easyMultiple Choice
SC-200 Practice Question: A security analyst in Microsoft 365 Defender is…
A security analyst in Microsoft 365 Defender is investigating an incident that involves a malicious email attachment. Which advanced hunting table should the analyst use to find information about the email including sender, recipient, and subject?
⚠ Common exam trap
Candidates often confuse the purpose of the tables, thinking EmailAttachmentInfo or EmailUrlInfo contain the email header data, when in fact they only store metadata about specific elements (attachments or URLs) and require a join with EmailEvents to get sender/recipient/subject.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents
The EmailEvents table in Microsoft 365 Defender advanced hunting contains the core email metadata, including sender (SenderFromAddress), recipient (RecipientEmailAddress), and subject (Subject). This table records events such as email delivery, blocking, and filtering actions, making it the primary source for investigating email-related incidents. The other tables focus on specific components like attachments or URLs, not the full email envelope details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailEvents
Why this is correct
EmailEvents is the correct choice because it is the primary Microsoft 365 Defender advanced hunting table that stores email message-level metadata, including the sender (From), recipient (To), subject, delivery status, and critical identifiers like NetworkMessageId and InternetMessageId. When investigating an email-related incident, this table provides the authoritative record of the email's header and routing details, enabling correlation of delivery and threat actions.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo is incorrect because although it does store per-attachment data such as file name, SHA-256 hash, and file size, its schema is keyed to the attachment rather than the message header. You would use this table after already identifying the relevant email in EmailEvents to pivot into malicious file details, but it does not contain the sender, recipient, subject, or delivery status needed to answer an email-header investigation.
- ✗
EmailUrlInfo
Why it's wrong here
EmailUrlInfo is not the right table because its rows are individual URLs extracted from the email body, not the email's envelope or header metadata. This table is designed for pivot-oriented hunting from a known message to web threats (e.g., phishing links), and it lacks the sender, recipient, and delivery-status fields that are fundamental to the incident query being run.
- ✗
IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents is unrelated to email content because it records cloud app authentication and sign-in activity—such as user logon timestamps, IP addresses, and success/failure results—across services like Microsoft Entra ID and Exchange Online. Investigating email header details requires a table in the Email schema (EmailEvents), not the Identity schema, which would only be relevant if the incident also involved anomalous logon behavior.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.