Domain 1: Microsoft Defender for AI & Copilot Security
Microsoft SC-500 Security Copilot · 47 questions
- A security engineer is configuring Azure AI Content Safety for a company's customer-facing chatbot built on Azure OpenAI Service. The engineer needs to detect and block prompt injection attacks where end users attempt to override the system prompt. Which feature should be enabled in Azure AI Content Safety?
- An organization has deployed Microsoft Copilot for Microsoft 365. The security team wants to ensure that Copilot cannot surface files labeled 'Confidential - Finance' to users who do not have the appropriate sensitivity label permissions. Which configuration achieves this outcome?
- A security operations team is using Microsoft Security Copilot to investigate a suspected phishing campaign. The analyst wants Security Copilot to automatically retrieve related indicators from Microsoft Defender Threat Intelligence. Which Security Copilot capability enables this integration?
- Microsoft Defender for Cloud has detected potential threats against an Azure OpenAI Service deployment. The security team wants to enable AI-specific threat protection plans in Defender for Cloud. Which Defender plan must be enabled to receive AI workload security alerts?
- A company's security team needs to review all interactions users have with Microsoft Copilot for Microsoft 365, including the prompts submitted and responses generated, to investigate a potential policy violation. Which Microsoft service provides access to this audit data?
- An organization is deploying an AI workload on Azure and wants to use Microsoft Defender for Cloud's AI security posture management capabilities. The security team needs to identify misconfigurations in their Azure OpenAI deployments. Which Defender for Cloud feature surfaces AI-specific security recommendations?
- A red team has demonstrated that an attacker can embed hidden instructions inside a document that a user uploads to a Copilot-powered assistant, causing the assistant to perform unauthorized actions. What type of attack is this, and what Azure AI Content Safety feature mitigates it?
- A security engineer is configuring Microsoft Security Copilot and needs to ensure that analyst-created promptbooks are only accessible to members of the Security Operations Center team. Which feature in Security Copilot supports this access control?
- A security engineer is using Microsoft Security Copilot to investigate a ransomware incident that impacted several endpoints and may have exfiltrated data through an AI-connected pipeline. The engineer wants to use Security Copilot to generate a full incident summary, extract IOCs, and check threat intelligence in one workflow. Which Security Copilot feature should the engineer use to run this predefined multi-step investigation?
- An organization has purchased Microsoft Security Copilot and wants to restrict which analysts can submit prompts, while allowing managers to view all session outputs. Which role assignments in Microsoft Security Copilot provide these access levels?
- Microsoft Defender for Cloud has generated an alert titled 'Jailbreak attempt detected on Azure OpenAI model deployment.' A security engineer needs to investigate this alert. Which data source contains the full prompt content that triggered the alert?
- An enterprise's IT administrator needs to prevent specific Microsoft 365 user groups from accessing Microsoft Copilot for Microsoft 365. Only users in the 'AI-Approved' Entra ID group should be able to use Copilot. What is the correct administrative approach?
- A security team using Microsoft Defender for Cloud receives an alert indicating 'Credential theft from Azure OpenAI resource via metadata service.' This alert suggests an attacker on a compute resource is attempting to steal the managed identity token to call Azure OpenAI. Which Defender for Cloud plan generates this AI workload security alert?
- A SOC team wants to integrate Microsoft Security Copilot with a third-party SOAR platform (Splunk SOAR) so that Copilot can be invoked from Splunk playbooks during incident response. Which integration mechanism supports this?
- An organization in the European Union is deploying Microsoft Security Copilot and must ensure that all prompt and response data is processed and stored within EU data boundaries. Which Security Copilot configuration satisfies this requirement?
- A developer built a Copilot Studio agent that connects to enterprise data via Microsoft Graph connectors. The security team wants to ensure that the agent cannot retrieve or output content from SharePoint sites where the calling user does not have read access. Which foundational design principle ensures this?
- A security engineer wants to use Microsoft Security Copilot to identify attack paths targeting Azure OpenAI resources in the organization's environment. The engineer uses the Security Exposure Management integration within Security Copilot. What does this integration provide?
- A Defender for Cloud recommendation states that an Azure OpenAI resource has 'Public network access enabled.' The recommendation severity is 'High.' The security engineer wants to understand what specific risk this creates before remediating. Which Defender for Cloud feature provides the contextual risk reasoning for this recommendation?
- An organization uses Microsoft Copilot for Microsoft 365 and wants to generate usage reports showing which users are actively using Copilot, which Microsoft 365 apps they use it in, and how many prompts were submitted per week. Where are these reports available?
- An organization has configured Azure AI Content Safety with a custom blocklist to prevent their Azure OpenAI-powered application from generating content containing competitor brand names. A user submits a prompt containing a competitor name. The content safety API should block the response before it reaches the user. Which Azure AI Content Safety configuration step creates this custom blocking behavior?
- A security team notices that Microsoft Defender for Cloud has raised an alert for 'Anomalous access to Azure OpenAI' for a service principal that normally calls the API with consistent token counts between 500-1,000 per hour but suddenly made 50,000 calls in one hour. The team needs to determine whether this is a legitimate batch job or an attack. Which initial investigation step uses Microsoft Security Copilot most effectively?
- An organization wants to detect when Microsoft Purview AI Hub shows that users are sharing sensitive files marked with the 'Confidential' sensitivity label as inputs to Microsoft Copilot for Microsoft 365 prompts with external recipients. Which Purview AI Hub capability surfaces this oversharing risk?
- An enterprise has deployed Microsoft 365 Copilot for its legal team but wants to prevent Copilot from accessing and synthesizing content from the 'Mergers & Acquisitions' SharePoint site, which contains deal information restricted to a small subset of users. The legal team members do not have access to this site. What ensures Copilot cannot access this site for legal team users?
- An organization's compliance officer wants to implement Microsoft Security Copilot to help analysts respond to compliance questions about AI usage policies. The officer wants to create a custom promptbook with 5 sequential prompts that walk analysts through an AI compliance review checklist. After creating the promptbook, it should be available to all security analysts. Which sharing option makes the promptbook available organization-wide?
- A security engineer is reviewing Microsoft Copilot for Microsoft 365 usage logs and notices that users are submitting prompts containing customer PII. The engineer needs to prevent sensitive data from being included in Copilot prompts without blocking Copilot entirely. Which feature should the engineer configure?
- An organization has deployed Microsoft Copilot Studio to build a custom enterprise chatbot. The security team discovers the bot can be manipulated via crafted user messages to reveal internal SharePoint document contents. Which Microsoft service provides runtime protection against this type of prompt injection attack targeting Copilot Studio bots?
- A security operations team wants to use Microsoft Copilot for Security to accelerate incident triage. A new analyst asks which built-in promptbook they should use to quickly summarize a Microsoft Sentinel incident and recommend next steps. What is the correct promptbook to use?
- An organization is evaluating the risk of Microsoft 365 Copilot oversharing sensitive files with employees who lack the appropriate permissions. The CISO wants to assess which files Copilot could surface to users before deployment. Which tool provides a pre-deployment oversharing assessment?
- A security engineer is configuring Microsoft Defender for Cloud to protect an Azure OpenAI resource. They want to receive alerts when the OpenAI endpoint is accessed from a Tor exit node or anonymous proxy. Which Microsoft Defender plan must be enabled?
- During a security review of Copilot for Microsoft 365, an engineer discovers that users are using Copilot to summarize emails from external parties that contain potential phishing content. The engineer needs to ensure Copilot does not process emails flagged as phishing. What should be configured?
- A company wants to monitor how employees use Microsoft 365 Copilot and generate reports showing prompt topics and response categories for compliance review. Which Microsoft service provides this Copilot interaction audit data?
- A security engineer is tasked with assessing whether Microsoft Copilot for Security has access to the right data sources for investigating cloud threats. The engineer needs to add a plugin to connect Copilot for Security to Microsoft Defender for Cloud. Where in the Copilot for Security portal are plugins managed?
- An organization needs to restrict Microsoft 365 Copilot from returning results based on files stored in a specific SharePoint site containing merger and acquisition data. The data cannot be labeled with sensitivity labels due to technical constraints. What is the most effective approach?
- A security engineer configures Microsoft Defender for Cloud Defender for AI plan. After enabling it, alerts appear for 'Jailbreak attempt detected on Azure OpenAI endpoint.' Which underlying technology enables this detection?
- A security engineer is configuring Microsoft Copilot for Security to integrate with an on-premises SIEM. The engineer wants Copilot for Security to query on-premises security event data. Which mechanism allows Copilot for Security to access data from a non-Microsoft SIEM?
- An organization enables Microsoft Copilot for Microsoft 365 and receives reports that Copilot is surfacing confidential HR documents to non-HR employees in Teams. After investigation, the security team determines the HR documents are stored in SharePoint without proper access controls. What is the ROOT CAUSE of the oversharing issue?
- A security engineer needs to monitor all interactions between employees and Microsoft 365 Copilot for signs of policy violations, including employees attempting to get Copilot to produce content that violates the acceptable use policy. Which Microsoft service should be configured?
- An organization's security team wants to understand which Microsoft Copilot for Security capabilities require Security Compute Units (SCUs) versus which are included in existing Microsoft licenses. A new analyst asks about the billing model. What is the correct understanding?
- A healthcare organization deploys Microsoft Copilot for Microsoft 365. The legal team requires that all Copilot interactions involving Protected Health Information (PHI) be flagged for legal review before the interaction data can be deleted. Which Microsoft 365 feature achieves this?
- A security engineer configures Microsoft Defender for AI to protect an Azure OpenAI deployment. The engineer wants to ensure that the protection covers both the prompt inputs and the model responses. Which configuration in Defender for AI achieves bidirectional monitoring?
- A security engineer is configuring Copilot for Security to assist with threat hunting for AI-targeted attacks. The engineer wants to use Copilot to run a custom KQL query against Microsoft Sentinel and then analyze the results. Which Copilot for Security capability enables this workflow?
- A security engineer is reviewing the Microsoft Defender for Cloud security posture for an Azure AI Foundry deployment. Defender for Cloud shows a recommendation to 'Enable Microsoft Defender for AI.' After enabling the plan, the engineer wants to verify that the protection is active. Where can the engineer confirm that Azure OpenAI resources are being protected?
- A company wants to use Microsoft Copilot for Security to analyze a suspicious PowerShell script discovered on a server that may have been used to exfiltrate Azure OpenAI API keys. Which Copilot for Security capability allows direct analysis of the script content?
- An organization has enabled Microsoft 365 Copilot and the security team wants to understand the data residency model. A compliance officer asks where Microsoft stores Copilot for Microsoft 365 interaction data (prompts and responses). What is the correct answer?
- A security engineer is deploying Microsoft Copilot Studio with custom connectors that access internal APIs. The security team requires that authentication between Copilot Studio bots and internal APIs must use OAuth 2.0 with Entra ID, not API keys. How should the custom connector be configured?
- A security engineer discovers that Microsoft Copilot for Security is generating responses that reference stale threat intelligence that is over 12 months old. The engineer needs to ensure Copilot for Security uses the most current threat intelligence. Which configuration should be verified?
- A company's security team wants to leverage Microsoft Copilot for Security to generate a comprehensive summary of all security incidents involving Azure OpenAI resources over the past 30 days, including common attack patterns and recommended mitigations. Which Copilot for Security feature is best suited for this retrospective analysis?