mediumMultiple Choice
SC-200 Practice Question: A security analyst is investigating a phishing…
A security analyst is investigating a phishing campaign targeting multiple users. The analyst has identified a malicious attachment with a known SHA256 hash. The analyst needs to find all email messages that were delivered to any user and contained this specific attachment. Which advanced hunting table should the analyst query in Microsoft 365 Defender to obtain the message IDs of emails containing the attachment?
⚠ Common exam trap
Many candidates confuse EmailAttachmentInfo with EmailEvents, mistakenly thinking that EmailEvents contains attachment details, when in fact EmailEvents only provides delivery-level metadata and requires a join to access attachment-specific information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailAttachmentInfo
The EmailAttachmentInfo table in Microsoft 365 Defender advanced hunting contains metadata about attachments on email messages, including the SHA256 hash of each attachment. By querying this table with the known malicious SHA256 hash, the analyst can retrieve the NetworkMessageId values for all emails that contained that specific attachment, regardless of whether the email was delivered or blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EmailEvents
Why it's wrong here
EmailEvents contains one row per email with metadata like sender, recipient, subject, and delivery status, but its schema does not include columns for attachment file names or SHA256 hashes. Therefore, filtering EmailEvents directly by a known malicious hash will return no rows, because attachment-to-message mapping is held in a separate table. To pivot from a hash, you must first query EmailAttachmentInfo to obtain the NetworkMessageId, then join EmailEvents for delivery context.
- ✓
EmailAttachmentInfo
Why this is correct
EmailAttachmentInfo is correct because it stores each attachment's file name, size, and SHA256 hash, along with the parent email's NetworkMessageId in Microsoft 365 Defender's advanced hunting schema. Querying this table with a known malicious SHA256 returns all NetworkMessageIds for messages that contained that exact file, allowing you to identify every recipient in the phishing campaign. You can then join EmailEvents to gather sender, subject, and delivery status details for further analysis.
- ✗
EmailPostDeliveryEvents
Why it's wrong here
EmailPostDeliveryEvents records actions taken on messages after they reach the mailbox, such as administrator moves to quarantine, ZAP removals, or user-reported phishing submissions. Its schema does not include any attachment hash column, so it cannot be used to search for emails by file hash. It is only useful later in an investigation, after EmailAttachmentInfo has identified the NetworkMessageIds, to understand how users and the system responded to the phishing email.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents records endpoint file system activity such as file creation, modification, and deletion, including cryptographic hashes of files that exist on a device. However, it lacks email envelope data and the email NetworkMessageId, so it cannot associate an attachment hash with a specific phishing email. It only shows post-delivery artifacts after a user has downloaded or executed the payload, not the original email delivery event.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst is investigating a potential phishing campaign and has identified a malicious attachment with a known SHA256 hash. The analyst needs to find all email messages that were delivered to users and contained this exact attachment. Which advanced hunting table should the analyst query to obtain the network message IDs of the relevant emails?
easy- A.EmailEvents
- ✓ B.EmailAttachmentInfo
- C.EmailUrlInfo
- D.EmailPostDeliveryEvents
Why B: The EmailAttachmentInfo table in Microsoft 365 Advanced Hunting contains records of every attachment in email messages, including the SHA256 hash. By querying this table with the known hash, the analyst can retrieve the NetworkMessageId values for all emails that contained that specific malicious attachment, enabling further investigation into delivery and impact.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.