nerdexam
Microsoft

SC-200 · Question #369

You have a Microsoft 365 E5 subscription that uses Microsoft Copilot for Security. You have a Copilot for Security workspace that uses the following plugins: - Microsoft Entra - Microsoft Defender…

The correct answer is B. Open the investigation in the Copilot for Security standalone experience. To run a promptbook that includes Microsoft Entra ID Protection information within Copilot for Security when investigating from the Defender portal, first open the investigation in the Copilot for Security standalone experience.

Submitted by yuki_2020· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription that uses Microsoft Copilot for Security. You have a Copilot for Security workspace that uses the following plugins:

  • Microsoft Entra
  • Microsoft Defender XDR

From the Microsoft Defender portal, you use Copilot for Security to investigate a reported incident. You need to run a promptbook that will include information from Microsoft Entra ID Protection in the investigation. What should you do first?

Options

  • AFrom the Microsoft Defender portal, create an incident report.
  • BOpen the investigation in the Copilot for Security standalone experience.
  • COpen the investigation in Microsoft Sentinel.
  • DFrom the Microsoft Defender portal, create an advanced hunting query.

How the community answered

(61 responses)
  • A
    13% (8)
  • B
    77% (47)
  • C
    3% (2)
  • D
    7% (4)

Why each option

To run a promptbook that includes Microsoft Entra ID Protection information within Copilot for Security when investigating from the Defender portal, first open the investigation in the Copilot for Security standalone experience.

AFrom the Microsoft Defender portal, create an incident report.

Creating an incident report is typically a post-investigation or documentation step, not a prerequisite for running a promptbook in Copilot for Security.

BOpen the investigation in the Copilot for Security standalone experience.Correct

While Copilot for Security is integrated into the Microsoft Defender portal, the full capabilities for managing and running promptbooks that leverage various plugins, including Microsoft Entra ID Protection, are primarily accessed and orchestrated from the dedicated Copilot for Security standalone experience.

COpen the investigation in Microsoft Sentinel.

Opening the investigation in Microsoft Sentinel is an alternative investigation platform and would bypass the direct use of Copilot for Security's promptbooks and plugins for this specific scenario.

DFrom the Microsoft Defender portal, create an advanced hunting query.

Creating an advanced hunting query is a specific investigative action and not the necessary first step to enable the use of promptbooks within Copilot for Security to leverage plugin data.

Concept tested: Microsoft Copilot for Security promptbooks and standalone experience

Source: learn.microsoft.com/security/copilot/promptbooks-microsoft-copilot-security

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice