A security engineer is using Microsoft Security Copilot to investigate a ransomware incident that impacted several endpoints and may have exfiltrated data through an AI-connected pipeline. The engineer wants to use Security Copilot to generate a full incident summary, extract IOCs, and check threat intelligence in one workflow. Which Security Copilot feature should the engineer use to run this predefined multi-step investigation?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Promptbooks in Microsoft Security Copilot are pre-built sequences of prompts that automate multi-step security investigation workflows. A ransomware investigation promptbook would chain together prompts to summarize the incident, extract IOCs, query threat intelligence, and suggest remediation steps—all in a single workflow execution.
Full explanation below image
Full Explanation
B is correct because Promptbooks in Microsoft Security Copilot are pre-built sequences of prompts that automate multi-step security investigation workflows. A ransomware investigation promptbook would chain together prompts to summarize the incident, extract IOCs, query threat intelligence, and suggest remediation steps—all in a single workflow execution. A is wrong because a plugin connects Copilot to a data source or tool (e.g., Sentinel, Defender TI) but is a data integration mechanism, not a multi-step investigation workflow. C is wrong because custom skills extend Copilot's reasoning capabilities for specific tasks; they do not orchestrate multi-step investigation sequences. D is wrong because the Defender XDR embedded Copilot experience provides AI assistance within the Defender portal for single-incident analysis, not a reusable multi-step promptbook workflow.