mediumMultiple Choice
SC-200 Practice Question: A security analyst is investigating a phishing…
A security analyst is investigating a phishing incident and needs to find the specific email message that was delivered to a user. The analyst knows the subject line and the sender domain. Which advanced hunting table should the analyst query?
⚠ Common exam trap
Many candidates confuse EmailEvents with EmailPostDeliveryEvents, thinking post-delivery actions are needed to find the original message, but EmailEvents is the only table that stores the subject and sender domain for delivered emails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents
The EmailEvents table in Microsoft Defender XDR's advanced hunting schema contains the core properties of email messages, including subject line, sender domain, recipient details, and delivery status. Since the analyst needs to find a specific email by subject and sender domain, this table is the correct starting point for querying delivered messages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailEvents
Why this is correct
EmailEvents is the central email record in the Microsoft 365 Defender advanced hunting schema. It stores one row per email delivery event and contains the message-level metadata needed for a phishing investigation: subject (Subject), sender and sender domain (SenderFromAddress/SenderMailFromDomain), recipient (RecipientEmailAddress), and the delivery status (DeliveryAction/DeliveryLocation). Therefore it is the correct starting point for correlating a suspected phish.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo stores attachment-centric details such as the file name, file size, and SHA-256 hash for each file attached to an email. It does not include the email subject, sender domain, or delivery status, so it cannot answer the question directly. However, it can be joined to EmailEvents by NetworkMessageId if you need to pivot from a suspicious attachment back to the email's metadata.
- ✗
EmailUrlInfo
Why it's wrong here
EmailUrlInfo contains the URLs and link domains extracted from the body of an email message, along with their detection verdicts if any. It is focused on URL-based indicators and does not carry the email's subject line or sender domain, which belong to the EmailEvents table. You would query it only after you have the email identifier (NetworkMessageId) and want to examine embedded links.
- ✗
EmailPostDeliveryEvents
Why it's wrong here
EmailPostDeliveryEvents logs events that occur after a message has been delivered, such as an admin or user action like 'Email reported by user', 'Email forwarded', or a link click event. These records reference the original message through NetworkMessageId but do not store the initial email metadata such as subject, sender domain, recipient, or final delivery status. Thus it is only useful for investigating what happened after delivery, not the original phishing email's identifying details.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.