A security operations team wants to use Microsoft Copilot for Security to accelerate incident triage. A new analyst asks which built-in promptbook they should use to quickly summarize a Microsoft Sentinel incident and recommend next steps. What is the correct promptbook to use?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the Incident Investigation promptbook in Microsoft Copilot for Security is specifically designed to summarize security incidents from connected sources like Sentinel, identify key entities, and provide recommended investigative steps. A is incorrect because the Threat Actor Profile promptbook focuses on intelligence about known threat groups, not specific incidents.
Full explanation below image
Full Explanation
B is correct because the Incident Investigation promptbook in Microsoft Copilot for Security is specifically designed to summarize security incidents from connected sources like Sentinel, identify key entities, and provide recommended investigative steps. A is incorrect because the Threat Actor Profile promptbook focuses on intelligence about known threat groups, not specific incidents. C is incorrect because Vulnerability Impact Assessment targets CVE analysis and exposure, not incident triage. D is incorrect because Device Investigation focuses on a specific device's security posture, not a broader incident.