mediumMultiple Choice
SC-200 Practice Question: A security analyst wants to create a custom…
A security analyst wants to create a custom detection rule in Microsoft 365 Defender that alerts when a user receives more than 5 emails with the same attachment name within 1 hour, indicating a possible malware campaign. Which advanced hunting tables should be joined to achieve this detection?
⚠ Common exam trap
Many exam-takers think they need to join with endpoint file events (DeviceFileEvents) to detect malware, but the question specifically requires detecting the email receipt pattern, not post-delivery execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Join EmailEvents and EmailAttachmentInfo on NetworkMessageId
To detect when a user receives more than 5 emails with the same attachment name within 1 hour, you need to correlate email metadata with attachment details. The EmailEvents table contains email-level information (e.g., recipient, timestamp), while the EmailAttachmentInfo table stores attachment-level data (e.g., file name). Joining these on NetworkMessageId allows you to count occurrences of the same attachment name per recipient within a time window, enabling the custom detection rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Join EmailEvents and EmailAttachmentInfo on NetworkMessageId
Why this is correct
Joining EmailEvents to EmailAttachmentInfo on NetworkMessageId is correct because NetworkMessageId uniquely identifies a single email message in both tables, and this preserves the relationship between the recipient (in EmailEvents) and each attached file (in EmailAttachmentInfo). This join lets you count emails by RecipientEmailAddress and FileName within a specified time bucket, which is exactly what a detection rule for attachment-based threats requires. Because EmailAttachmentInfo contains one row per attachment, you can aggregate with summarize count() and optionally bin the Timestamp to detect spikes in attachments per user.
- ✗
Join EmailEvents and EmailUrlInfo on NetworkMessageId
Why it's wrong here
Joining EmailEvents to EmailUrlInfo on NetworkMessageId targets URLs found in the email body, not the names of files attached to the message. EmailUrlInfo stores URLs and their detection verdicts, so it has no column for filename, extension, or attachment size. Consequently, any query built this way would filter on URL data and completely ignore attachment content, allowing malicious files with no URL in the body to escape detection. It also loses the ability to count per attachment name because URL rows are unrelated to attachment attributes.
- ✗
Use only EmailAttachmentInfo table with a filter on file name
Why it's wrong here
Filtering only EmailAttachmentInfo on the file name is insufficient because this table lacks recipient identity, such as RecipientEmailAddress or UserId, which is essential for a per-user detection stat. The table stores metadata like FileName, SHA256, FileSize, and NetworkMessageId, but to know which user received that attachment you must join back to EmailEvents. Without that join, you can only see that a file was sent somewhere, not which users were targeted, nor can you correlate patterns such as the same attachment sent repeatedly to the same mailbox.
- ✗
Join EmailEvents and DeviceFileEvents on SHA1 hash
Why it's wrong here
Joining EmailEvents to DeviceFileEvents on SHA1 is conceptually flawed because DeviceFileEvents describes file operations on endpoint devices—creation, modification, deletion—not the files carried in an incoming email. Email attachment hashes are stored in EmailAttachmentInfo along with filename, not in DeviceFileEvents, and even if a hash matched, the join would not tell you which email recipient received the attachment. It would instead produce device-centric events, mixing unrelated telemetry and missing the per-recipient attachment count that the rule needs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.