AI-102 Practice Question: Implement natural language processing solutions
A healthcare portal must summarize patient feedback stored in Azure Blob Storage. Documents are plain UTF-8 text and the summaries must be generated without sending content to a public endpoint. You are building the pipeline with Azure AI Language and a private network. Which configuration should you use to call extractive summarization while meeting the network requirement?
⚠ Common exam trap
The trap here is treating encryption in transit or IP allowlisting as equivalent to eliminating the public endpoint entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure AI Language resource with a private endpoint and disable public network access, then call the REST API from a client inside the virtual network.
Meeting a no-public-endpoint requirement means the Azure AI Language resource must be reachable only through private networking. Combining a private endpoint with disabled public network access forces all calls, including extractive summarization, to travel inside the virtual network, which keeps document content off the public internet while preserving full API functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an Azure AI Language resource with a private endpoint and disable public network access, then call the REST API from a client inside the virtual network.
Why this is correct
A private endpoint places the Azure AI Language resource inside your virtual network and disabling public network access blocks internet traffic, so REST calls from an in-network client never traverse a public endpoint. This satisfies the requirement while still allowing the extractive summarization operation, which is available through the standard Language REST API.
- ✗
Deploy the open-source summarization container for Azure AI Language on an Azure Kubernetes Service cluster and call its local endpoint.
Why it's wrong here
The containerized Language features that support disconnected use do not include extractive summarization, so this container cannot perform the required operation. Even where containers exist, they require specific licensing and connectivity checks, so proposing this for summarization misstates the available capability and would not deliver the summaries.
- ✗
Create a standard Azure AI Language resource and authenticate with an account key, relying on TLS to protect the content in transit.
Why it's wrong here
TLS encrypts traffic but the resource still exposes a public endpoint, so content leaves your network boundary and reaches a publicly addressable host. The requirement forbids sending content to a public endpoint, and key-based authentication does not change the network path, so this design fails the stated constraint even though it is secure in transit.
- ✗
Use the Azure AI Language resource with a service tag firewall rule that allows only the portal's app service outbound IP addresses.
Why it's wrong here
IP allowlisting restricts who may call the public endpoint, but the endpoint itself remains publicly addressable and the request still egresses to it. The requirement is that content is not sent to a public endpoint at all, so narrowing the source addresses does not satisfy it; a private endpoint is what removes the public exposure.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
This AI-102 question is part of Courseiva's 761-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.