AI-200 Containerized AI Workloads Practice Question
You are using Azure Container Apps to host a web API for an AI model. You want to ensure that only authorized traffic reaches the container. How should you secure the endpoint?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Authentication' in the Ingress settings.
Container Apps can be placed in a VNET or use 'Ingress' settings with 'Authentication' enabled (e.g., Azure AD).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an Azure Firewall in front of the Container App.
Why it's wrong here
While possible, it is an architectural pattern, not an endpoint configuration.
- ✓
Enable 'Authentication' in the Ingress settings.
Why this is correct
ACA provides built-in authentication integration for ingress.
- ✗
Use the --allow-all flag in the deployment command.
Why it's wrong here
This explicitly opens the container to all traffic.
- ✗
Place the container in a Public IP configuration.
Why it's wrong here
Public IP makes the container accessible to everyone.
About these practice questions
Courseiva writes every AI-200 question from scratch — 507 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Microsoft exam blueprint
This AI-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-200 exam.