Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunt, you suspect a user may have exfiltrated data via email. Which Microsoft 365 Defender advanced hunting table should you query to review email attachments and their file hashes?

⚠ Common exam trap

SC-200 often tests the distinction between email-related tables in advanced hunting, and candidates frequently confuse EmailAttachmentInfo with EmailEvents or EmailUrlInfo, forgetting that only EmailAttachmentInfo contains file hashes for attachments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EmailAttachmentInfo

EmailAttachmentInfo is the correct table because it specifically contains metadata about email attachments, including the SHA256 hash of each attached file, file name, file type, and size. This table is designed for scenarios where you need to investigate suspicious attachments, such as during a data exfiltration hunt. The other tables focus on URLs, general email events, or post-delivery actions, not attachment details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EmailUrlInfo

    Why it's wrong here

    EmailUrlInfo is incorrect for this investigation because it only tracks URLs embedded in email bodies, not file-level details. While a malicious link could be an exfiltration vector, the table lacks any reference to attachment file names, hashes, or MIME types. To pivot on an attachment's SHA256 hash, you need a table that stores file metadata, which EmailUrlInfo does not contain.

  • ✓

    EmailAttachmentInfo

    Why this is correct

    EmailAttachmentInfo is the correct table because it is specifically designed to store metadata about files attached to emails, including the file name, file size, and crucially the SHA256 hash. In a threat hunt for data exfiltration, this hash lets you pivot to threat intelligence sources or correlate with command-and-control activities. This table is the only one among the options that directly provides a hash value to verify if a file was malicious or sensitive.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents is insufficient because it captures email header and delivery metadata such as sender, recipient, subject, and timestamp, but it does not include any information about the content of attachments. Without a file hash or even a file name, you cannot confirm whether an actual file was exfiltrated or match it against known malicious hashes. It may help you identify a suspicious message, but it lacks the attachment-level evidence needed to close the exfiltration hypothesis.

  • ✗

    EmailPostDeliveryEvents

    Why it's wrong here

    EmailPostDeliveryEvents tracks actions taken after a message has been delivered, such as zero-hour auto purge (ZAP), phishing simulation results, or manual remediation like 'soft delete' or 'move to inbox'. It does not contain any original attachment metadata or hashes, so it cannot be used to identify whether a file was exfiltrated in the initial message. This table is useful for investigating post-delivery user interactions, but not for analyzing the attachment itself.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.