A security engineer is configuring Microsoft Copilot for Security to integrate with an on-premises SIEM. The engineer wants Copilot for Security to query on-premises security event data. Which mechanism allows Copilot for Security to access data from a non-Microsoft SIEM?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because Microsoft Copilot for Security supports a plugin framework that allows third-party vendors and custom developers to create plugins integrating external data sources including non-Microsoft SIEMs. These plugins enable Copilot to query and reason over data from connected systems.
Full explanation below image
Full Explanation
C is correct because Microsoft Copilot for Security supports a plugin framework that allows third-party vendors and custom developers to create plugins integrating external data sources including non-Microsoft SIEMs. These plugins enable Copilot to query and reason over data from connected systems. A is incorrect because Microsoft Sentinel data connectors bring data into Sentinel's workspace, and Copilot then accesses Sentinel; the SIEM data would need to be in Sentinel first, not queried directly. B is incorrect because Copilot for Security does not have an agent that installs on external systems. D is incorrect because Logic Apps forwarding alerts to a webhook does not create a queryable interface for Copilot for Security; plugins are the correct integration mechanism.