Courseiva

AI-102 Implement an agentic solution Practice Question

A logistics company runs an Azure AI Agent Service agent that must call an internal REST API to book delivery slots. The API requires a per-tenant OAuth token that must never be visible in run logs or agent definitions. The agent is invoked by many tenants through your own web application. Which approach should you use to give the agent access to the API securely?

⚠ Common exam trap

The trap here is treating function tools as the only way to call external APIs, when OpenAPI tools with managed connections are designed precisely to keep credentials out of model-visible data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define the API as an OpenAPI tool with a project connection that holds the credential, and pass the tenant identity as a non-secret parameter.

Using an OpenAPI tool with a project connection keeps credentials server-side while still letting the agent decide when to invoke the booking API. The tenant identifier travels as an ordinary parameter, so logs remain free of secrets and per-tenant authorization is resolved by the connection at call time rather than by the model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Define the API as an OpenAPI tool with a project connection that holds the credential, and pass the tenant identity as a non-secret parameter.

    Why this is correct

    OpenAPI tools let the service make the HTTP call on the agent's behalf, and the credential lives in the project connection rather than in messages or agent configuration. Passing only a tenant identifier as a tool parameter keeps the secret out of logs while still letting each invocation resolve the correct authorization behind the connection.

  • ✗

    Store the tenant token in the agent's instructions and let the model include it in the function call arguments.

    Why it's wrong here

    Instructions and tool arguments are part of the conversation and appear in run steps and logs, so the token would be exposed to anyone who can read thread data. It also places secret material inside model context, which is neither auditable nor rotatable without editing the agent. This fails the requirement that the token never be visible.

  • ✗

    Have the agent emit the tenant ID, then let your web application call the booking API directly and append the response as a user message.

    Why it's wrong here

    This moves orchestration back into your application and breaks the agentic pattern where the agent decides when to call the API. The model would have to be prompted to emit a structured request, and you would need extra code to resume the run with the result, adding latency and complexity without using the agent's native tool pipeline.

  • ✗

    Create a function tool that returns the tenant token to the model so the model can place it in the next function call.

    Why it's wrong here

    Returning the token as function output writes the secret into the thread and run history, which is exactly what the scenario forbids. Even if the token is short-lived, it becomes readable by anyone with access to thread data and may be captured in telemetry. Credentials should be resolved server-side by the tool, not surfaced to the model.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.