Which Defender for Office 365 Policy Quarantines .apk and .appx Attachments?

Implement and manage email and collaboration protection by using Microsoft Defender for Office 365
Answer Correct answer: A — Configure an anti-malware policy in Defender for Office 365 and add .apk and .appx to the common attachment types filter, set to quarantine.

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to create a policy that will quarantine messages containing attachments that match .apk and .appx extensions. Which type of policy should you configure?

  1. anti-malware Correct Answer
  2. anti-phishing
  3. Safe Attachments
  4. anti-spam

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you know that file-extension matching (.apk, .appx) belongs to the Common attachment types filter in anti-malware policies, not to Safe Attachments detonation or anti-spam filtering.

In Microsoft Defender for Office 365, extension-based attachment blocking and quarantine is controlled by the Common attachment types filter, which lives inside an anti-malware policy. This page confirms that anti-malware is the policy type to configure for quarantining messages with .apk and .appx attachments.

The most common wrong pick is Safe Attachments, because candidates assume any 'attachment' requirement means sandbox detonation — but Safe Attachments evaluates behaviour and malware verdicts, not a configurable list of file extensions.

Community Discussion (4 comments)

SeijuroSGD 👍 1 Selected: A
A. anti-malware
TechGuys 👍 4 Selected: A
The correct answer is: A. Anti-malware Explanation: To quarantine messages containing attachments with specific file extensions (e.g., .apk and .appx), you need to configure an anti-malware policy in Microsoft Defender for Office 365.
Newb007 👍 2 Selected: A
yes malware I think
pxeboot 👍 3 Selected: A
Shouldn’t it be anti-malware?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Anti-malware policies in Defender for Office 365 (and Exchange Online Protection) contain the Common attachment types filter, which is the one control that matches incoming mail by file extension and can be set to Quarantine. The scenario names two concrete extensions,.apk and.appx, which is exactly the input the filter expects: you add the custom file types and choose the action (Block, or Quarantine for the recipient to review). No other policy type in Defender for Office 365 lets you specify.apk or.appx as the matching condition. Because the required outcome is quarantine of messages carrying those attachment types, configuring an anti-malware policy is the only correct answer, which also matches the source key.

Why the Other Options Are Wrong

Anti-phishing policies (B) cover spoof intelligence, user and domain impersonation protection, mailbox intelligence and safety tips — they have no concept of attachment extensions. Safe Attachments (C) is tempting because its name mentions attachments, but it works by detonating files in a sandbox, applying dynamic delivery and blocking on an unknown-malware verdict; it cannot quarantine 'messages containing.apk and.appx' because it exposes no extension list. Anti-spam policies (D) govern spam, high-confidence spam, bulk mail thresholds and sender allow/block lists, and again provide no extension-based attachment control. Each distractor fails on the same point: none of them can be keyed to.apk or.appx.

Community Comment Notes

The community is unanimous here, with all 100 votes on the same option. TechGuys explained the reasoning plainly, stating "The correct answer is: A. Anti-malware" and noting that file extensions are handled by anti-malware policy. pxeboot questioned whether the answer should be anti-malware, and Newb007 replied "yes malware I think", while SeijuroSGD simply confirmed anti-malware. The learner comments therefore reinforce the vendor-documented behaviour rather than merely echoing the key, and no commenter proposed a credible argument for Safe Attachments or anti-spam.

Official Reference

Exam Strategy

When an MS-102 scenario names specific file extensions, stop scanning the options for 'attachment' keywords and go straight to the Common attachment types filter in anti-malware policies. Reserve Safe Attachments for questions about detonation, unknown malware or dynamic delivery, and anti-spam for sender filtering and bulk mail thresholds.

Frequently Asked Questions

Why is a Safe Attachments policy wrong when the requirement is about attachments?

Safe Attachments detonates files in a sandbox and acts on malware verdicts or unknown-malware timeouts. It has no list where you can name .apk and .appx, so it cannot satisfy an extension-based quarantine requirement.

Where exactly do I add .apk and .appx in the anti-malware policy?

In the policy's Common attachment types filter, add each extension as a custom file type and set the action to Quarantine. Messages carrying those attachment types are then quarantined for review.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide