mediumMultiple Choice
SC-200 Practice Question: A security analyst is investigating a user who…
A security analyst is investigating a user who may have been compromised. The analyst sees a sign-in from an unusual location and then a series of suspicious actions performed by that user, including deleting files and sending emails. The analyst wants to find all emails sent by the user after the anomalous sign-in. Which advanced hunting tables should be used?
⚠ Common exam trap
Many exam-takers confuse DeviceFileEvents or DeviceEvents with email-related tables, forgetting that email actions are logged in EmailEvents, not in endpoint-level event tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents and IdentityLogonEvents
The investigation requires correlating a specific sign-in event (from IdentityLogonEvents) with subsequent email activity (from EmailEvents). IdentityLogonEvents captures authentication details including location, while EmailEvents records email send/receive metadata. Joining these tables on the user principal name (UPN) and timestamp allows the analyst to filter all emails sent after the anomalous sign-in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailEvents and IdentityLogonEvents
Why this is correct
EmailEvents is the authoritative table for email activity, containing sender, recipient, subject, and send timestamp, while IdentityLogonEvents provides authentication context such as IP address, device, and sign-in time. Joining these two tables on the user account and a time window lets the analyst identify emails sent immediately after an anomalous sign-in, which is a key indicator of account compromise. This correlation directly answers whether the user (or an attacker using the user's identity) sent emails from the suspicious session.
- ✗
EmailEvents and DeviceFileEvents
Why it's wrong here
DeviceFileEvents tracks file operations on endpoints, including creation, modification, and deletion of local files, but it does not record email transmission metadata like sender, recipient, or message ID. While an email client might create a temporary or cached file during composition, this table cannot reliably prove that an email was sent from the user's mailbox, and it lacks any sign-in or authentication data to link the activity to a specific suspicious logon. Therefore, pairing EmailEvents with DeviceFileEvents would miss the crucial identity correlation needed for this investigation.
- ✗
IdentityLogonEvents and DeviceEvents
Why it's wrong here
IdentityLogonEvents and DeviceEvents can show that a user signed in and that some device-level activity occurred, but neither table contains email-specific fields such as message submission, recipient address, or send status. DeviceEvents might capture process creations or network connections, including possibly an email client communicating with an Exchange server, but that is indirect, noisy, and does not enumerate emails sent by the user. Without EmailEvents, the analyst cannot correlate the suspicious sign-in to actual email transactions, so this pairing is insufficient.
- ✗
EmailAttachmentInfo and EmailUrlInfo alone
Why it's wrong here
EmailAttachmentInfo and EmailUrlInfo are enrichment tables that describe files and URLs referenced in emails, but they do not contain the core message envelope—sender, recipients, subject, and send time—nor do they tie an email to a specific user's sign-in session. These tables are typically joined to EmailEvents via a common message ID; using them alone leaves the analyst with detached artifact details and no way to determine which emails the targeted user actually sent. Additionally, without IdentityLogonEvents, the critical temporal link between the suspicious sign-in and subsequent email activity is lost.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.