mediumMultiple Choice
SC-200 Practice Question: A security analyst is investigating a potential…
A security analyst is investigating a potential data exfiltration incident in Microsoft 365 Defender. They have identified a suspicious email sent to an external recipient containing an attachment. They want to know if the attachment has been opened and if any sensitive data was accessed. Which advanced hunting table should the analyst query to find email attachment activities, such as file download or view?
⚠ Common exam trap
Watch out — candidates often confuse EmailAttachmentInfo (which only provides static metadata) with EmailEvents (which includes user actions), leading them to select the wrong table for activity tracking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents
B is correct because EmailEvents is the advanced hunting table in Microsoft 365 Defender that captures email-level activities, including whether an attachment was opened or viewed by the recipient. This table contains actions such as 'Email open' and 'Attachment open', which directly answer the analyst's question about attachment access and potential data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents is an Advanced Hunting table that records endpoint file operations such as file creation, modification, or deletion. While opening an attachment may generate a device-level file event when the file is written to disk by the mail client, it does not directly capture the email attachment action like 'EmailAttachmentOpened' or 'EmailAttachmentDownloaded'. It lacks the email context (sender, subject, mailbox) and the action type tied to the mail flow, so it is the wrong table for confirming a user opened an attachment from a specific email.
- ✓
EmailEvents
Why this is correct
EmailEvents is the correct Advanced Hunting table because it contains the action types for user interactions with email attachments. Specifically, it includes columns like ActionType with values such as EmailAttachmentOpened or EmailAttachmentDownloaded, and it records the email metadata (sender, recipient, subject, and timestamp) associated with those actions. This table directly ties the attachment open event to the email message, making it ideal for investigating potential data exfiltration or phishing attachment engagement.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo provides attachment metadata such as file name, file size, file type, and SHA256 hash, but it is a reference table, not an event log. It does not have a column that indicates whether the attachment was opened, downloaded, or otherwise acted upon by the user. To find the action, you must join EmailAttachmentInfo to EmailEvents via the NetworkMessageId or other key, so the verdict is wrong because it lacks the required action/event data.
- ✗
UrlClickEvents
Why it's wrong here
UrlClickEvents tracks clicks on URLs, including links embedded in email messages, by the Safe Links service. It records evidence of user interaction with a web link, not with an email attachment. Attachment open/download events are separate and stored in EmailEvents, while UrlClickEvents would only be relevant if the attack involved a malicious URL rather than a malicious attachment. Therefore, it is incorrect for this investigation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst in Microsoft 365 Defender is investigating an incident that involves a malicious email attachment. Which advanced hunting table should the analyst use to find information about the email including sender, recipient, and subject?
easy- ✓ A.EmailEvents
- B.EmailAttachmentInfo
- C.EmailUrlInfo
- D.IdentityLogonEvents
Why A: The EmailEvents table in Microsoft 365 Defender advanced hunting contains the core email metadata, including sender (SenderFromAddress), recipient (RecipientEmailAddress), and subject (Subject). This table records events such as email delivery, blocking, and filtering actions, making it the primary source for investigating email-related incidents. The other tables focus on specific components like attachments or URLs, not the full email envelope details.
Variation 2. A security analyst is reviewing phishing emails in Microsoft 365 Defender and wants to identify all messages that were blocked by an anti-phish policy before delivery. The analyst plans to use advanced hunting. Which table column indicates whether an email was blocked as phishing?
easy- ✓ A.EmailEvents table, the 'DeliveryAction' column
- B.EmailPostDeliveryEvents table, the 'Action' column
- C.EmailAttachmentInfo table, the 'FileType' column
- D.EmailUrlInfo table, the 'Url' column
Why A: The EmailEvents table records actions taken on emails before delivery, including whether a message was blocked by anti-phish policies. The 'DeliveryAction' column specifically indicates the final disposition, such as 'Blocked' for phishing. This makes it the correct source for identifying pre-delivery phishing blocks in advanced hunting.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.