Courseiva

AI-102 Implement agentic AI solutions Practice Question

A media company is building an Azure AI Foundry agent that generates summaries of news articles. The agent uses a tool to fetch articles from an internal CMS. The company wants to ensure the agent respects content usage rights and does not summarize articles that are marked as restricted. The agent must also log every article it accesses for auditing. Which two actions should the team take? (Choose two.)

⚠ Common exam trap

The trap here is relying on prompt instructions to enforce content restrictions, which is not deterministic, instead of implementing access control at the tool or data source level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable diagnostic logging on the Azure AI Foundry resource to capture all tool calls and their responses.

To respect usage rights, the CMS tool should filter articles based on the usage rights field before they reach the agent, ensuring only permissible content is summarized. To audit access, diagnostic logging on the Azure AI Foundry resource captures all tool calls and responses. Together, these actions enforce policy at the data layer and provide a verifiable audit trail without exposing restricted content to the model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Instruct the agent in its system message to ignore articles that are marked restricted.

    Why it's wrong here

    Instructions in the system message are not a reliable enforcement mechanism. The model might still process restricted content if it appears in the context, and there is no guarantee it will comply. This approach also does not prevent restricted articles from being fetched, so the data could be exposed in logs or intermediate steps. It fails to provide a deterministic control.

  • ✓

    Enable diagnostic logging on the Azure AI Foundry resource to capture all tool calls and their responses.

    Why this is correct

    Diagnostic logging captures tool invocations and responses, providing an audit trail of every article the agent accesses. This satisfies the auditing requirement by recording which articles were fetched and when. It works in conjunction with access controls to ensure compliance, and it does not expose restricted content because the filtering already prevents such articles from being returned.

  • ✗

    Use a content filter to block articles that contain certain keywords associated with restricted content.

    Why it's wrong here

    Keyword-based content filters are imprecise and may block legitimate articles or miss restricted ones. Usage rights are metadata, not necessarily reflected in keywords. This method does not reliably enforce the policy and could disrupt summarization of allowed content. It also does not provide auditing, so it fails both requirements.

  • ✗

    Store a copy of every article in the agent's conversation history for later review.

    Why it's wrong here

    Storing articles in conversation history does not provide a reliable audit log and may violate data retention policies. It also increases the risk of exposing restricted content if the history is accessed. This approach does not enforce usage rights and duplicates data unnecessarily. It is not a substitute for proper diagnostic logging or access control.

  • ✓

    Configure the CMS tool to return only articles with a usage rights field set to 'public' or 'licensed', and have the agent filter based on that field.

    Why this is correct

    Filtering at the tool level ensures restricted articles never reach the agent's context. By returning only articles with permissible usage rights, the agent cannot summarize restricted content. This approach enforces policy at the data access layer, which is more reliable than relying on the model to self-censor, and it reduces the risk of accidental misuse.

About these practice questions

Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.