easyMultiple Choice
SC-200 Practice Question: A security analyst wants to see the delivery…
A security analyst wants to see the delivery status and phishing verdict of an email. Which advanced hunting table should the analyst query in Microsoft 365 Defender?
⚠ Common exam trap
Many candidates confuse EmailEvents (initial delivery and verdict) with EmailPostDeliveryEvents (post-delivery actions), mistakenly thinking the latter includes the original verdict when it only records changes after delivery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents
The EmailEvents table in Microsoft 365 Defender's advanced hunting schema contains the delivery status (e.g., Delivered, Failed, Filtered as spam) and the phishing verdict (e.g., Phish, Normal) for each email. This table records the initial processing and classification of the email, making it the correct source for both pieces of information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailEvents
Why this is correct
EmailEvents is the primary advanced hunting schema for email security in Microsoft 365 Defender. Each row represents a distinct email message and includes fields such as DeliveryAction (e.g., Delivered, Junked, Blocked), ThreatTypes (e.g., Phish, Malware), and DetectionMethods. The Phish filter in Threat Explorer relies on this table because it contains the original verdict determined at the time of delivery, making it exactly what the analyst needs.
- ✗
EmailPostDeliveryEvents
Why it's wrong here
EmailPostDeliveryEvents is a separate advanced hunting table that records only what happened after an email was already delivered. It captures user-reported actions like 'ReportPhish' and automated remediation such as ZAP (Zero-Hour Auto Purge) deleting a message from a mailbox. Because these events occur after the initial delivery verdict, this table will never contain the original delivery status or phishing verdict - that information always resides in EmailEvents.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo is an advanced hunting table that exposes metadata about every file attached to an email, including the filename, file type, and SHA-256 hash. This data is valuable for correlating attachment-based threats, but it does not include the email's delivery status or the phishing verdict. An attacker could send a benign attachment with a phishing link, so attachment details alone cannot answer the analyst's question.
- ✗
EmailUrlInfo
Why it's wrong here
EmailUrlInfo is the advanced hunting table that lists every URL found in an email, along with domain and IP-related fields. It can be joined with EmailEvents to see whether a URL was detonated or related to a threat, but it does not contain the delivery disposition or phishing verdict for the email itself. The presence of a URL does not indicate whether the email was actually delivered as phishing, because URL filtering can be separate from the email's overall verdict.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.