PL-900 Practice Question: Demonstrate the capabilities of Microsoft Copilot Studio
A retail company's Copilot Studio copilot must look up a customer's loyalty points from a proprietary REST API and return the balance in chat. The API requires an API key. Which approach should the maker use to integrate this external system with the copilot?
⚠ Common exam trap
The trap here is treating knowledge sources or message nodes as API integration points, when custom API calls belong in Power Automate flows invoked as topic actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Power Automate cloud flow that calls the REST API and invoke the flow from a copilot topic action node.
To call a proprietary REST API that requires an API key, the maker should build a Power Automate cloud flow that performs the call and returns the result, then invoke it from a copilot topic action node. This pattern keeps credentials in the flow's secure connections, supports parameterized lookups, and returns structured values into the conversation, which knowledge sources and message nodes cannot do.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Paste the API key into a message node in the topic so the copilot can call the API directly.
Why it's wrong here
Message nodes only display text to users; they cannot execute API calls. Placing an API key in a message would also expose the secret in the conversation, creating a serious security risk. This approach neither performs the lookup nor protects credentials, so it fails the scenario's requirement to retrieve and return loyalty points securely.
- ✗
Add the API endpoint URL as a public website knowledge source.
Why it's wrong here
Knowledge sources are for retrieving informational content to answer questions generatively. They do not authenticate with API keys or return structured values like a specific customer's point balance. Treating the API as a website source would yield unreliable or no results, because generative retrieval is not designed for authenticated, parameterized data lookups.
- ✗
Configure the copilot's authentication to Microsoft Entra ID and rely on single sign-on to the API.
Why it's wrong here
Microsoft Entra ID authentication identifies users to the copilot but does not automatically authorize calls to a third-party API that uses its own key. The proprietary API expects an API key, not an Entra token. Without a flow or connector to supply the key, the copilot cannot retrieve the loyalty balance, so this option does not meet the requirement.
- ✓
Create a Power Automate cloud flow that calls the REST API and invoke the flow from a copilot topic action node.
Why this is correct
A Power Automate cloud flow can call the REST API, manage the API key securely, and return the loyalty balance. The copilot topic then uses a Call an action node to invoke the flow and display the result. This is the supported no-code integration pattern for custom APIs in Copilot Studio topics, satisfying the lookup and response requirement.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.