AI-102 Implement agentic AI solutions Practice Question
A company is building an agent using Azure AI Foundry Agent Service. The agent must be able to call an external REST API that returns real-time inventory data. The API requires an OAuth 2.0 token that changes frequently. Which approach should the team use to enable the agent to call this API securely?
⚠ Common exam trap
The trap here is assuming that managed identity can authenticate to any external API, but it only works with resources that trust Microsoft Entra ID.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a function tool in the agent definition that invokes an Azure Function, which retrieves the token from Azure Key Vault and calls the REST API.
The correct approach is to use a function tool that invokes an Azure Function, which securely retrieves the OAuth token from Azure Key Vault and calls the REST API. This keeps credentials out of the agent and handles token refresh. Other options either expose the token, rely on unsupported authentication, or misuse the knowledge base.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the agent to use a managed identity and assign it the necessary permissions to call the REST API directly.
Why it's wrong here
Managed identity can authenticate to Azure resources that support Microsoft Entra ID, but the external REST API requires an OAuth 2.0 token from a third-party identity provider. Managed identity cannot directly obtain tokens for arbitrary external APIs. This approach would fail unless the external API supports federated identity, which is not stated.
- ✗
Store the OAuth token in the agent's knowledge base and have the agent retrieve it when needed.
Why it's wrong here
Storing tokens in a knowledge base is not secure and does not provide a mechanism for automatic token refresh. The agent might retrieve an expired token, causing API calls to fail. Knowledge bases are designed for documents, not secrets, and this approach would expose sensitive credentials to anyone with access to the knowledge base.
- ✓
Use a function tool in the agent definition that invokes an Azure Function, which retrieves the token from Azure Key Vault and calls the REST API.
Why this is correct
This approach is correct because the agent can call an Azure Function as a function tool, and the function can securely retrieve the OAuth token from Key Vault at runtime. This keeps the token out of the agent's configuration and allows the function to handle token refresh and API calls, ensuring secure and up-to-date authentication for the external REST API.
- ✗
Embed the OAuth token in the agent's system prompt so the agent can include it in API calls.
Why it's wrong here
Embedding the token in the system prompt is insecure because the token would be visible in logs and could be exposed to users. Additionally, tokens expire, so the agent would need manual updates. This approach does not support automatic token refresh and violates security best practices for handling credentials in Azure AI solutions.
Go deeper
Related to this question
About these practice questions
One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.