SC-200 Practice Question 3846
Exam: SC-200
Domain: Perform threat hunting
Difficulty: medium
You are hunting across email telemetry in Defender for Office 365. You need to identify messages where a phishing attachment was delivered to a user inbox without being stripped by anti-malware policies. Which table should you query?
Answer Options
A
The EmailAttachmentInfo and EmailEvents tables
B
The DeviceRegistryEvents table
C
The DeviceLogonEvents table
D
The CommonSecurityLog table
Correct Answer
A: The EmailAttachmentInfo and EmailEvents tables
Explanation
The EmailAttachmentInfo and EmailEvents tables correlate message delivery status, recipient addresses, attachment file names, SHA256 hashes, and verdict actions.