SC-200 Practice Question 3846

Exam: SC-200
Domain: Perform threat hunting
Difficulty: medium
You are hunting across email telemetry in Defender for Office 365. You need to identify messages where a phishing attachment was delivered to a user inbox without being stripped by anti-malware policies. Which table should you query?

Answer Options

A
The EmailAttachmentInfo and EmailEvents tables
B
The DeviceRegistryEvents table
C
The DeviceLogonEvents table
D
The CommonSecurityLog table

Correct Answer

A: The EmailAttachmentInfo and EmailEvents tables

Explanation

The EmailAttachmentInfo and EmailEvents tables correlate message delivery status, recipient addresses, attachment file names, SHA256 hashes, and verdict actions.