Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst uses Microsoft 365 Defender…

A security analyst uses Microsoft 365 Defender advanced hunting to investigate a phishing campaign. The analyst knows the Internet Message ID of a malicious email. Which table should the analyst query to find all users who received that specific email?

⚠ Common exam trap

Test-takers frequently confuse EmailEvents with EmailPostDeliveryEvents, assuming post-delivery actions include recipient data, but EmailPostDeliveryEvents only logs post-delivery events like user clicks or remediation actions, not the original recipient list.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EmailEvents

The EmailEvents table in Microsoft 365 Defender advanced hunting stores records of email transactions, including the Internet Message ID and recipient information. By querying this table with the known Internet Message ID, the analyst can retrieve all users who received that specific email, as it contains the RecipientEmailAddress field for each delivery event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    EmailEvents

    Why this is correct

    EmailEvents is the authoritative table for email delivery metadata; it stores one record for each email event, capturing sender, recipient, subject, InternetMessageId, and delivery status at the moment of delivery. Querying this table directly with the InternetMessageId returns all message records and their full envelope information, making it the correct starting point for an email investigation.

  • ✗

    EmailAttachmentInfo

    Why it's wrong here

    EmailAttachmentInfo is designed to hold attachment-centric data such as filename, file size, SHA256 hash, and file type, but it does not store delivery attributes like recipient addresses, subject lines, or send timestamps. While it can be linked to EmailEvents through InternetMessageId, querying it alone will only yield attachment details, not the email's recipient distribution, so it is unsuitable for identifying who received a specific InternetMessageId.

  • ✗

    EmailUrlInfo

    Why it's wrong here

    EmailUrlInfo contains rows representing URLs found in email bodies or links, along with threat indicators like reputation and detection status, but it lacks the email envelope fields such as sender, recipient, and delivery outcome. Because it is scoped to link-level telemetry, searching it by InternetMessageId would return only the URLs associated with that message, not the email's recipient list, making it the wrong table for this query.

  • ✗

    EmailPostDeliveryEvents

    Why it's wrong here

    EmailPostDeliveryEvents focuses on actions taken on an email after it reaches the mailbox, such as user clicks, forwarding, or reporting as phishing, including the timestamp and action type. It does not capture the original delivery context like the sender, recipient, or the InternetMessageId assigned at send time; therefore, querying it cannot reconstruct the set of emails delivered, which is why relying on this table would miss the core delivery metadata needed.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.