Courseiva
mediumMultiple Choice

Querying Email Delivery Events with EmailEvents

A security analyst is investigating a suspicious email that was reported by a user. The email contains an attachment with a known malicious macro. The analyst wants to find all instances of this same email being delivered to other users in the organization. Which Advanced Hunting table should the analyst query to find the delivery events?

Quick Answer

The answer is the EmailEvents table. This is correct because EmailEvents in Microsoft Defender XDR Advanced Hunting captures every email delivery event across the organization, including sender, recipient, subject, and delivery status, making it the precise table to query when you need to find all instances of a specific email—identified by its NetworkMessageId—that was delivered to other users. On the SC-200 exam, this question tests your ability to map investigative goals to the correct Advanced Hunting schema; a common trap is confusing EmailEvents with EmailAttachmentInfo (which stores attachment metadata but not delivery events) or EmailPostDeliveryEvents (which tracks actions after delivery). Remember that delivery events are the core of EmailEvents, so if the scenario asks where an email was sent or delivered, start here. A helpful memory tip: think of EmailEvents as the “shipping log” for every email that landed in a mailbox.

⚠ Common exam trap

Test-takers frequently confuse EmailAttachmentInfo (which contains attachment hashes) with EmailEvents, assuming attachment data alone can identify all recipients, but only EmailEvents holds the delivery event records needed to find every user who received the email.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EmailEvents

The EmailEvents table in Microsoft Defender XDR Advanced Hunting contains records of email delivery events, including sender, recipient, subject, and delivery status. Since the analyst needs to find all instances where the same email (with the malicious macro attachment) was delivered to other users, querying EmailEvents with the email's unique identifier (e.g., NetworkMessageId) will return all delivery events across the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EmailAttachmentInfo

    Why it's wrong here

    EmailAttachmentInfo holds metadata about attachments such as file name, hash and verdict, but not the delivery events or recipient list. It would be correct for identifying the attachment's SHA256, yet finding all deliveries of the same email requires the email events table.

  • ✓

    EmailEvents

    Why this is correct

    EmailEvents records delivery, block and post-delivery events for messages, including sender, recipient, subject and verdict. Querying it for the malicious attachment's sender or subject hash reveals every mailbox that received the same email, which is exactly the delivery evidence required.

  • ✗

    EmailUrlInfo

    Why it's wrong here

    EmailUrlInfo stores URLs extracted from emails and their verdicts, so it holds no attachment or delivery metadata. It would be correct when investigating a malicious link, but this scenario concerns a macro-bearing attachment, which requires the email events table recording delivery and recipients.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents records file creation, modification and deletion activity on endpoints, so it captures macro execution artefacts rather than mail delivery. It would be the right table for tracing a dropped payload on a device, but delivery to other recipients requires the email events table.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst is investigating a phishing incident and needs to find the specific email message that was delivered to a user. The analyst knows the subject line and the sender domain. Which advanced hunting table should the analyst query?

medium
  • ✓ A.EmailEvents
  • B.EmailAttachmentInfo
  • C.EmailUrlInfo
  • D.EmailPostDeliveryEvents

Why A: The EmailEvents table in Microsoft Defender XDR's advanced hunting schema contains the core properties of email messages, including subject line, sender domain, recipient details, and delivery status. Since the analyst needs to find a specific email by subject and sender domain, this table is the correct starting point for querying delivered messages.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.