How to Purge Malicious Mail Already Delivered to a Mailbox in Defender?

Implement and manage email and collaboration protection by using Microsoft Defender for Office 365
Answer Correct answer: A — Enable zero-hour auto purge (ZAP) in Policy1 so malicious messages already delivered to the mailbox are retroactively quarantined.

You have a Microsoft 365 E5 subscription. You plan to create an anti-malware policy named Policy1. You need to ensure that Policy1 can detect malicious email messages that were already delivered to a user's mailbox. What should you do in the Microsoft Defender portal?

  1. Enable zero-hour auto purge (ZAP). Correct Answer
  2. Enable enhanced filtering.
  3. Configure a quarantine policy.
  4. Modify the common attachments filter.

Community Votes

A
83%
B
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you know which Defender for Office 365 feature works retroactively on delivered mail, and the trap is confusing it with enhanced filtering, which only corrects connector/SPF-based filtering for inbound hybrid mail.

Anti-malware policies in Microsoft Defender for Office 365 can act on messages that were already delivered, but only through zero-hour auto purge (ZAP). This page confirms that enabling ZAP in Policy1 is what lets it detect and act on malicious email already sitting in a user's mailbox.

Choosing enhanced filtering (B) because the phrase suggests stronger detection, when in fact enhanced filtering only fixes false-positive filtering for mail relayed through an on-premises connector — it never revisits or purges messages already in a mailbox.

Community Discussion (3 comments)

JohnDoe47 👍 7
The given answer A (ZAP) is correct. https://learn.microsoft.com/en-us/defender-office-365/zero-hour-auto-purge
kosikovec 👍 5 Selected: A
https://learn.microsoft.com/en-us/defender-office-365/zero-hour-auto-purge
HamitB 👍 1 Selected: B
Enhanced Filtering: This feature in Microsoft Defender for Office 365 provides advanced protection against malware, phishing attacks, and other threats. It scans incoming and outgoing emails, including those already delivered to user mailboxes, and can take actions like quarantining or deleting malicious messages.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Zero-hour auto purge (ZAP) is the only mechanism listed that operates on mail after delivery: when Microsoft's spam, malware, phish or high-confidence-phish verdicts are updated for a message that already reached the inbox, ZAP moves it to quarantine (or junk) and notifies the recipient. Because the scenario explicitly says Policy1 must "detect malicious email messages that were already delivered to a user's mailbox," the anti-malware policy needs ZAP enabled, which is exactly option A. The Defender portal exposes the ZAP toggle in the policy family that matches the threat (anti-malware policy for malware ZAP, anti-spam policy for spam/phish ZAP), so enabling it inside Policy1 satisfies the requirement. Malware ZAP is on by default tenant-wide, but the question asks what to do to ensure the capability, and enabling ZAP is the documented answer.

Why the Other Options Are Wrong

Enhanced filtering (B) enables Exchange Online to recognize the last-hop IP of an on-premises mail server and apply skip-listing/anti-spoofing intelligence to mail routed through that connector — it changes how inbound mail is filtered, not what happens to messages already delivered. A quarantine policy (C) only defines what a detained message looks like (retention, recipient notifications, permissions) and cannot by itself reach into mailboxes to find already-delivered threats. The common attachments filter (D) blocks messages whose attachments match a file-type or file-extension list at transport time, so it is purely preventive and never retrospective. None of B, C or D can satisfy the "already delivered" condition in the stem.

Community Comment Notes

Community consensus matches the answer: JohnDoe47 states "The given answer A (ZAP) is correct" and links the official Learn article, and kosikovec posts the same zero-hour auto purge documentation URL, reinforcing that the retroactive-purge behaviour is what the question is testing. HamitB chose B, arguing that enhanced filtering "provides advanced protection" and scans mail "already delivered to user mailboxes" — but that claim misreads the feature: enhanced filtering is a hybrid-connector filtering fix, not a retroactive purge engine. The vote split (83 for A, 17 for B) reflects the same misunderstanding of enhanced filtering, so treat the ZAP documentation, not the vote count, as the deciding evidence.

Official Reference

Exam Strategy

When a Defender for Office 365 stem contains words like "already delivered," "recall," or "remove after delivery," eliminate every option whose effect happens at transport time (filters, quarantine policies) and look for ZAP. Then check which policy family the scenario names — anti-malware policy for malware ZAP — and pick the option that turns ZAP on there.

Frequently Asked Questions

Why does enhanced filtering not remove malicious mail already in a mailbox?

Enhanced filtering only lets Exchange Online trust the last-hop IP and SPF handling of an on-premises connector so hybrid mail is filtered correctly. It never revisits or deletes messages that were already delivered.

Do I configure ZAP in an anti-malware policy in the Defender portal?

Yes. Malware ZAP is controlled from the anti-malware policy family in the Microsoft Defender portal; spam and phishing ZAP live in the anti-spam policy. Malware ZAP is on by default but can be toggled.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide