easyMultiple Choice
SC-200 Practice Question: A security analyst uses Microsoft 365 Defender…
A security analyst uses Microsoft 365 Defender advanced hunting to investigate a phishing campaign. The analyst knows the Internet Message ID of a malicious email. Which table should the analyst query to find all users who received that specific email?
⚠ Common exam trap
Test-takers frequently confuse EmailEvents with EmailPostDeliveryEvents, assuming post-delivery actions include recipient data, but EmailPostDeliveryEvents only logs post-delivery events like user clicks or remediation actions, not the original recipient list.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents
The EmailEvents table in Microsoft 365 Defender advanced hunting stores records of email transactions, including the Internet Message ID and recipient information. By querying this table with the known Internet Message ID, the analyst can retrieve all users who received that specific email, as it contains the RecipientEmailAddress field for each delivery event.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailEvents
Why this is correct
EmailEvents is the authoritative table for email delivery metadata; it stores one record for each email event, capturing sender, recipient, subject, InternetMessageId, and delivery status at the moment of delivery. Querying this table directly with the InternetMessageId returns all message records and their full envelope information, making it the correct starting point for an email investigation.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo is designed to hold attachment-centric data such as filename, file size, SHA256 hash, and file type, but it does not store delivery attributes like recipient addresses, subject lines, or send timestamps. While it can be linked to EmailEvents through InternetMessageId, querying it alone will only yield attachment details, not the email's recipient distribution, so it is unsuitable for identifying who received a specific InternetMessageId.
- ✗
EmailUrlInfo
Why it's wrong here
EmailUrlInfo contains rows representing URLs found in email bodies or links, along with threat indicators like reputation and detection status, but it lacks the email envelope fields such as sender, recipient, and delivery outcome. Because it is scoped to link-level telemetry, searching it by InternetMessageId would return only the URLs associated with that message, not the email's recipient list, making it the wrong table for this query.
- ✗
EmailPostDeliveryEvents
Why it's wrong here
EmailPostDeliveryEvents focuses on actions taken on an email after it reaches the mailbox, such as user clicks, forwarding, or reporting as phishing, including the timestamp and action type. It does not capture the original delivery context like the sender, recipient, or the InternetMessageId assigned at send time; therefore, querying it cannot reconstruct the set of emails delivered, which is why relying on this table would miss the core delivery metadata needed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.