Microsoft AI Agent Builder Associate (AB-620)

Practice AB-620 questions for Test and manage agents (20–25%). These original questions are grounded in verified Microsoft Learn content.

Q01 - Question

Fabrikam's order management agent in Copilot Studio must work with a shipment tracking agent that Northwind Traders built on its own AI platform. The Northwind agent reasons about shipment context, uses its own logistics tools, and returns contextual responses. A team member suggests calling a tracking API instead. Why is an Agent2Agent (A2A) integration the better fit?

Domain: Test and manage agents (20–25%) Type: Single choice

C is correct.

Explanation: The Northwind agent manages its own reasoning, tools, and orchestration. A standard API call isn't sufficient for that kind of agent. A2A is an open standard that lets one agent delegate tasks to another agent across platform and organizational boundaries.

A is incorrect: With A2A, the orchestrator doesn't select the partner's individual tools. The external agent's reasoning and tools stay under its own control.

B is incorrect: Returning raw data describes an API call. The Northwind agent returns contextual, agent-generated responses.

D is incorrect: A2A is designed for agents that run on different platforms. The partner doesn't need to rebuild its agent in Copilot Studio.

Learn more in Microsoft Learn

Q02 - Question

A company builds a Copilot Studio orchestrator for inventory questions. The architects require the orchestrator to choose which individual inventory tools to call for each request and to combine the results itself. The tools must not be hidden behind another agent's reasoning. Which integration approach should you use?

Domain: Test and manage agents (20–25%) Type: Single choice

A is correct.

Explanation: MCP provides controlled access to tools and data. The orchestrator selects individual tools and synthesizes the results, which matches the requirement.

B is incorrect: A2A delegates a task to an external agent whose reasoning, tools, and orchestration are opaque. The orchestrator can't choose the individual tools.

C is incorrect: An HTTP connector calls an API and returns raw data. It doesn't provide orchestrator-controlled selection across multiple tools.

D is incorrect: Placing the tools behind an external A2A agent hides them behind that agent's reasoning, which conflicts with the requirement.

Learn more in Microsoft Learn

Q03 - Question

You add an Agent2Agent connection to a Copilot Studio orchestrator. After you enter the partner's endpoint URL, Copilot Studio doesn't populate the agent name and description. Which two actions should you take? Each correct answer presents part of the solution.

Domain: Test and manage agents (20–25%) Type: Multiple choice

B and D are correct.

Explanation: Copilot Studio retrieves {endpoint}/.well-known/agent.json and populates the name and description only when the agent card is valid. If discovery fails, verify the endpoint and the card JSON. You can enter the name and description manually while the external owner fixes the card.

A is incorrect: Authentication doesn't fix a missing or malformed agent card. Use None only for unprotected development scenarios.

C is incorrect: An HTTP connector returns raw API data instead of an agent-generated response. It doesn't resolve an agent-card discovery failure.

Learn more in Microsoft Learn

Q04 - Question

A partner organization protects its A2A-enabled agent. The partner gives you a client ID, a client secret, an authorization URL, a token URL, and a refresh URL. You configure the Agent2Agent connection in Copilot Studio. Which authentication option should you select?

Domain: Test and manage agents (20–25%) Type: Single choice

B is correct.

Explanation: OAuth 2.0 authentication requires a client ID, client secret, authorization URL, token URL, and refresh URL. These are the values that the partner provided.

A is incorrect: Use None only for unprotected development scenarios. The partner agent is protected.

C is incorrect: API-key authentication requires a header or query-parameter name and a key value. It doesn't use the OAuth 2.0 URLs and client credentials.

D is incorrect: Treat client secrets as sensitive credentials. The routing description is used to route requests, not to store secrets.

Learn more in Microsoft Learn

Q05 - Question

You connect a Copilot Studio orchestrator to an external shipment tracking agent by using A2A. The orchestrator also has internal agents. Before production, you need to validate that requests route to the correct agent. What should you do?

Domain: Test and manage agents (20–25%) Type: Single choice

D is correct.

Explanation: Test delegation in the Copilot Studio test canvas and activity log with varied prompts. Include in-scope, out-of-scope, edge-case, and multi-turn prompts. Refine the descriptions to resolve routing ambiguity.

A is incorrect: Testing only in-scope prompts doesn't verify that unrelated requests stay away from the external agent.

B is incorrect: A valid agent card confirms discovery only. It doesn't validate routing accuracy or response quality.

C is incorrect: Routing descriptions must be specific and distinct from other agents. A broader description can overlap with internal agents and cause misrouting.

Learn more in Microsoft Learn

Q06 - Question

A bank has several Copilot Studio agents, including an account-opening agent. Each agent needs tools from the same group of backend systems. A central platform team wants to publish these tools once, maintain them in one place, and make updates available to connected agents without republishing each agent. What should you recommend?

Domain: Test and manage agents (20–25%) Type: Single choice

B is correct.

Explanation: An MCP server publishes tools once for all connected agents. Updates made on the server become available to those agents without republishing them. This approach avoids separate integrations with each backend system.

A is incorrect: You define REST API tools separately in each agent. This approach repeats the integration work for each backend system and each agent.

C is incorrect: You define connector tools separately in each agent. This approach does not give you one centrally published set of tools.

D is incorrect: Topics in each agent that call each backend system create repeated integrations. This approach does not use a centrally managed tool source.

Learn more in Microsoft Learn

Q07 - Question

A maker is building a Copilot Studio agent for a single department. At a specific step in a topic, the agent must call a backend operation. What should the maker use for this integration?

Domain: Test and manage agents (20–25%) Type: Single choice

D is correct.

Explanation: A topic-triggered call is a use case for a connector or a REST API tool. You define these tools in the agent. They give you more control than MCP tools and work for one-off integrations.

A is incorrect: Topics cannot call MCP tools directly. Only generative orchestration can invoke MCP tools.

B is incorrect: MCP tools require generative orchestration. If you turn off generative orchestration, the agent cannot invoke MCP tools.

C is incorrect: You cannot edit MCP tool descriptions in Copilot Studio. Also, a description change does not let a topic call an MCP tool.

Learn more in Microsoft Learn

Q08 - Question

A partner hosts a custom MCP server that uses Server-Sent Events (SSE) as its transport. You need to connect a Copilot Studio agent to this server. What should you do first?

Domain: Test and manage agents (20–25%) Type: Single choice

A is correct.

Explanation: Copilot Studio supports only the Streamable HTTP transport. The server URL must be the HTTPS Streamable HTTP endpoint that the server owner provides. An SSE server must migrate before you can connect to it.

B is incorrect: SSE has not been supported since August 2025. You cannot use SSE to connect the server.

C is incorrect: The MCP catalog provides prebuilt Microsoft connectors. A custom partner server requires onboarding configuration.

D is incorrect: The authentication type does not change the transport. The server must still use Streamable HTTP.

Learn more in Microsoft Learn

Q09 - Question

You connect an agent to an MCP server that returns sensitive production data. The server supports OAuth 2.0, but its identity provider doesn't support Dynamic Client Registration (DCR). Which OAuth 2.0 option should you configure?

Domain: Test and manage agents (20–25%) Type: Single choice

C is correct.

Explanation: Use Manual when the identity provider doesn't support DCR. Provide the client credentials and configure the endpoints. If the identity provider requires it, register the generated callback URL.

A is incorrect: Dynamic discovery requires DCR with discovery endpoints. The identity provider doesn't support DCR.

B is incorrect: Dynamic requires DCR. With this option, you provide the authorization and token URLs because discovery isn't available.

D is incorrect: None is suitable for trusted, network-controlled servers. Use API key or OAuth 2.0 for sensitive production data.

Learn more in Microsoft Learn

Q10 - Question

An account-opening agent is connected to a shared MCP server that exposes many tools. Allow all is on. During testing, the orchestrator sometimes selects tools that the account-opening workflow doesn't need. Some server-published tool descriptions are vague. Which two actions should you take? Each correct answer presents part of the solution.

Domain: Test and manage agents (20–25%) Type: Multiple choice

B and D are correct.

Explanation: When you turn off Allow all and enable only the tools that the workflow needs, you reduce orchestration ambiguity and apply least privilege. The orchestrator uses server-published tool descriptions to select tools. Only the server owner can update those descriptions.

A is incorrect: MCP tool descriptions are read-only in Copilot Studio. The server owner must update inadequate descriptions.

C is incorrect: Topics cannot call MCP tools directly. Only generative orchestration can invoke MCP tools.

Learn more in Microsoft Learn

Take the AB-620 practice test · Read the AB-620 study guide