AI-102 Plan and manage an Azure AI solution Practice Question
A healthcare organization uses Azure AI Language to extract medical entities from clinical notes. The solution must comply with HIPAA and data residency requirements. Which configuration is essential?
⚠ Common exam trap
Many candidates confuse network-level security (private endpoints) or encryption controls (CMK) with data residency, assuming any security measure automatically satisfies geographic compliance requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create the AI resource in the required Azure region.
Data residency requirements dictate that the Azure AI Language resource must be physically located in the specific Azure region where the clinical notes and extracted medical entities are permitted to reside. Creating the resource in the required Azure region ensures that all data at rest and in transit stays within that geographic boundary, which is a fundamental compliance step for HIPAA and data residency. Other configurations like encryption keys or private endpoints enhance security but do not satisfy the core residency requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable diagnostic logging for all operations.
Why it's wrong here
Diagnostic logging records operations for auditing and troubleshooting; it neither constrains where data is stored nor establishes the HIPAA safeguards the stem requires. It is tempting because logging is a common compliance expectation, but the essential configuration is selecting a resource region within the required geography under an approved agreement.
- ✗
Use a customer-managed key (CMK) for encryption.
Why it's wrong here
Customer-managed keys control encryption key ownership, not the physical location where clinical notes are processed or stored, so residency remains unaddressed. It is tempting because CMK is a recognised data-protection control, but the stem's requirement is geographic placement of the AI resource, which region selection determines.
- ✗
Enable private endpoint for the AI resource.
Why it's wrong here
A private endpoint restricts network access to the resource but does not itself pin data to a geography or satisfy the HIPAA assurance requirements; residency is set by the resource region and a BAA. It is tempting because private endpoints are a standard network-isolation control, yet the stem asks for the configuration governing data location and compliance.
- ✓
Create the AI resource in the required Azure region.
Why this is correct
Data residency requires the Azure AI resource to reside in the mandated geography, because Azure AI Language processes and stores data in the resource's region. Creating the resource in the required region satisfies the residency constraint; HIPAA compliance is then addressed through the resulting regional deployment.
Go deeper
Related to this question
About these practice questions
This AI-102 question is part of Courseiva's 761-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.