AI-102 Practice Question: Implement natural language processing solutions
A healthcare company uses Azure AI Language's custom question answering to build a bot that answers patient FAQs. The knowledge base contains documents with sensitive information. The company needs to ensure that the bot only returns answers from documents that the user is authorized to access. What should they implement?
⚠ Common exam trap
It's easy for candidates to confuse authentication with authorization; authenticating a user does not automatically restrict which documents they can retrieve answers from.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement document-level access control by using metadata tags and filtering in the query.
The correct solution is to use metadata tags on documents and apply filters during query execution. This allows the custom question answering service to return only answers from documents that match the user's authorization level. Other options either address resource management, require complex duplication, or only authenticate without enforcing access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the bot to prompt users for credentials before answering and validate against Microsoft Entra ID.
Why it's wrong here
Authenticating users is necessary but not sufficient. Even if a user is authenticated, the bot must still filter answers based on what that user is allowed to access. Without metadata filtering, an authenticated user could still receive answers from unauthorized documents. Authentication alone does not enforce document-level authorization.
- ✗
Enable role-based access control (RBAC) on the Azure AI Language resource.
Why it's wrong here
RBAC on the Azure resource controls who can manage the service, not which documents a user can access through the bot. It does not filter answers based on user identity at query time. The requirement is to restrict answer content based on user authorization, which requires a different mechanism integrated into the query pipeline.
- ✓
Implement document-level access control by using metadata tags and filtering in the query.
Why this is correct
Azure AI Language custom question answering supports metadata on documents, which can be used to tag documents with access levels or user groups. At query time, you can filter results based on metadata, ensuring users only get answers from documents they are authorized to see. This is the recommended approach for document-level security.
- ✗
Use separate knowledge bases for each user group and route queries based on user identity.
Why it's wrong here
Separate knowledge bases would require duplicating content and complex routing logic, which is inefficient and hard to maintain. It also does not dynamically enforce per-user access; it only segments by group. The scenario requires granular control based on individual user authorization, not just group-level separation.
Go deeper
Related to this question
About these practice questions
One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.