Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst is investigating a phishing…

A security analyst is investigating a phishing incident and needs to find the specific email message that was delivered to a user. The analyst knows the subject line and the sender domain. Which advanced hunting table should the analyst query?

⚠ Common exam trap

Many candidates confuse EmailEvents with EmailPostDeliveryEvents, thinking post-delivery actions are needed to find the original message, but EmailEvents is the only table that stores the subject and sender domain for delivered emails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EmailEvents

The EmailEvents table in Microsoft Defender XDR's advanced hunting schema contains the core properties of email messages, including subject line, sender domain, recipient details, and delivery status. Since the analyst needs to find a specific email by subject and sender domain, this table is the correct starting point for querying delivered messages.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    EmailEvents

    Why this is correct

    EmailEvents is the central email record in the Microsoft 365 Defender advanced hunting schema. It stores one row per email delivery event and contains the message-level metadata needed for a phishing investigation: subject (Subject), sender and sender domain (SenderFromAddress/SenderMailFromDomain), recipient (RecipientEmailAddress), and the delivery status (DeliveryAction/DeliveryLocation). Therefore it is the correct starting point for correlating a suspected phish.

  • ✗

    EmailAttachmentInfo

    Why it's wrong here

    EmailAttachmentInfo stores attachment-centric details such as the file name, file size, and SHA-256 hash for each file attached to an email. It does not include the email subject, sender domain, or delivery status, so it cannot answer the question directly. However, it can be joined to EmailEvents by NetworkMessageId if you need to pivot from a suspicious attachment back to the email's metadata.

  • ✗

    EmailUrlInfo

    Why it's wrong here

    EmailUrlInfo contains the URLs and link domains extracted from the body of an email message, along with their detection verdicts if any. It is focused on URL-based indicators and does not carry the email's subject line or sender domain, which belong to the EmailEvents table. You would query it only after you have the email identifier (NetworkMessageId) and want to examine embedded links.

  • ✗

    EmailPostDeliveryEvents

    Why it's wrong here

    EmailPostDeliveryEvents logs events that occur after a message has been delivered, such as an admin or user action like 'Email reported by user', 'Email forwarded', or a link click event. These records reference the original message through NetworkMessageId but do not store the initial email metadata such as subject, sender domain, recipient, or final delivery status. Thus it is only useful for investigating what happened after delivery, not the original phishing email's identifying details.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.