Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst is investigating a phishing…

A security analyst is investigating a phishing campaign targeting multiple users. The analyst has identified a malicious attachment with a known SHA256 hash. The analyst needs to find all email messages that were delivered to any user and contained this specific attachment. Which advanced hunting table should the analyst query in Microsoft 365 Defender to obtain the message IDs of emails containing the attachment?

⚠ Common exam trap

Many candidates confuse EmailAttachmentInfo with EmailEvents, mistakenly thinking that EmailEvents contains attachment details, when in fact EmailEvents only provides delivery-level metadata and requires a join to access attachment-specific information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EmailAttachmentInfo

The EmailAttachmentInfo table in Microsoft 365 Defender advanced hunting contains metadata about attachments on email messages, including the SHA256 hash of each attachment. By querying this table with the known malicious SHA256 hash, the analyst can retrieve the NetworkMessageId values for all emails that contained that specific attachment, regardless of whether the email was delivered or blocked.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents contains one row per email with metadata like sender, recipient, subject, and delivery status, but its schema does not include columns for attachment file names or SHA256 hashes. Therefore, filtering EmailEvents directly by a known malicious hash will return no rows, because attachment-to-message mapping is held in a separate table. To pivot from a hash, you must first query EmailAttachmentInfo to obtain the NetworkMessageId, then join EmailEvents for delivery context.

  • ✓

    EmailAttachmentInfo

    Why this is correct

    EmailAttachmentInfo is correct because it stores each attachment's file name, size, and SHA256 hash, along with the parent email's NetworkMessageId in Microsoft 365 Defender's advanced hunting schema. Querying this table with a known malicious SHA256 returns all NetworkMessageIds for messages that contained that exact file, allowing you to identify every recipient in the phishing campaign. You can then join EmailEvents to gather sender, subject, and delivery status details for further analysis.

  • ✗

    EmailPostDeliveryEvents

    Why it's wrong here

    EmailPostDeliveryEvents records actions taken on messages after they reach the mailbox, such as administrator moves to quarantine, ZAP removals, or user-reported phishing submissions. Its schema does not include any attachment hash column, so it cannot be used to search for emails by file hash. It is only useful later in an investigation, after EmailAttachmentInfo has identified the NetworkMessageIds, to understand how users and the system responded to the phishing email.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents records endpoint file system activity such as file creation, modification, and deletion, including cryptographic hashes of files that exist on a device. However, it lacks email envelope data and the email NetworkMessageId, so it cannot associate an attachment hash with a specific phishing email. It only shows post-delivery artifacts after a user has downloaded or executed the payload, not the original email delivery event.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst is investigating a potential phishing campaign and has identified a malicious attachment with a known SHA256 hash. The analyst needs to find all email messages that were delivered to users and contained this exact attachment. Which advanced hunting table should the analyst query to obtain the network message IDs of the relevant emails?

easy
  • A.EmailEvents
  • ✓ B.EmailAttachmentInfo
  • C.EmailUrlInfo
  • D.EmailPostDeliveryEvents

Why B: The EmailAttachmentInfo table in Microsoft 365 Advanced Hunting contains records of every attachment in email messages, including the SHA256 hash. By querying this table with the known hash, the analyst can retrieve the NetworkMessageId values for all emails that contained that specific malicious attachment, enabling further investigation into delivery and impact.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.