SC-200 Perform threat hunting Practice Question
Which TWO Microsoft 365 Defender advanced hunting tables would you use together to investigate a potential data exfiltration via email?
⚠ Common exam trap
The trap is confusing email-layer tables (EmailEvents, EmailAttachmentInfo) with endpoint or cloud-app tables — candidates pick DeviceNetworkEvents or CloudAppEvents because they sound like they cover 'exfiltration' broadly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents
EmailEvents is correct because it is the advanced hunting table that records email message-level metadata and delivery/security verdicts (sender, recipient, subject, timestamps, delivery action, and threat types), which is essential to identify suspicious outbound messages tied to exfiltration. EmailAttachmentInfo is correct because it provides per-attachment details for those messages (file name, SHA-256 hash, file type, and size), letting you pivot from an EmailEvents record via NetworkMessageId to inspect what data was actually attached and sent. Together they correlate the message context with the payload, which is the core of an email-based exfiltration investigation. DeviceNetworkEvents, CloudAppEvents, and DeviceProcessEvents are not the right pairing here: they cover endpoint network connections, cloud app/service activity, and process execution respectively, none of which directly expose email message and attachment metadata for an email exfiltration scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailEvents
Why this is correct
The EmailEvents table in Microsoft 365 Defender Advanced Hunting is the primary source for email metadata, including the sender, recipient, subject, and message ID (NetworkMessageId). It also records delivery status (Delivered, Blocked, Failed) and detection verdicts for malware, phishing, and spam. This table is essential for hunting email-borne threats because it allows you to filter by specific senders or recipients, inspect message disposition, and correlate with other email and identity tables.
- ✓
EmailAttachmentInfo
Why this is correct
The EmailAttachmentInfo table stores details about files associated with email messages, such as the attachment file name, size, SHA256 hash, and attachment type (e.g., inline or embedded). It is specifically designed for analyzing payloads delivered via email, making it a correct choice when hunting for malicious attachments. This table joins with EmailEvents using NetworkMessageId to attach a file to the email delivery context, enabling queries that map a malicious hash to the sender, recipient, and delivery outcome.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents is incorrect for email hunting because it records network connection activity on endpoint devices—such as source/destination IPs, ports, and protocols—not email message properties like sender, recipient, subject, or attachment metadata. While a compromised device could establish a network connection to exfiltrate data, this table lacks the email-specific context needed to identify the initial malicious email or inspect its attachments. Email threat hunting should focus on the EmailEvents and EmailAttachmentInfo tables, which reside in the same schema.
- ✗
CloudAppEvents
Why it's wrong here
CloudAppEvents is incorrect because it captures activity events for cloud apps across Microsoft 365, including Exchange Online, SharePoint, and OneDrive, but it focuses on actions like mailbox access, item modifications, or admin operations—not the content or headers of individual email messages. It may log Exchange-related events such as 'MailItemsAccessed' or 'Send,' but it does not include the sender/recipient, subject, or attachment details necessary to investigate email exfiltration fully. For email-specific hunting, you need the dedicated email tables in Advanced Hunting, not the general cloud app audit log.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents is incorrect because it logs process creation and execution events on endpoints—such as process name, command line, parent process, and file paths—giving visibility into behavior on the device after a user clicks an attachment or link. It cannot reveal email properties because it does not ingest email messages, attachments, or their metadata at all. Using this table in an email-threat hunting query would miss the actual email artifacts, and its process data would only be useful for post-exploitation analysis after an email has already caused an execution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.