mediumMultiple Choice
SC-200 Practice Question: A SOC team ingests Microsoft 365 Defender…
A SOC team ingests Microsoft 365 Defender advanced hunting data into Microsoft Sentinel. They want to create a scheduled analytics rule that detects when a user receives more than 5 emails from an external sender containing a specific attachment name within 1 hour. Which KQL tables and approach should the analyst use?
⚠ Common exam trap
Watch out — candidates often assume EmailEvents contains all email data including attachments, but attachment details are stored in a separate table (EmailAttachmentInfo) and require a join to access the file name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents and EmailAttachmentInfo; summarize count() by AccountUpn, AttachmentFileName, bin(Timestamp,1h)
The detection requires joining EmailEvents (which contains sender/recipient metadata) with EmailAttachmentInfo (which contains attachment file names) to filter by external senders and a specific attachment name, then using summarize count() with bin(Timestamp,1h) to group events into 1-hour windows and identify users receiving more than 5 such emails. This approach directly maps to the requirement: external sender, attachment name, user identity (AccountUpn), and time-based aggregation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailEvents and EmailAttachmentInfo; summarize count() by AccountUpn, AttachmentFileName, bin(Timestamp,1h)
Why this is correct
EmailEvents carries the core mail flow metadata—sender, recipient, subject, and delivery timestamp—but no attachment details; EmailAttachmentInfo provides AttachmentFileName and references the parent email through NetworkMessageId. Joining these tables on NetworkMessageId lets you count how many times a given attachment name reached a specific AccountUpn, and binning Timestamp every 1h reveals temporal bursts. This is the correct combination because only this pair supplies both the recipient identity and the file name in the same logical context.
- ✗
EmailEvents and EmailUrlInfo; summarize count() by SenderObjectId
Why it's wrong here
This pairing is wrong because EmailUrlInfo tracks URLs extracted from or clicked in email bodies, not attachment files, so it can never yield a meaningful AttachmentFileName. Additionally, the query groups by SenderObjectId, which shifts the analysis to the sender rather than the recipient who is at risk; a single sender sending many messages makes the count misleading. The result would be a count of URL-embedding emails per sender, which does not answer which recipients received which attachments.
- ✗
EmailEvents only; filter by AttachmentFileName
Why it's wrong here
Querying EmailEvents alone and filtering by AttachmentFileName is invalid because that column does not exist in EmailEvents; the attachment entities are stored separately in EmailAttachmentInfo to support one email having many attachments. In Kusto, referencing a non-existent column raises a query failure rather than returning empty results. Even conceptually, EmailEvents only holds a 'has attachment' flag (like AttachmentCount) if any, so you cannot inspect individual file names without the join.
- ✗
EmailPostDeliveryEvents; summarize count() by RecipientEmailAddress
Why it's wrong here
EmailPostDeliveryEvents describes operations that occur after an email is delivered, such as user-reported phishing, malware verdict updates, or automatic remediation actions, and it does not contain the original attachment file name from the delivery event. Restricting to this table ignores the source EmailEvents metadata entirely and groups solely by RecipientEmailAddress, which cannot identify attachment names or time-honored frequency patterns. This table is useful for post-breach hunting, not for characterizing the inbound attachment traffic on the fresh mail path.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.