Courseiva
Genaiops InfrastructurehardMultiple ChoiceObjective-mapped

AI-300 Genaiops Infrastructure Practice Question

You are securing an agent orchestration infrastructure where agents must access internal data stores. To prevent data exfiltration, you need to restrict all traffic to the Azure AI Foundry project to a private network. What should be configured?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a Private Endpoint for the Azure AI project and disable public access.

A Private Endpoint for the Azure AI project ensures that all communication with the service happens over a private IP address within your VNet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable a Virtual Network Service Endpoint on the storage account only.

    Why it's wrong here

    Service Endpoints provide connectivity but are less secure than Private Endpoints for enterprise data exfiltration prevention.

  • Implement an Azure Firewall to inspect all outbound traffic from the agents.

    Why it's wrong here

    While useful for outbound filtering, it does not secure the ingress to the AI Foundry project itself.

  • Use an API Gateway with IP whitelisting.

    Why it's wrong here

    IP whitelisting is not as robust as Private Link/Private Endpoints for securing internal service communication.

  • Configure a Private Endpoint for the Azure AI project and disable public access.

    Why this is correct

    Private Endpoints ensure traffic stays on the Microsoft backbone and is isolated from the public internet.

About these practice questions

One of 204 original AI-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Microsoft exam blueprint

This AI-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-300 exam.