts. It has no list where you can name .apk and .appx, so it cannot satisfy an extension-based quarantine requirement.
Where exactly do I add .apk and .appx in the anti-malware policy?
In the policy's Common attachment types filter, add each extension as a custom file type and set the action to Quarantine. Messages carrying those attachment types are then quarantined for review.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →