正解:B
The correct answer is Create a Tenant payload . In Microsoft Defender for Office 365 Attack simulation training, the payload is the simulated phishing email content presented to users. Microsoft defines a payload as the link, QR code, or attachment in the simulated phishing email message. For the Credential Harvest technique, the payload is the phishing email that drives the user to interact with a simulated credential-capture scenario. Microsoft also states that while Attack simulation training includes built-in payloads, administrators can create custom payloads that work better for their organization. Tenant payloads are the organization- created payloads, so they are the correct choice when the email must contain organization-specific wording, branding, and a custom phishing link.
A Global payload is Microsoft-provided and generic, so it will not satisfy the requirement for company- based terminology and branding. Custom end-user notifications are used for training or notification messages after simulation events, not for defining the phishing email itself. A tenant landing page controls the page shown after the user interacts with the phishing link; it does not define the email message content.
Therefore, the simulation must use a Tenant payload .