easyMultiple Choice
SC-200 Practice Question: A security analyst is reviewing a phishing…
A security analyst is reviewing a phishing incident in Microsoft 365 Defender. They need to find all users who received a specific email message by searching for the email's Internet Message ID. Which advanced hunting table should the analyst query?
⚠ Common exam trap
Test-takers frequently confuse the Internet Message ID with other identifiers like the NetworkMessageId (a Microsoft-generated ID) or assume attachment or URL tables contain recipient data, leading them to pick EmailAttachmentInfo or EmailUrlInfo instead of EmailEvents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents
The EmailEvents table in Advanced Hunting stores metadata about email transactions, including the Internet Message ID (a unique identifier defined in RFC 5322). By querying this table with the specific Internet Message ID, the analyst can retrieve all recipients who received that exact email, making it the correct choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailEvents
Why this is correct
EmailEvents is the correct table because it stores the metadata for every email message processed by Microsoft 365, including the InternetMessageId header that uniquely identifies a particular message. Querying on InternetMessageId lets an analyst retrieve every row for that message, and each row contains RecipientEmailAddress, so aggregating those rows lists all recipients of the phishing email. This table also includes subject, sender, and delivery status, making it the central starting point for email incident investigation.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo focuses on attachment metadata, such as fileName, SHA256 hash, file size, and the verdict from detonation or reputation services. Rows in this table do not include the recipient email address; at most they reference the parent message via NetworkMessageId. To map a malicious attachment back to every mailbox that received it, you must join EmailAttachmentInfo to EmailEvents on NetworkMessageId, but the recipient list itself comes from EmailEvents, not from EmailAttachmentInfo.
- ✗
EmailUrlInfo
Why it's wrong here
EmailUrlInfo is designed for investigating URLs extracted from email bodies and includes fields like Url, UrlDomain, and threat detection verdicts. It does not contain recipient address fields, so it is not the table where you would find who received the message; its purpose is to identify malicious links and correlate with click activity. A hunt for URL-related indicators therefore needs to join to EmailEvents for recipient identity, but the correct table for the recipient list remains EmailEvents itself.
- ✗
AADSignInEventsBeta
Why it's wrong here
AADSignInEventsBeta tracks authentication activity in Microsoft Entra ID, such as successful or failed sign-ins and conditional access results for user accounts. It does not contain email message metadata, recipient address lists, or message delivery information, so it cannot reveal everyone who received the phishing email. While this table can help identify an account that was later compromised, it is not the correct source for tracing message recipients.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.