What Implements Social Engineering Awareness in Defender for Office 365?

Implement and manage email and collaboration protection by using Microsoft Defender for Office 365
Answer Correct answer: C — Attack simulation training in the Microsoft Defender portal emulates the password-reset email, tracks link clickers, and assigns further social engineering training.

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to implement a social engineering awareness solution that meets the following requirements: • To reset a user's password, emulate an email message that contains a link. • Track any users that selects the email message link. • Suggest further social engineering training. What should you use in the Microsoft Defender portal?

  1. Exposure insights
  2. Learning hub
  3. Attack simulation training Correct Answer
  4. Threat tracker

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests which Defender portal feature combines phishing simulation, click tracking, and training assignment; the trap is confusing it with Learning hub or Exposure insights, which educate or report but do not launch the simulated password-reset campaign.

Attack simulation training in Microsoft Defender for Office 365 lets you emulate password-reset phishing emails, track link clicks, and assign follow-up training. This page confirms Attack simulation training (C) is the correct tool in the Microsoft Defender portal for the stated social engineering awareness requirements.

Some learners choose Learning hub because it sounds like security awareness training, but it only provides educational content and cannot emulate or track the password-reset phishing email.

Community Discussion (4 comments)

Krayzr 👍 1 Selected: C
Repeated Question
Crille 👍 1
Correct A I think C is for learn user not to click on link with suspicious things
KoenJas 👍 4
C. Attack simulation training
Iccen 👍 3
I thin given answer is correct! C.Attack simulation training. Correct me if im wrong pls:)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Attack simulation training in the Microsoft Defender portal is designed for exactly these three requirements: it can launch a simulated phishing campaign, including a password-reset lure with a tracked link, report which users clicked, and assign or recommend follow-up training. Microsoft positions it under Defender for Office 365 as the social engineering awareness solution. Community voters agree almost unanimously; as Iccen wrote, "given answer is correct! C.Attack simulation training". KoenJas also simply noted "C. Attack simulation training". Therefore C is correct.

Why the Other Options Are Wrong

Exposure insights shows posture data and recommendations but does not run a simulated password-reset email or track clickers. Learning hub provides training content, so it can educate users but cannot emulate the lure or report link selection. Threat tracker visualizes threat detections and campaigns, not an internal awareness simulation. Crille initially suggested A but reasoned that "C is for learn user not to click on link with suspicious things" — actually that training-and-tracking combination is exactly what attack simulation training supplies.

Community Comment Notes

Most commenters selected C, and Krayzr noted it is a "Repeated Question", indicating this scenario appears regularly in MS-102 dumps. Iccen asked for correction but was right. Crille's doubt about A shows the common trap of confusing Exposure insights with active simulation. The community consensus and the Microsoft documentation align on attack simulation training.

Official Reference

Exam Strategy

For MS-102 Defender for Office 365 scenarios, map the verbs in the requirement: simulate and track a phishing lure plus assign training points directly to Attack simulation training. If the option only reports posture, shows threat data, or hosts learning content, it lacks the active campaign capability the question demands.

Frequently Asked Questions

Why is Learning hub not the answer for social engineering awareness?

Learning hub only provides security awareness content; it cannot create the password-reset phishing simulation or track users who click the link like attack simulation training does.

What does attack simulation training track after a simulated password-reset email?

It records payload link clicks and can automatically assign or suggest follow-up training to users who interact with the simulated message.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide