Q01 - Question
Fabrikam's order management agent in Copilot Studio must work with a shipment tracking agent that Northwind Traders built on its own AI platform. The Northwind agent reasons about shipment context, uses its own logistics tools, and returns contextual responses. A team member suggests calling a tracking API instead. Why is an Agent2Agent (A2A) integration the better fit?
Domain: Test and manage agents (20–25%) Type: Single choice
- A. A2A lets the Fabrikam orchestrator select and invoke each Northwind logistics tool directly.
- B. A2A returns raw shipment data that the Fabrikam agent can format without partner involvement.
- C. A2A delegates tasks to an external agent that keeps its own reasoning, tools, and orchestration across platform and organizational boundaries.
- D. A2A requires Northwind Traders to rebuild its agent in Copilot Studio so that both agents share one platform.
C is correct.
Explanation: The Northwind agent manages its own reasoning, tools, and orchestration. A standard API call isn't sufficient for that kind of agent. A2A is an open standard that lets one agent delegate tasks to another agent across platform and organizational boundaries.
A is incorrect: With A2A, the orchestrator doesn't select the partner's individual tools. The external agent's reasoning and tools stay under its own control.
B is incorrect: Returning raw data describes an API call. The Northwind agent returns contextual, agent-generated responses.
D is incorrect: A2A is designed for agents that run on different platforms. The partner doesn't need to rebuild its agent in Copilot Studio.
Q02 - Question
A company builds a Copilot Studio orchestrator for inventory questions. The architects require the orchestrator to choose which individual inventory tools to call for each request and to combine the results itself. The tools must not be hidden behind another agent's reasoning. Which integration approach should you use?
Domain: Test and manage agents (20–25%) Type: Single choice
- A. Use MCP so that the orchestrator controls tool selection and synthesizes the results.
- B. Use an A2A connection to delegate each inventory request to an external agent.
- C. Use an HTTP connector that calls a single API and returns raw data.
- D. Package the tools as a separate agent on another platform and connect it by using A2A.
A is correct.
Explanation: MCP provides controlled access to tools and data. The orchestrator selects individual tools and synthesizes the results, which matches the requirement.
B is incorrect: A2A delegates a task to an external agent whose reasoning, tools, and orchestration are opaque. The orchestrator can't choose the individual tools.
C is incorrect: An HTTP connector calls an API and returns raw data. It doesn't provide orchestrator-controlled selection across multiple tools.
D is incorrect: Placing the tools behind an external A2A agent hides them behind that agent's reasoning, which conflicts with the requirement.
Q03 - Question
You add an Agent2Agent connection to a Copilot Studio orchestrator. After you enter the partner's endpoint URL, Copilot Studio doesn't populate the agent name and description. Which two actions should you take? Each correct answer presents part of the solution.
Domain: Test and manage agents (20–25%) Type: Multiple choice
- A. Change the authentication type to None so that Copilot Studio can retrieve the agent card.
- B. Verify the endpoint URL and the agent card JSON at /.well-known/agent.json.
- C. Replace the A2A connection with an HTTP connector until the partner publishes a new endpoint.
- D. Enter the name and description manually while the external owner corrects the missing or malformed agent card.
B and D are correct.
Explanation: Copilot Studio retrieves {endpoint}/.well-known/agent.json and populates the name and description only when the agent card is valid. If discovery fails, verify the endpoint and the card JSON. You can enter the name and description manually while the external owner fixes the card.
A is incorrect: Authentication doesn't fix a missing or malformed agent card. Use None only for unprotected development scenarios.
C is incorrect: An HTTP connector returns raw API data instead of an agent-generated response. It doesn't resolve an agent-card discovery failure.
Q04 - Question
A partner organization protects its A2A-enabled agent. The partner gives you a client ID, a client secret, an authorization URL, a token URL, and a refresh URL. You configure the Agent2Agent connection in Copilot Studio. Which authentication option should you select?
Domain: Test and manage agents (20–25%) Type: Single choice
- A. None, because the partner provides an endpoint URL.
- B. OAuth 2.0
- C. API key, with the client secret entered as the key value.
- D. None, with the client secret added to the agent routing description.
B is correct.
Explanation: OAuth 2.0 authentication requires a client ID, client secret, authorization URL, token URL, and refresh URL. These are the values that the partner provided.
A is incorrect: Use None only for unprotected development scenarios. The partner agent is protected.
C is incorrect: API-key authentication requires a header or query-parameter name and a key value. It doesn't use the OAuth 2.0 URLs and client credentials.
D is incorrect: Treat client secrets as sensitive credentials. The routing description is used to route requests, not to store secrets.
Q05 - Question
You connect a Copilot Studio orchestrator to an external shipment tracking agent by using A2A. The orchestrator also has internal agents. Before production, you need to validate that requests route to the correct agent. What should you do?
Domain: Test and manage agents (20–25%) Type: Single choice
- A. Test only in-scope shipment prompts, because out-of-scope prompts are handled by the external agent.
- B. Confirm that the agent card loads, and then publish the orchestrator without further testing.
- C. Broaden the external agent's routing description so that it captures more types of requests.
- D. Use the test canvas and activity log with in-scope, out-of-scope, edge-case, and multi-turn prompts, and then refine the descriptions to resolve routing ambiguity.
D is correct.
Explanation: Test delegation in the Copilot Studio test canvas and activity log with varied prompts. Include in-scope, out-of-scope, edge-case, and multi-turn prompts. Refine the descriptions to resolve routing ambiguity.
A is incorrect: Testing only in-scope prompts doesn't verify that unrelated requests stay away from the external agent.
B is incorrect: A valid agent card confirms discovery only. It doesn't validate routing accuracy or response quality.
C is incorrect: Routing descriptions must be specific and distinct from other agents. A broader description can overlap with internal agents and cause misrouting.
Q06 - Question
A bank has several Copilot Studio agents, including an account-opening agent. Each agent needs tools from the same group of backend systems. A central platform team wants to publish these tools once, maintain them in one place, and make updates available to connected agents without republishing each agent. What should you recommend?
Domain: Test and manage agents (20–25%) Type: Single choice
- A. Add a separate REST API tool for each backend system to every agent.
- B. Publish the tools on a centrally managed MCP server and connect each agent to that server.
- C. Create a separate connector tool for each backend system in every agent.
- D. Create topics in each agent that call each backend system individually.
B is correct.
Explanation: An MCP server publishes tools once for all connected agents. Updates made on the server become available to those agents without republishing them. This approach avoids separate integrations with each backend system.
A is incorrect: You define REST API tools separately in each agent. This approach repeats the integration work for each backend system and each agent.
C is incorrect: You define connector tools separately in each agent. This approach does not give you one centrally published set of tools.
D is incorrect: Topics in each agent that call each backend system create repeated integrations. This approach does not use a centrally managed tool source.
Q07 - Question
A maker is building a Copilot Studio agent for a single department. At a specific step in a topic, the agent must call a backend operation. What should the maker use for this integration?
Domain: Test and manage agents (20–25%) Type: Single choice
- A. Connect an MCP server and call the MCP tool directly from the topic.
- B. Turn off generative orchestration and connect an MCP server.
- C. Edit the MCP tool description in Copilot Studio so that the topic can select the tool.
- D. Use a connector or REST API tool in the agent.
D is correct.
Explanation: A topic-triggered call is a use case for a connector or a REST API tool. You define these tools in the agent. They give you more control than MCP tools and work for one-off integrations.
A is incorrect: Topics cannot call MCP tools directly. Only generative orchestration can invoke MCP tools.
B is incorrect: MCP tools require generative orchestration. If you turn off generative orchestration, the agent cannot invoke MCP tools.
C is incorrect: You cannot edit MCP tool descriptions in Copilot Studio. Also, a description change does not let a topic call an MCP tool.
Q08 - Question
A partner hosts a custom MCP server that uses Server-Sent Events (SSE) as its transport. You need to connect a Copilot Studio agent to this server. What should you do first?
Domain: Test and manage agents (20–25%) Type: Single choice
- A. Ask the server owner to migrate the server to Streamable HTTP, and then enter the HTTPS Streamable HTTP endpoint in the onboarding wizard.
- B. Select SSE as the transport type in the MCP onboarding wizard.
- C. Add the partner server from the MCP catalog so that Microsoft manages the endpoint configuration.
- D. Configure OAuth 2.0 authentication so that the agent can connect to the SSE endpoint.
A is correct.
Explanation: Copilot Studio supports only the Streamable HTTP transport. The server URL must be the HTTPS Streamable HTTP endpoint that the server owner provides. An SSE server must migrate before you can connect to it.
B is incorrect: SSE has not been supported since August 2025. You cannot use SSE to connect the server.
C is incorrect: The MCP catalog provides prebuilt Microsoft connectors. A custom partner server requires onboarding configuration.
D is incorrect: The authentication type does not change the transport. The server must still use Streamable HTTP.
Q09 - Question
You connect an agent to an MCP server that returns sensitive production data. The server supports OAuth 2.0, but its identity provider doesn't support Dynamic Client Registration (DCR). Which OAuth 2.0 option should you configure?
Domain: Test and manage agents (20–25%) Type: Single choice
- A. Dynamic discovery
- B. Dynamic
- C. Manual
- D. None
C is correct.
Explanation: Use Manual when the identity provider doesn't support DCR. Provide the client credentials and configure the endpoints. If the identity provider requires it, register the generated callback URL.
A is incorrect: Dynamic discovery requires DCR with discovery endpoints. The identity provider doesn't support DCR.
B is incorrect: Dynamic requires DCR. With this option, you provide the authorization and token URLs because discovery isn't available.
D is incorrect: None is suitable for trusted, network-controlled servers. Use API key or OAuth 2.0 for sensitive production data.
Q10 - Question
An account-opening agent is connected to a shared MCP server that exposes many tools. Allow all is on. During testing, the orchestrator sometimes selects tools that the account-opening workflow doesn't need. Some server-published tool descriptions are vague. Which two actions should you take? Each correct answer presents part of the solution.
Domain: Test and manage agents (20–25%) Type: Multiple choice
- A. Edit the vague MCP tool descriptions on the Tools page in Copilot Studio.
- B. Turn off Allow all and enable only the tools that the account-opening workflow needs.
- C. Create topics that call the correct MCP tools directly.
- D. Ask the MCP server owner to update the vague tool descriptions on the server.
B and D are correct.
Explanation: When you turn off Allow all and enable only the tools that the workflow needs, you reduce orchestration ambiguity and apply least privilege. The orchestrator uses server-published tool descriptions to select tools. Only the server owner can update those descriptions.
A is incorrect: MCP tool descriptions are read-only in Copilot Studio. The server owner must update inadequate descriptions.
C is incorrect: Topics cannot call MCP tools directly. Only generative orchestration can invoke MCP tools.