SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Copilot for Security. You want to use natural language to generate a KQL query for threat hunting. What should you do?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Copilot for Security with Microsoft 365 Copilot, assuming any 'Copilot' subscription will generate KQL queries, when in fact only the security-specific Copilot integrated into the Defender portal provides this capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Copilot prompt bar in the Microsoft Defender portal.
Microsoft Copilot for Security is integrated directly into the Microsoft Defender portal, allowing security analysts to use natural language prompts to generate KQL queries for threat hunting. The Copilot prompt bar interprets the natural language input and converts it into the appropriate KQL syntax, eliminating the need for manual query writing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually write the KQL query in the advanced hunting page.
Why it's wrong here
Manually writing KQL queries in the Advanced Hunting page is a fundamental skill for security analysts, but it bypasses the core value proposition of Microsoft Copilot for Security. When Copilot is available, its purpose is to automate and accelerate the query generation process by translating natural language into precise KQL. Therefore, choosing to manually write queries when Copilot is deployed for this specific task would be an inefficient use of the AI assistant's capabilities, especially for complex investigations or less experienced users.
- ✓
Use the Copilot prompt bar in the Microsoft Defender portal.
Why this is correct
Utilizing the Copilot prompt bar within the Microsoft Defender portal is the correct and intended method for leveraging Microsoft Copilot for Security to generate KQL queries. This integrated interface allows security analysts to input natural language descriptions of their threat hunting or investigation needs. Copilot then processes these prompts, translating them into accurate KQL queries that can be immediately executed in Advanced Hunting, significantly streamlining security operations and enhancing analyst productivity.
- ✗
Install the Copilot add-in for Sentinel.
Why it's wrong here
Microsoft Copilot for Security is not an 'add-in' that requires separate installation specifically for Sentinel or any other integrated security service. Instead, it is a unified AI assistant that integrates natively across various Microsoft security products, including Microsoft Defender XDR and Microsoft Sentinel, once provisioned. Its capabilities are accessible directly within the respective portals where it provides contextual assistance, making the concept of installing a separate 'add-in' for Sentinel inaccurate and unnecessary.
- ✗
Subscribe to Microsoft 365 Copilot.
Why it's wrong here
Subscribing to Microsoft 365 Copilot would not enable the generation of KQL queries for security operations because it is a fundamentally different product offering. Microsoft 365 Copilot is designed to enhance productivity across Microsoft 365 applications like Word, Excel, and Outlook, focusing on content creation and data analysis in a business context. Microsoft Copilot for Security, conversely, is a specialized AI solution built specifically for security professionals, focusing on tasks like threat hunting, incident response, and vulnerability management within security platforms.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.