Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst wants to see the delivery…

A security analyst wants to see the delivery status and phishing verdict of an email. Which advanced hunting table should the analyst query in Microsoft 365 Defender?

⚠ Common exam trap

Many candidates confuse EmailEvents (initial delivery and verdict) with EmailPostDeliveryEvents (post-delivery actions), mistakenly thinking the latter includes the original verdict when it only records changes after delivery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EmailEvents

The EmailEvents table in Microsoft 365 Defender's advanced hunting schema contains the delivery status (e.g., Delivered, Failed, Filtered as spam) and the phishing verdict (e.g., Phish, Normal) for each email. This table records the initial processing and classification of the email, making it the correct source for both pieces of information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    EmailEvents

    Why this is correct

    EmailEvents is the primary advanced hunting schema for email security in Microsoft 365 Defender. Each row represents a distinct email message and includes fields such as DeliveryAction (e.g., Delivered, Junked, Blocked), ThreatTypes (e.g., Phish, Malware), and DetectionMethods. The Phish filter in Threat Explorer relies on this table because it contains the original verdict determined at the time of delivery, making it exactly what the analyst needs.

  • ✗

    EmailPostDeliveryEvents

    Why it's wrong here

    EmailPostDeliveryEvents is a separate advanced hunting table that records only what happened after an email was already delivered. It captures user-reported actions like 'ReportPhish' and automated remediation such as ZAP (Zero-Hour Auto Purge) deleting a message from a mailbox. Because these events occur after the initial delivery verdict, this table will never contain the original delivery status or phishing verdict - that information always resides in EmailEvents.

  • ✗

    EmailAttachmentInfo

    Why it's wrong here

    EmailAttachmentInfo is an advanced hunting table that exposes metadata about every file attached to an email, including the filename, file type, and SHA-256 hash. This data is valuable for correlating attachment-based threats, but it does not include the email's delivery status or the phishing verdict. An attacker could send a benign attachment with a phishing link, so attachment details alone cannot answer the analyst's question.

  • ✗

    EmailUrlInfo

    Why it's wrong here

    EmailUrlInfo is the advanced hunting table that lists every URL found in an email, along with domain and IP-related fields. It can be joined with EmailEvents to see whether a URL was detonated or related to a threat, but it does not contain the delivery disposition or phishing verdict for the email itself. The presence of a URL does not indicate whether the email was actually delivered as phishing, because URL filtering can be separate from the email's overall verdict.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.