Design security operations, identity, and compliance capabilities →hardMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Sentinel as a SIEM. The security team wants to use Microsoft Copilot for Security to assist in incident investigation. You need to ensure that Copilot can access Sentinel data while meeting compliance requirements. Which integration should you configure?
⚠ Common exam trap
It's easy for candidates to confuse enabling Threat Intelligence connectors (Option C) with granting data access, but those connectors only import external threat data and do not provide Copilot with read access to Sentinel's internal logs or incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Copilot for Security plugin for Sentinel
The Microsoft Copilot for Security plugin for Sentinel is the correct integration because it enables Copilot to directly query and analyze Sentinel data through a native, compliant connection. This plugin uses Sentinel's API and role-based access control (RBAC) to ensure that Copilot only accesses data the user is authorized to see, meeting compliance requirements without additional data movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a playbook to query Sentinel data
Why it's wrong here
Playbooks in Microsoft Sentinel are built on Azure Logic Apps and are designed to automate response actions such as isolating a compromised host or notifying an admin. While you could write a playbook that uses an API or Azure Monitor logs query to pull data from Sentinel, that is a custom automation path, not the built-in Copilot integration. The correct feature is the Microsoft Copilot for Security plugin, which provides native natural-language access to Sentinel data without requiring you to construct, maintain, or manage Logic Apps workflows.
- ✓
Enable Microsoft Copilot for Security plugin for Sentinel
Why this is correct
Enabling the Microsoft Copilot for Security plugin for Sentinel is the direct, secure integration that lets Copilot query and interact with Sentinel data using natural language. When enabled, a security analyst can ask Copilot questions like 'summarize the most recent high-severity alerts' or 'show all open incidents involving user X,' and Copilot translates that into KQL queries against Sentinel's underlying Log Analytics workspace. This plugin explicitly bridges Copilot to Sentinel, providing incident summaries, guided investigations, and context-aware responses, which is exactly what the organization needs to leverage Copilot as a SIEM interface.
- ✗
Enable Sentinel's Threat Intelligence connectors
Why it's wrong here
Sentinel's Threat Intelligence connectors are used to import external threat intelligence data — such as indicators of compromise (IOCs) from Microsoft Graph Security, TAXII feeds, or third-party TI platforms — into the Sentinel workspace for correlation and detection. These connectors enrich your detection capabilities but do not install or activate any Copilot functionality. They do not create a conversational interface or provide AI-assisted querying; they simply ingest raw data for analytic rules, so this option addresses data inflow rather than the requested Copilot integration.
- ✗
Use Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform that monitors Azure, on-premises, and other cloud resources for vulnerabilities and threats. Although Copilot for Security can integrate with Defender for Cloud, this tool is a separate service from Microsoft Sentinel and does not give Copilot access to Sentinel incident data. The question asks about enabling Copilot for Sentinel specifically, and Defender for Cloud would not establish that connection; you need a Sentinel plugin or equivalent, not a different security product.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.