Courseiva

CCNA Implement an agentic solution Questions

31 questions · Implement an agentic solution · All types, answers revealed

1
Multi-Selectmedium

You are designing an agent in Microsoft Copilot Studio that must answer questions by using a large corpus of internal policy documents. The agent must provide accurate citations and must not invent policy details. You need to configure knowledge sources and grounding behaviour. Which two actions should you take? (Choose two.)

Select 2 answers
A.Configure the agent to use generative answers with the knowledge source and review the moderation settings.
B.Disable the knowledge source and rely on the model's pre-trained policy knowledge.
C.Publish the agent immediately and let user feedback correct inaccurate policy statements over time.
D.Add the policy documents as a knowledge source and enable citations in responses.
E.Increase the agent's creativity level to high so it can paraphrase policies more naturally.
AnswersA, D

Generative answers let the agent compose responses grounded in the configured knowledge source, which is how citations and accurate policy summarization are produced. Reviewing moderation settings ensures the generated content meets organizational standards for the policy domain. Together with a knowledge source, this is the supported way to deliver grounded, cited answers.

Why this answer

Grounding the agent in the policy documents and enabling citations ensures answers trace back to authoritative content, while generative answers with reviewed moderation settings produce compliant responses. High creativity and reliance on pre-trained knowledge both increase the chance of fabricated policy details, and deferring accuracy to post-publication feedback does not meet the requirement.

Exam trap

The trap here is assuming that a more creative model produces better policy answers, when creativity increases the likelihood of unsupported details.

2
MCQhard

You are developing an agentic solution that uses Azure AI Agent Service with a custom function calling tool. The agent needs to call a function that requires authentication to an external API. How should you securely pass the API key to the function?

A.Hardcode the API key in the function code
B.Use Azure Key Vault to store the API key and reference it in the function
C.Store the API key in an environment variable
D.Pass the API key as part of the agent's system prompt
AnswerB

Storing the key in Azure Key Vault keeps the secret out of code and prompt context, satisfying the secure-authentication constraint. The function retrieves it at runtime via its managed identity, so credentials are never exposed in the agent definition or logs.

Why this answer

Azure Key Vault provides a secure, centralized service for storing and managing secrets like API keys. In Azure AI Agent Service, you can configure the function to retrieve the API key at runtime from Key Vault using managed identities, ensuring the key is never exposed in code, configuration, or prompts. This follows the principle of least privilege and aligns with Azure's security best practices for agentic solutions.

Exam trap

The trap here is that candidates often choose environment variables (Option C) because they seem 'secure enough' in local development, but Azure explicitly tests that environment variables are not considered secure for production secrets in cloud-native solutions, especially when audit trails and fine-grained access control are required.

How to eliminate wrong answers

Option A is wrong because hardcoding the API key in the function code violates security best practices, as the key would be exposed in source control, logs, and compiled binaries. Option C is wrong because storing the API key in an environment variable is insecure in cloud environments; environment variables can be leaked through process dumps, logs, or misconfigured container settings, and they lack access control and auditing. Option D is wrong because passing the API key as part of the agent's system prompt would expose the secret in prompt logs, conversation history, and potentially to the language model itself, creating a severe security vulnerability.

3
MCQmedium

You are developing an agent by using the Azure AI Foundry Agent Service. The agent must query a proprietary internal REST API that returns JSON data. The API requires an OAuth 2.0 access token for authentication. You need to configure the agent to call this API. What should you do?

A.Configure an OpenAPI tool for the agent, specifying the API's OpenAPI specification and setting up an OAuth 2.0 connection for authentication.
B.Use the Azure AI Foundry SDK to programmatically inject the OAuth token into each request by using a custom middleware component.
C.Add the API endpoint as a knowledge source in Azure AI Search and use integrated vectorization to index the JSON responses.
D.Create a custom tool by using a function calling definition that includes the API endpoint and authentication details, and register it with the agent.
AnswerA

OpenAPI tools in Azure AI Foundry Agent Service allow you to import an API specification and configure authentication, including OAuth 2.0. This provides a secure, managed way for the agent to call the API, handling token acquisition and refresh automatically. This is the recommended approach for integrating external REST APIs with OAuth.

Why this answer

The agent must call an OAuth-protected REST API. Azure AI Foundry Agent Service supports OpenAPI tools, which allow you to import an API specification and configure OAuth 2.0 authentication. This enables the agent to securely call the API, with the service handling token acquisition and refresh.

Other options either lack secure authentication support or are not designed for dynamic API invocation.

Exam trap

The trap here is assuming that function calling definitions can handle authentication, but they only describe the API schema and do not manage credentials securely.

4
MCQhard

Refer to the exhibit. You have created an assistant with the above configuration. When you send a message 'What is the weather in Seattle?', the assistant responds without calling the function. What is the most likely cause?

A.The 'instructions' are not being followed
B.The 'strict' parameter is set to true
C.The function is missing the 'description' property
D.The 'tool_resources' code_interpreter has empty file_ids
AnswerC

Function definitions require a description so the model can judge when to invoke them. Without it, the model cannot match the weather query to the function and answers from its own knowledge instead of calling it.

Why this answer

The function definition lacks a 'description' property. In the Assistants API, the 'description' field is critical for the model to understand when and why to invoke a function. Without it, the model may not recognize that the function is relevant to the user's query about weather, causing it to respond directly instead of calling the function.

Exam trap

Azure AI often tests the misconception that the 'instructions' field or 'strict' parameter is the primary driver for function calling, when in reality the 'description' property is the key enabler for the model to understand tool relevance.

How to eliminate wrong answers

Option A is wrong because the 'instructions' field is used to set the assistant's behavior and system prompt, but it does not directly control function calling; the model can still ignore instructions if function definitions are incomplete. Option B is wrong because setting 'strict' to true (if supported) would enforce schema adherence, not prevent function calls; it would actually make the model more likely to follow the defined tools. Option D is wrong because 'tool_resources' with empty 'file_ids' for code_interpreter only affects file-based retrieval or code execution, not the decision to call a function; the function tool is defined separately in the 'tools' array.

5
MCQeasy

A company wants to build a customer support agent using Microsoft Copilot Studio. The agent needs to understand natural language and handle complex queries beyond simple keyword matching. The agent should be able to escalate to a human agent when it cannot resolve the issue. Which feature should the agent use to understand natural language?

A.Create a Power Automate flow to process queries.
B.Enable generative answers and configure a knowledge source.
C.Create topics with trigger phrases.
D.Use entities to extract key information.
AnswerB

Generative answers with a configured knowledge source let the agent use large language models to interpret intent and retrieve relevant content, handling complex queries beyond keyword matching. This satisfies the natural language understanding requirement, and escalation can be added separately.

Why this answer

Generative answers in Microsoft Copilot Studio use large language models (LLMs) to interpret natural language queries and generate responses based on configured knowledge sources (e.g., SharePoint, websites, or custom data). This enables the agent to handle complex, conversational queries beyond simple keyword matching, and it can escalate to a human agent when confidence is low or the issue cannot be resolved.

Exam trap

The trap here is that candidates often confuse entity extraction (Option D) or topic triggers (Option C) with true natural language understanding, not realizing that generative answers powered by LLMs are required for handling complex, unconstrained queries beyond simple keyword matching.

How to eliminate wrong answers

Option A is wrong because Power Automate flows are for automating workflows and integrating systems, not for understanding natural language or handling complex queries in a conversational agent. Option C is wrong because topics with trigger phrases rely on keyword-based pattern matching to route conversations, which cannot handle the nuanced, multi-turn understanding required for complex queries. Option D is wrong because entities extract specific data points (e.g., dates, product names) from user input but do not provide the broad natural language comprehension needed to interpret and respond to complex queries.

6
MCQeasy

You are building an agent using Microsoft Copilot Studio to handle customer returns. The agent must collect the order ID, reason for return, and then provide a return shipping label. The process requires the user to provide information step-by-step. Which type of conversation flow should you implement?

A.Use an adaptive card to collect all inputs in one step.
B.Use multiple question nodes in a sequential flow.
C.Use a single question node to collect all information at once.
D.Use a generative answers node to parse the user's intent.
AnswerB

Sequential question nodes present one prompt at a time and wait for the user's answer before advancing, which matches the requirement to collect order ID and return reason step-by-step. Each node captures a single value, ensuring ordered data collection before the shipping label is generated.

Why this answer

Microsoft Copilot Studio uses 'Question' nodes to collect user input one piece at a time in a sequential flow, which matches the step-by-step requirement for order ID, reason, and shipping label. This approach ensures each piece of data is validated before moving to the next, maintaining a guided conversation.

Exam trap

The trap here is that candidates might confuse the flexibility of generative answers or adaptive cards with the structured, sequential data collection needed for transactional workflows, overlooking that Copilot Studio's Question nodes are purpose-built for step-by-step input gathering.

How to eliminate wrong answers

Option A is wrong because an adaptive card collects all inputs in one step, which violates the requirement for step-by-step collection and can overwhelm users or miss validation per field. Option C is wrong because a single question node cannot collect multiple distinct pieces of information at once; it only handles one input per node. Option D is wrong because a generative answers node is designed for open-ended Q&A using AI, not for structured data collection with specific fields like order ID and reason.

7
MCQmedium

A company plans to deploy a Copilot Studio agent to Microsoft Teams. The agent should be available to all employees in the company. The security team requires that only authenticated users from the company's Microsoft Entra ID tenant can access the agent. Which channel configuration should be used?

A.Publish the agent to the Direct Line channel and embed it in a Teams tab.
B.Publish the agent to the Web channel and share the link in Teams.
C.Publish the agent to the Teams channel and turn off authentication.
D.Publish the agent to the Teams channel and configure authentication to require Microsoft Entra ID with the company's tenant ID.
AnswerD

Publishing to the Teams channel with authentication set to Microsoft Entra ID and the company's tenant ID restricts access to authenticated employees within that tenant, satisfying the security team's requirement that only tenant users reach the agent.

Why this answer

Publishing the Copilot Studio agent to the Teams channel and configuring authentication to require Microsoft Entra ID with the company's tenant ID ensures that only authenticated users from that specific tenant can access the agent. This meets the security requirement by restricting access to the company's Entra ID tenant, while the Teams channel provides native integration for all employees.

Exam trap

The trap here is that candidates may think the Teams channel inherently restricts access to the company's tenant, but without explicitly configuring authentication to require the specific tenant ID, the agent could be accessible to external guests or users from other tenants.

How to eliminate wrong answers

Option A is wrong because the Direct Line channel is designed for custom application integration, not for native Teams distribution, and embedding it in a Teams tab would not enforce the required Entra ID authentication at the channel level. Option B is wrong because the Web channel uses anonymous or generic authentication by default, and sharing a link in Teams does not restrict access to the company's Entra ID tenant. Option C is wrong because turning off authentication on the Teams channel would allow any user, including unauthenticated or external users, to access the agent, violating the security requirement.

8
MCQmedium

You are designing an agent that uses Azure AI Search as a knowledge store. The agent must handle multiple languages. Which feature should you configure in Azure AI Search to ensure the agent retrieves relevant results for queries in different languages?

A.Scoring profiles
B.Language analyzers
C.Semantic search
D.Synonym maps
AnswerB

Language analyzers apply language-specific tokenisation, stemming and stop-word rules per field, so indexed content and queries in each language are processed consistently. This lexical matching satisfies the stem's requirement that the agent retrieve relevant results across multiple languages.

Why this answer

Language analyzers in Azure AI Search are specifically designed to handle linguistic variations across different languages, such as stemming, stop word removal, and tokenization rules. By configuring the appropriate language analyzer (e.g., 'en.microsoft' for English or 'fr.microsoft' for French) on a searchable field, the agent can retrieve relevant results for queries in multiple languages because the analyzer processes both the indexed content and the query string using the same language-specific rules.

Exam trap

The trap here is that candidates often confuse semantic search (which improves relevance via AI) with language-specific text processing, assuming semantic search alone can handle multilingual queries, but semantic search still relies on the underlying analyzer for tokenization and cannot perform language-specific stemming or stop word removal.

How to eliminate wrong answers

Option A is wrong because scoring profiles influence the ranking of search results based on fields, functions, or weights, but they do not alter how text is tokenized or stemmed for different languages; they cannot ensure cross-lingual retrieval relevance. Option C is wrong because semantic search improves result relevance by understanding query intent and context using deep learning models, but it does not provide language-specific tokenization or stemming; it works on top of existing analyzers and is not a substitute for language analyzers. Option D is wrong because synonym maps expand queries with equivalent terms but do not handle language-specific linguistic rules like stemming or diacritic normalization; they are language-agnostic and cannot adapt to different languages' morphological structures.

9
MCQeasy

You are using Microsoft Copilot Studio to create an agent that handles customer support. The agent needs to understand the user's intent from free-text input. Which feature should you use to map user utterances to specific topics?

A.Configure variables to capture user input
B.Add actions to process the input
C.Create custom entities to extract key phrases
D.Define trigger phrases for each topic
AnswerD

Trigger phrases map free-text utterances to specific topics by matching user input against defined example phrases, letting the agent route intent correctly. This is Copilot Studio's native mechanism for intent recognition without custom language models.

Why this answer

In Microsoft Copilot Studio, trigger phrases are the primary mechanism for mapping user utterances to specific topics. When a user types a free-text input, the agent's natural language understanding (NLU) engine compares the input against the defined trigger phrases for each topic. The topic with the highest confidence score based on semantic similarity is triggered, enabling intent recognition without requiring exact keyword matches.

Exam trap

The trap here is that candidates often confuse entity extraction (Option C) with intent recognition, assuming that extracting key phrases is sufficient to understand the user's intent, whereas in Copilot Studio, trigger phrases are the dedicated feature for mapping utterances to topics.

How to eliminate wrong answers

Option A is wrong because configuring variables captures and stores user input after it has been processed, but does not perform intent recognition or map utterances to topics. Option B is wrong because actions (such as calling Power Automate flows or APIs) are used to execute logic after a topic is triggered, not to understand the user's intent from free-text input. Option C is wrong because custom entities extract specific data points (like product names or dates) from utterances, but they do not map the entire utterance to a topic; entities are used within a topic to refine understanding, not to trigger the topic itself.

10
MCQeasy

You are creating an agent in Microsoft Foundry that answers questions about internal HR policies. The policy documents are already indexed in Azure AI Search, and you want the fastest path to a working agent without writing retrieval code. What should you do first?

A.Upload the policy documents to the agent's file storage and enable file search.
B.Export the policies to CSV and attach them as a code interpreter file.
C.Build an Azure Functions app that queries the index and expose it as a function tool.
D.Create the agent, then connect the existing Azure AI Search index as a knowledge source for the agent.
AnswerD

Because the documents are already indexed, connecting that index as a knowledge source is the minimal-effort path. The agent gains retrieval over the policy content immediately, with the service handling queries and context injection, so no custom retrieval code is needed and the existing index investment is reused.

Why this answer

Connecting the existing Azure AI Search index as a knowledge source gives the agent retrieval over the HR policies with no custom retrieval code. It reuses the index the organization already maintains, so content updates flow through automatically and the agent is functional with minimal configuration.

Exam trap

The trap here is reaching for a custom function or file upload when an existing search index can be connected directly as a knowledge source.

11
MCQmedium

A company uses Microsoft Copilot Studio to create an agent that helps employees schedule meetings. The agent must access the user's calendar to find free time slots and book meetings. The agent should only work for users who have granted consent. Which authentication and authorization approach should be used?

A.Configure OAuth 2.0 authentication with Microsoft Entra ID and request delegated permissions for Microsoft Graph.
B.Use certificate-based authentication for the agent.
C.Use API key authentication to call Microsoft Graph.
D.Use OAuth 2.0 client credentials flow with application permissions.
AnswerA

OAuth 2.0 with Microsoft Entra ID and delegated Microsoft Graph permissions ensures the agent acts only on behalf of users who granted consent, scoping calendar access to their own free/busy data. Application permissions would bypass per-user consent, violating the requirement.

Why this answer

The agent needs to act on behalf of a signed-in user (delegated identity) to access their calendar. OAuth 2.0 with Microsoft Entra ID and delegated permissions for Microsoft Graph allows the agent to request only the scopes (e.g., Calendars.ReadWrite) that the user has consented to, ensuring the agent operates within the user's granted permissions.

Exam trap

The trap here is that candidates often confuse delegated permissions (user-context) with application permissions (tenant-wide), and mistakenly choose the client credentials flow (Option D) because it seems simpler, but it violates the explicit requirement for per-user consent.

How to eliminate wrong answers

Option B is wrong because certificate-based authentication is a method for establishing the identity of the agent itself (client credential), not for obtaining user-delegated access to a resource like a calendar; it does not support per-user consent. Option C is wrong because API key authentication is not supported by Microsoft Graph; Microsoft Graph requires OAuth 2.0 tokens and does not accept static API keys. Option D is wrong because the OAuth 2.0 client credentials flow uses application permissions, which grant the agent tenant-wide access to all users' calendars without per-user consent, violating the requirement that the agent should only work for users who have granted consent.

12
MCQhard

A developer is building an agent using the Microsoft Bot Framework SDK in C#. The agent must authenticate users via Microsoft Entra ID and maintain state across conversations. The solution must store user preferences (e.g., language, timezone) in Azure Cosmos DB. Which state management approach should the developer use?

A.Use the Bot State Service (deprecated).
B.Use UserState with Blob Storage.
C.Use ConversationState with Memory Storage.
D.Use UserState with Cosmos DB Storage.
AnswerD

UserState scopes data per user across conversations, and Cosmos DB Storage persists it durably, satisfying both the Entra ID authentication and cross-conversation preference requirements. ConversationState alone would lose language and timezone settings once the session ends.

Why this answer

The developer needs to persist user preferences across conversations, which requires UserState (not ConversationState, which is scoped to a single conversation). Cosmos DB Storage is the appropriate choice for durable, scalable, and low-latency storage of user-specific data, and it integrates directly with the Bot Framework SDK's `CosmosDbPartitionedStorage` class.

Exam trap

The trap here is confusing UserState (persistent across conversations) with ConversationState (temporary per conversation), leading candidates to incorrectly choose ConversationState with Memory Storage, which loses data when the bot restarts.

How to eliminate wrong answers

Option A is wrong because the Bot State Service was deprecated and is no longer supported; using it would violate the requirement for a modern, supported solution. Option B is wrong because Blob Storage is designed for large unstructured data (e.g., files, images) and is not optimized for the small, frequent read/write operations typical of user state in a bot; Cosmos DB is the recommended storage for state data. Option C is wrong because ConversationState is scoped to a single conversation and does not persist across conversations, so it cannot store user preferences that must be available across multiple sessions.

13
MCQhard

You are troubleshooting an agent built with Microsoft Copilot Studio. The agent uses a custom topic to check inventory levels. The topic calls a Power Automate flow that returns JSON with 'inStock' boolean. The agent sometimes says 'Item is in stock' even when the flow returns false. What is the most likely cause?

A.The Power Automate flow has a timeout and returns default true.
B.The topic's condition is using a variable that is not being updated with the flow output.
C.The agent's response is based on a different variable that defaults to true.
D.The agent's topic is not parsing the JSON output correctly.
AnswerB

The topic evaluates a variable that never receives the flow's 'inStock' output, so the condition tests stale or default data rather than the returned boolean. Binding the flow response to that variable before the condition resolves the false-positive 'in stock' message.

Why this answer

The most likely cause is that the topic's condition is referencing a variable that does not get updated with the flow's output. In Microsoft Copilot Studio, when a Power Automate flow returns data, the output must be explicitly assigned to a topic variable. If the condition checks a different variable (e.g., a default or uninitialized one), it will not reflect the actual 'inStock' value from the flow, leading to incorrect responses like 'Item is in stock' even when the flow returns false.

Exam trap

The trap here is that candidates may assume the issue is with JSON parsing (Option D) or flow timeout (Option A), but the real problem is a variable assignment mismatch, which is a subtle but critical configuration detail in Copilot Studio topic design.

How to eliminate wrong answers

Option A is wrong because a Power Automate flow timeout would typically cause an error or trigger a timeout branch, not silently return a default 'true' value; flows do not have a built-in mechanism to return default true on timeout. Option C is wrong because while the agent's response could be based on a different variable that defaults to true, this is essentially a restatement of the correct cause but lacks the specific mechanism of the variable not being updated with the flow output; the core issue is the variable assignment, not just a default value. Option D is wrong because Copilot Studio automatically parses JSON output from Power Automate flows into structured variables; incorrect parsing would usually result in an error or null value, not a consistent false positive where the agent says 'in stock' when the flow returns false.

14
MCQmedium

You are building an agent with Azure AI Agent Service. The agent must consult a product catalog stored in an Azure AI Search index before answering questions, and you want the retrieval to happen automatically on every run without writing any orchestration code. You have already created the index and a project connection to it. Which configuration should you apply to the agent?

A.Enable grounding by uploading the catalog documents to the agent's file storage and referencing them in the system message.
B.Attach the Azure AI Search index as a knowledge tool on the agent and let the service invoke it during runs.
C.Create a function tool that calls the Azure AI Search REST API and register it as a tool on every run.
D.Add the search index endpoint and admin key to the agent's instructions so the model can call it directly.
AnswerB

Knowledge tools are the built-in retrieval mechanism for Azure AI Agent Service. Once the search index is attached as a knowledge tool with a valid project connection, the service decides when to query it and injects the retrieved passages into the model context, so no application-side orchestration code is required for the automatic retrieval behavior described.

Why this answer

Attaching the Azure AI Search index as a knowledge tool is the native way Azure AI Agent Service performs retrieval-augmented generation. The service manages query formulation, execution against the index through the project connection, and injection of results into the model context, satisfying the no-orchestration-code requirement while reusing the existing index.

Exam trap

The trap here is assuming the model can reach an external search endpoint from instructions alone, when retrieval must be exposed as a tool backed by a project connection.

15
MCQhard

You are building an agent using Azure AI Agent Service that must execute code in a sandbox environment. The code should be able to install Python packages. Which action type should you use?

A.function
B.code_interpreter
C.openApi
D.httpRequest
AnswerB

The code_interpreter action type runs Python in a Microsoft-managed sandbox, satisfying the requirement to execute code safely. It supports installing packages at runtime via pip within that sandbox, so dependencies can be added dynamically. This directly meets the stem's constraint that the agent install Python packages during execution.

Why this answer

The code_interpreter action type in Azure AI Agent Service provides a sandboxed environment where code can be executed, and it supports installing Python packages via pip. This allows the agent to run code that requires additional libraries not pre-installed.

Exam trap

AI-102 often tests the differences between action types; candidates may confuse code_interpreter with function or httpRequest, but only code_interpreter provides a sandbox for executing code and installing packages.

How to eliminate wrong answers

Option A is wrong because the function action type is for calling custom functions defined in the agent, not for executing arbitrary code in a sandbox. Option C is wrong because openApi is for calling external APIs defined by OpenAPI specifications, not for code execution. Option D is wrong because httpRequest is for making HTTP requests, not for executing code or installing packages.

16
MCQeasy

You are building an agent in Microsoft Copilot Studio that needs to send a confirmation email after a user completes a survey. The email should be sent using the user's email address collected during the conversation. Which feature should you use to send the email?

A.Create a Power Automate flow that sends an email and call it from the topic.
B.Use the Send an email action directly in Copilot Studio.
C.Use an adaptive card with an email button.
D.Use the email channel to send a response.
AnswerA

Power Automate provides the Office 365 Outlook connector with a Send an email action, letting the topic pass the collected address as a dynamic input. Copilot Studio topics alone cannot dispatch SMTP mail, so the flow satisfies the send-after-survey requirement.

Why this answer

Microsoft Copilot Studio does not have a native 'Send an email' action; it relies on Power Automate flows to perform external actions like sending emails. By creating a flow that uses the user's email address collected during the conversation and calling it from the topic, you can send a confirmation email after the survey is completed.

Exam trap

The trap here is that candidates assume Copilot Studio has built-in email actions similar to Power Automate, but Microsoft deliberately separates conversation logic from external integrations to enforce a modular architecture.

How to eliminate wrong answers

Option B is wrong because Copilot Studio does not include a built-in 'Send an email' action; it lacks native email capabilities and must delegate such tasks to Power Automate. Option C is wrong because an adaptive card with an email button only provides a clickable interface to open the user's default mail client; it does not programmatically send an email from the bot. Option D is wrong because the email channel in Copilot Studio is used to receive and respond to messages via email, not to send outbound emails like a confirmation.

17
MCQmedium

You are troubleshooting an agentic solution where the agent is not returning responses within acceptable time limits. You suspect the agent is making too many sequential calls to external tools. Which strategy should you recommend to reduce latency?

A.Increase the max token limit
B.Enable parallel tool execution
C.Add more tools to distribute the load
D.Reduce the thread history length
AnswerB

Parallel tool execution dispatches independent external tool calls concurrently rather than sequentially, so total latency reflects the slowest call instead of the sum of all calls. This directly addresses the stem's constraint of excessive sequential tool invocations exceeding acceptable response times.

Why this answer

Enabling parallel tool execution allows the agent to invoke multiple external tools simultaneously rather than sequentially, directly reducing the total latency caused by serial tool calls. This is a core optimization in agentic frameworks like Semantic Kernel or AutoGen, where tool calls are independent and can be dispatched concurrently.

Exam trap

The trap here is that candidates confuse throughput improvements (like adding tools or increasing token limits) with latency reduction, when the real bottleneck is the sequential dependency of tool calls.

How to eliminate wrong answers

Option A is wrong because increasing the max token limit does not affect the number or sequence of tool calls; it only allows longer responses, which can actually increase latency. Option C is wrong because adding more tools increases the workload and potential sequential calls, worsening latency rather than distributing load in a meaningful way. Option D is wrong because reducing thread history length may free context window space but does not change the sequential execution pattern of tool calls, so it has no direct impact on latency from tool orchestration.

18
Multi-Selecthard

You are designing an agentic solution using Azure AI Agent Service. The agent needs to perform actions on behalf of users, such as sending emails and updating databases. The solution must use managed identities for authentication to Azure resources. Which TWO configurations are required?

Select 2 answers
A.Store connection strings in Azure Key Vault and reference them in the agent's configuration
B.Create a service principal in Microsoft Entra ID and assign RBAC roles to the agent's resource
C.Use DefaultAzureCredential in the agent's code to authenticate to Azure services
D.Configure the agent to use an API key for each external service
E.Assign a system-assigned managed identity to the Azure resource hosting the agent
AnswersC, E

DefaultAzureCredential chains managed identity credentials automatically, so the agent authenticates to Azure resources without stored secrets — satisfying the stem's managed identity requirement. In Azure AI Agent Service, this credential resolves the assigned identity at runtime, enabling email and database actions on behalf of users without embedding connection strings or service principal keys.

Why this answer

Option E is correct because a system-assigned managed identity must first be enabled on the Azure resource hosting the agent (for example, the Azure AI Foundry/Azure AI Services resource or the compute running the agent code) so that Microsoft Entra ID can issue tokens for that resource without storing secrets. Option C is correct because DefaultAzureCredential is the recommended credential chain in the Azure Identity SDK; it automatically picks up the managed identity (via ManagedIdentityCredential/EnvironmentCredential) when running in Azure, allowing the agent code to authenticate to Azure services such as Azure SQL, Storage, or Microsoft Graph without embedding credentials. Option A is not required and contradicts the managed-identity requirement, since connection strings/secrets in Key Vault are a secret-based pattern rather than identity-based authentication.

Option B is not required because managed identities are service principals managed by the platform; you do not manually create a service principal in Microsoft Entra ID, and RBAC role assignments are made to the managed identity's principal, not to a separately created app registration. Option D is incorrect because API keys are static secrets and the scenario explicitly mandates managed identities for authentication to Azure resources.

Exam trap

The trap here is that candidates often confuse managed identities with service principals or API keys, thinking they need to create a separate service principal or store connection strings, when in fact managed identities are automatically managed service principals that require only RBAC role assignments and the use of DefaultAzureCredential (or ManagedIdentityCredential) in code.

19
MCQmedium

You are configuring an agent in Azure AI Foundry Agent Service to generate responses based on a large set of internal documents. The documents are stored in an Azure Storage account. You need to ensure the agent can retrieve relevant information from these documents to answer user queries. What should you do?

A.Create an Azure AI Search index that contains the documents and connect it to the agent as a knowledge source.
B.Upload the documents to the agent's file storage and enable the file search tool.
C.Use the Azure AI Foundry SDK to embed the documents into the agent's prompt by concatenating their contents.
D.Configure the agent to use a custom tool that calls the Azure Storage REST API to fetch documents on demand.
AnswerA

Azure AI Search is designed to index and query large volumes of documents. By creating an index and connecting it to the agent, you enable the agent to retrieve relevant information based on user queries. This approach scales well and provides advanced search capabilities like semantic ranking.

Why this answer

For large document sets, Azure AI Search provides scalable indexing and retrieval. By creating an index and connecting it as a knowledge source, the agent can query the index and retrieve relevant passages. This is the recommended approach for grounding agent responses in extensive internal documents.

Exam trap

The trap here is assuming that file upload or direct concatenation can handle large document sets, but they are limited by size and token constraints.

20
MCQeasy

You run the PowerShell script shown to audit your Azure AI Agent Service agents. The script outputs that several agents have no tools configured. What is the impact on those agents?

A.The agents cannot be deployed until tools are added
B.The agents can only respond to queries using the model's built-in knowledge, without ability to perform actions
C.The agents cannot start conversations with users
D.The agents will use default tools provided by Azure
AnswerB

Without tools configured, an agent has no function-calling or action capabilities, so it is limited to generating responses from the underlying model's built-in knowledge. It cannot retrieve external data or perform actions on the user's behalf.

Why this answer

Azure AI Agent Service agents without tools configured rely solely on the model's built-in knowledge (e.g., GPT-4o's training data) to generate responses. They cannot execute external actions like calling APIs, querying databases, or running code, which are enabled only when tools (e.g., code interpreter, function calling, or Azure Functions) are explicitly attached. This is by design: tools extend the agent's capabilities beyond the model's static knowledge.

Exam trap

The trap here is that candidates assume agents must have tools to be functional or deployed, but Azure AI Agent Service allows tool-less agents that operate as pure language models, and the exam tests understanding that tools are optional for basic Q&A but required for action-oriented tasks.

How to eliminate wrong answers

Option A is wrong because agents without tools can still be deployed and will function, but with limited capabilities—they simply lack action execution. Option C is wrong because agents can start conversations with users regardless of tool configuration; conversation initiation is controlled by the agent's trigger (e.g., user message or event), not by tool presence. Option D is wrong because Azure does not assign default tools to agents; tools must be explicitly defined in the agent's configuration or via the `tools` parameter in the Azure AI Agent Service SDK.

21
MCQhard

You are troubleshooting a Microsoft Copilot Studio agent that calls a custom connector action to retrieve shipment data. The action works in the test canvas, but when the agent is published to a channel, the action returns an authorization error for some users. The connector uses OAuth. You need to resolve the issue. What should you do?

A.Increase the connector's timeout setting so authorization calls have more time to complete.
B.Republish the agent to the channel so the connector definition refreshes for all users.
C.Verify that each user has consented to the OAuth connection and has permission in the source system, then have them sign in to the connection.
D.Change the connector authentication to API key and share the key with all users.
AnswerC

OAuth connections are user-scoped, so each user must consent and hold the necessary permissions in the source system. Users who fail are likely missing consent or lack rights in the shipment system. Having them authenticate and confirming their permissions resolves the authorization errors while preserving per-user security and auditing.

Why this answer

OAuth-protected connectors require each user to consent and to have appropriate rights in the target system. The test canvas often runs under the maker's credentials, which masks per-user authorization problems. Confirming consent and permissions, and having affected users sign in to the connection, fixes the errors without weakening the security model.

Exam trap

The trap here is assuming the connector itself is broken because it works in the test canvas, when the canvas often uses the maker's credentials rather than each end user's.

22
MCQeasy

You are building an agent with the Azure AI Agents SDK that must support multi-turn conversations for a help desk scenario. The agent should remember details a user provided earlier in the same conversation, such as their device model. You need to manage conversation state. What should you do?

A.Include the entire conversation history in every request and omit thread creation.
B.Enable a file search tool so the agent can look up the device model from uploaded files.
C.Store the device model in the agent's instructions each time the user mentions it.
D.Create a thread for the conversation and add messages to it as the user and agent exchange turns.
AnswerD

Threads persist the message history for a conversation, so the agent can reference earlier user details such as a device model when answering later questions. Each new user message is added to the same thread, and the agent's responses are stored there as well. This is the standard mechanism for maintaining multi-turn context in the Azure AI Agents SDK.

Why this answer

Threads are the Azure AI Agents SDK mechanism for multi-turn state. By creating a thread and adding each message to it, the agent has access to prior turns and can recall details like a device model. The other approaches either bypass platform state management, misuse instructions, or apply a retrieval tool to a problem that requires conversation history.

Exam trap

The trap here is confusing document retrieval with conversational memory, when only thread-managed history preserves earlier user statements.

23
MCQeasy

You are using Microsoft Copilot Studio to create an agent that helps users reset their passwords. The agent should first verify the user's identity using multi-factor authentication (MFA) before proceeding. Which feature should you configure?

A.Add a variable to store the user's identity status
B.Configure Authentication settings to require Microsoft Entra ID authentication with MFA policy
C.Add a Power Automate flow that calls Microsoft Entra ID MFA
D.Use a 'Sign in' topic trigger from the customer channel
AnswerB

Configuring Authentication to require Microsoft Entra ID with an MFA policy forces identity verification before the agent proceeds, satisfying the pre-reset verification requirement. This leverages Entra ID's native conditional access rather than building custom verification logic.

Why this answer

Microsoft Copilot Studio allows you to configure Authentication settings directly on the agent, and by selecting 'Microsoft Entra ID' as the authentication provider, you can enforce an MFA policy that is already configured in your Entra ID tenant. This ensures that before the agent processes any password reset logic, the user must complete MFA, satisfying the identity verification requirement without custom code or flows.

Exam trap

The trap here is that candidates often think they need to build custom MFA logic (e.g., via Power Automate or variables) when the platform already provides a native, declarative way to enforce MFA through Authentication settings, leading them to over-engineer the solution.

How to eliminate wrong answers

Option A is wrong because simply adding a variable to store the user's identity status does not enforce MFA; it only tracks a state that must be set by some other mechanism, leaving the actual verification unaddressed. Option C is wrong because while a Power Automate flow could call Microsoft Entra ID MFA, this approach is unnecessarily complex and indirect—Copilot Studio's built-in Authentication settings natively support Entra ID with MFA policy enforcement, making a separate flow redundant and less reliable. Option D is wrong because a 'Sign in' topic trigger from the customer channel only initiates a sign-in prompt but does not guarantee that MFA is enforced; the actual MFA requirement must be configured in the Authentication settings of the agent, not just in a topic trigger.

24
MCQeasy

You are deploying an agentic solution using Azure AI Agent Service. The agent needs to be invoked from a custom application using REST API calls. Which endpoint should you use to send a message to the agent?

A.POST /threads/{thread_id}/runs
B.POST /threads
C.POST /threads/{thread_id}/messages
D.GET /agents
AnswerC

Messages are added to an existing conversation thread, so POST /threads/{thread_id}/messages is the correct REST operation for sending user input to the agent. Thread creation happens first; the run is then started separately to process that message.

Why this answer

To send a message to an existing conversation thread in Azure AI Agent Service, you must use the POST /threads/{thread_id}/messages endpoint. This adds the user's message to the specified thread, which the agent can then process in a subsequent run. The REST API requires the thread to already exist, and messages are posted directly to that thread's resource.

Exam trap

The trap here is that candidates confuse the endpoint for sending a message with the endpoint for starting a run, mistakenly thinking that POST /threads/{thread_id}/runs both sends the message and invokes the agent, when in fact messages must be added separately before a run.

How to eliminate wrong answers

Option A is wrong because POST /threads/{thread_id}/runs is used to start a run (i.e., invoke the agent to process messages) on an existing thread, not to send a new message. Option B is wrong because POST /threads creates a new thread, but does not send a message; it only initializes the conversation container. Option D is wrong because GET /agents retrieves a list of available agents, not for sending messages.

25
MCQhard

A logistics company runs an Azure AI Agent Service agent that must call an internal REST API to book delivery slots. The API requires a per-tenant OAuth token that must never be visible in run logs or agent definitions. The agent is invoked by many tenants through your own web application. Which approach should you use to give the agent access to the API securely?

A.Define the API as an OpenAPI tool with a project connection that holds the credential, and pass the tenant identity as a non-secret parameter.
B.Store the tenant token in the agent's instructions and let the model include it in the function call arguments.
C.Have the agent emit the tenant ID, then let your web application call the booking API directly and append the response as a user message.
D.Create a function tool that returns the tenant token to the model so the model can place it in the next function call.
AnswerA

OpenAPI tools let the service make the HTTP call on the agent's behalf, and the credential lives in the project connection rather than in messages or agent configuration. Passing only a tenant identifier as a tool parameter keeps the secret out of logs while still letting each invocation resolve the correct authorization behind the connection.

Why this answer

Using an OpenAPI tool with a project connection keeps credentials server-side while still letting the agent decide when to invoke the booking API. The tenant identifier travels as an ordinary parameter, so logs remain free of secrets and per-tenant authorization is resolved by the connection at call time rather than by the model.

Exam trap

The trap here is treating function tools as the only way to call external APIs, when OpenAPI tools with managed connections are designed precisely to keep credentials out of model-visible data.

26
Multi-Selectmedium

You are building an agentic solution using Microsoft Semantic Kernel. The agent uses a planner to orchestrate multiple functions. You want to improve the planner's ability to handle complex user requests that involve multiple steps. Which THREE strategies should you implement?

Select 3 answers
A.Limit the number of available functions to reduce planning overhead
B.Enable the planner to ask the user for clarification when the request is ambiguous
C.Create composite functions that encapsulate common multi-step sub-tasks
D.Use a simple, generic prompt to avoid overfitting
E.Provide few-shot examples of multi-step workflows in the planner prompt
AnswersB, C, E

Clarification prompting lets the planner resolve ambiguous intent before committing to a function sequence, preventing mis-ordered or missing steps in multi-step orchestration. This directly satisfies the stem's goal of handling complex, multi-step requests, since ambiguity is a primary cause of planner failure in Semantic Kernel pipelines.

Why this answer

Option B is correct because allowing the planner to ask the user for clarification when a request is ambiguous prevents it from guessing at missing parameters or intent, which is essential for correctly decomposing complex multi-step requests. Option C is correct because composite functions encapsulate common multi-step sub-tasks into a single callable unit, reducing the planner's reasoning burden and making orchestration of complex workflows more reliable. Option E is correct because few-shot examples of multi-step workflows in the planner prompt demonstrate the expected decomposition and sequencing pattern, improving the planner's ability to generate correct multi-step plans.

Option A is not appropriate because arbitrarily limiting available functions removes capabilities the agent needs for complex requests rather than improving planning quality. Option D is not appropriate because a simple, generic prompt provides no guidance on multi-step decomposition and would degrade, not improve, planning performance for complex tasks.

Exam trap

Microsoft often tests the misconception that reducing function count (Option A) or using simpler prompts (Option D) improves planning, when in fact these strategies limit the planner's expressiveness and ability to handle complex, multi-step requests.

27
Multi-Selectmedium

You are implementing an agent with Azure AI Agent Service that must run a multi-step task: retrieve a customer record, then create a support ticket containing that record. You want the agent to complete both steps in a single run and to be able to report intermediate progress. Which two capabilities should you rely on? (Choose two.)

Select 2 answers
A.File search over the support policy documents, so the agent can justify the ticket priority.
B.Tool calling, so the model can request the retrieval and ticket-creation functions during the run.
C.Run steps, so the application can observe each tool call and its result as the run progresses.
D.Vector embeddings of the ticket schema, so the model can match the customer record to the correct ticket fields.
E.A separate thread per step, so each tool call is isolated from the others.
AnswersB, C

Tool calling is how an agent takes actions in Azure AI Agent Service. The model emits a tool call, the service or your code executes it, and the result returns to the model so it can decide the next step. Without tool calling, the agent could only produce text and could not retrieve the customer record or create the ticket.

Why this answer

Tool calling lets the model request the customer lookup and the ticket creation as part of one run, while run steps give the application visibility into each invocation and result. Together they enable a single multi-step run with observable progress, which is exactly what the scenario requires.

Exam trap

The trap here is confusing retrieval-augmented features such as embeddings or file search with the action-execution and observability features that actually drive a multi-step agent run.

28
MCQhard

Your Azure AI Agent Service agent occasionally calls a 'createOrder' tool with plausible but incorrect item codes. You must ensure that the order is created only when the item code exists in the product database, and that invalid calls are rejected before any order is written. Which approach should you take?

A.Validate the item code inside the function tool implementation and return an error result to the agent when the code is unknown.
B.Add the full product database to the agent's instructions so the model can check codes itself before calling the tool.
C.Enable content filtering on the model deployment and add a blocklist entry for malformed item codes.
D.Increase the model temperature to zero and add a system message telling the model to verify item codes before calling the tool.
AnswerA

Executing validation in the tool implementation puts a deterministic check between the model's proposal and the side effect. If the code is unknown, the tool refuses to create the order and returns an error the model can reason about, so no invalid order is written regardless of what the model suggested. This enforces the constraint where it cannot be bypassed.

Why this answer

Validation belongs in the tool implementation, where it runs deterministically before any write occurs. The model may still propose a bad code, but the tool rejects it and returns an error the agent can act on, guaranteeing that only codes present in the product database result in orders.

Exam trap

The trap here is believing that prompt instructions or lower temperature can enforce a business rule, when only code executing at the side-effect boundary can guarantee it.

29
MCQhard

You are implementing an agentic solution using Azure AI Agent Service with multiple agents that need to collaborate. Each agent has access to different knowledge bases. You want to ensure that the agents can share context and hand off tasks to each other seamlessly. Which architecture should you use?

A.Create a single monolithic agent that includes all knowledge bases
B.Deploy each agent independently and configure them to call each other via HTTP
C.Use a supervisor agent that delegates to specialized agents, with a shared context store in Azure Cosmos DB
D.Chain the agents sequentially, passing output from one to the next
AnswerC

A supervisor agent orchestrates delegation to specialised agents while a shared Cosmos DB context store lets each agent read and write common state, enabling seamless handoffs. Point-to-point messaging between agents would fragment context and complicate routing.

Why this answer

The supervisor agent pattern with a shared context store (e.g., Azure Cosmos DB) enables multiple agents to maintain a consistent conversation state and hand off tasks seamlessly. The supervisor orchestrates specialized agents, each with its own knowledge base, while the shared store ensures context is preserved across agent boundaries, which is essential for collaborative agentic workflows in Azure AI Agent Service.

Exam trap

The trap here is that candidates often assume sequential chaining (Option D) is sufficient for handoffs, but they overlook the need for a shared context store to maintain state across agent boundaries, which is a core requirement for seamless collaboration in agentic solutions.

How to eliminate wrong answers

Option A is wrong because a single monolithic agent that includes all knowledge bases violates the principle of separation of concerns and does not allow specialized agents to collaborate or share context dynamically; it also creates a single point of failure and scalability bottleneck. Option B is wrong because deploying each agent independently and configuring them to call each other via HTTP introduces tight coupling, latency, and no built-in mechanism for shared context or state management, leading to inconsistent handoffs. Option D is wrong because chaining agents sequentially passes output from one to the next without a shared context store, which prevents agents from accessing the full conversation history or collaborating in a non-linear fashion, breaking seamless handoff.

30
MCQeasy

You are building an agentic solution using Azure AI Agent Service. The agent needs to send an email via Microsoft Graph API. Which authentication method should you use for the action?

A.Client Certificate
B.API Key
C.OAuth 2.0
D.Basic Authentication
AnswerC

OAuth 2.0 provides delegated, scoped access tokens that Microsoft Graph requires for sending mail on a user's behalf. It satisfies the authentication constraint for Graph API actions, unlike API keys or connection strings, which Graph does not accept.

Why this answer

Microsoft Graph API requires OAuth 2.0 for authentication because it uses delegated or application permissions to access user data securely. Azure AI Agent Service can use OAuth 2.0 with a managed identity or service principal to obtain an access token for the Graph API, ensuring proper authorization and compliance with Microsoft's security model.

Exam trap

Azure certification exams often test the misconception that API keys or basic authentication can be used with modern REST APIs like Microsoft Graph, but the trap here is that candidates overlook the mandatory OAuth 2.0 requirement for Microsoft Graph API and the deprecation of basic authentication in Azure services.

How to eliminate wrong answers

Option A is wrong because client certificates are used for authentication in scenarios like mutual TLS or Azure AD app registration with certificate-based credentials, but Microsoft Graph API does not accept client certificates directly for token acquisition; OAuth 2.0 is still required to exchange the certificate for an access token. Option B is wrong because API keys are not supported by Microsoft Graph API; it relies on OAuth 2.0 tokens (Bearer tokens) for authorization, not static keys. Option D is wrong because Basic Authentication sends credentials in plaintext (Base64-encoded) and is deprecated for Microsoft Graph API; it lacks the token-based security and scoped permissions that OAuth 2.0 provides.

31
MCQeasy

You are designing an agentic solution that uses Microsoft Copilot Studio and Azure AI Search. The agent needs to answer questions based on confidential documents. Which security measure should you implement to ensure the agent only accesses documents the user has permission to read?

A.Disable public network access on the Azure AI Search service.
B.Implement document-level security using security filters in the search index.
C.Use a managed identity for the agent to access the search index.
D.Require multi-factor authentication for all users.
AnswerB

Security filters in the Azure AI Search index apply the user's identity at query time, trimming results to documents that identity may read. This enforces document-level permissions, satisfying the constraint that the agent must only surface confidential documents the requesting user is authorised to access.

Why this answer

Azure AI Search supports document-level security through security filters, which allow you to restrict search results based on the user's identity. By storing security identifiers (e.g., group memberships or user IDs) as a field in the index and applying an OData filter at query time, the agent can ensure users only see documents they are permitted to read. This is the standard approach for implementing row-level security in Azure AI Search.

Exam trap

The trap here is confusing authentication (verifying who the user is) with authorization (determining what the user can access), leading candidates to select network controls or MFA instead of the document-level security filter mechanism.

How to eliminate wrong answers

Option A is wrong because disabling public network access on the Azure AI Search service controls network-level access to the service itself, not document-level permissions within the index; it does not differentiate between users or documents. Option C is wrong because using a managed identity for the agent authenticates the agent to the search service, but does not enforce per-document access control; the agent would have full access to all indexed documents regardless of the end user's permissions. Option D is wrong because requiring multi-factor authentication for all users strengthens authentication but does not restrict which documents a user can see after they are authenticated; it addresses identity verification, not authorization at the document level.

Ready to test yourself?

Try a timed practice session using only Implement an agentic solution questions.