SC-200 Perform threat hunting Practice Question
During a threat hunt, you suspect a user may have exfiltrated data via email. Which Microsoft 365 Defender advanced hunting table should you query to review email attachments and their file hashes?
⚠ Common exam trap
SC-200 often tests the distinction between email-related tables in advanced hunting, and candidates frequently confuse EmailAttachmentInfo with EmailEvents or EmailUrlInfo, forgetting that only EmailAttachmentInfo contains file hashes for attachments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailAttachmentInfo
EmailAttachmentInfo is the correct table because it specifically contains metadata about email attachments, including the SHA256 hash of each attached file, file name, file type, and size. This table is designed for scenarios where you need to investigate suspicious attachments, such as during a data exfiltration hunt. The other tables focus on URLs, general email events, or post-delivery actions, not attachment details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EmailUrlInfo
Why it's wrong here
EmailUrlInfo is incorrect for this investigation because it only tracks URLs embedded in email bodies, not file-level details. While a malicious link could be an exfiltration vector, the table lacks any reference to attachment file names, hashes, or MIME types. To pivot on an attachment's SHA256 hash, you need a table that stores file metadata, which EmailUrlInfo does not contain.
- ✓
EmailAttachmentInfo
Why this is correct
EmailAttachmentInfo is the correct table because it is specifically designed to store metadata about files attached to emails, including the file name, file size, and crucially the SHA256 hash. In a threat hunt for data exfiltration, this hash lets you pivot to threat intelligence sources or correlate with command-and-control activities. This table is the only one among the options that directly provides a hash value to verify if a file was malicious or sensitive.
- ✗
EmailEvents
Why it's wrong here
EmailEvents is insufficient because it captures email header and delivery metadata such as sender, recipient, subject, and timestamp, but it does not include any information about the content of attachments. Without a file hash or even a file name, you cannot confirm whether an actual file was exfiltrated or match it against known malicious hashes. It may help you identify a suspicious message, but it lacks the attachment-level evidence needed to close the exfiltration hypothesis.
- ✗
EmailPostDeliveryEvents
Why it's wrong here
EmailPostDeliveryEvents tracks actions taken after a message has been delivered, such as zero-hour auto purge (ZAP), phishing simulation results, or manual remediation like 'soft delete' or 'move to inbox'. It does not contain any original attachment metadata or hashes, so it cannot be used to identify whether a file was exfiltrated in the initial message. This table is useful for investigating post-delivery user interactions, but not for analyzing the attachment itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.