Courseiva

Why Does Azure Language Service Return 403 Forbidden?

Exhibit

Refer to the exhibit.

{
  "apiVersion": "2024-01-01",
  "type": "Microsoft.CognitiveServices/accounts",
  "name": "myAIServices",
  "location": "eastus",
  "sku": {
    "name": "S0"
  },
  "properties": {
    "apiProperties": {
      "statisticsEnabled": true
    },
    "networkAcls": {
      "defaultAction": "Deny",
      "ipRules": []
    }
  }
}

You deploy an Azure AI Services resource using the ARM template shown in the exhibit. You need to test the Language service API from your local machine. What should you do first?

⚠ Common exam trap

Many exam-takers assume changing `defaultAction` to `Allow` is the simplest fix, but the question tests understanding that the resource is already deployed and the firewall is blocking traffic—so the correct first step is to explicitly permit your specific IP, not to open the resource to the entire internet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add your public IP address to the ipRules array in the networkAcls

The ARM template in the exhibit sets `defaultAction` to `Deny`, which blocks all traffic not explicitly allowed by the `ipRules` array. To test the Language service API from your local machine, you must add your public IP address to the `ipRules` array so that the resource's network firewall permits inbound requests from your IP. Without this step, all API calls from your local machine will be rejected with a 403 Forbidden error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a managed identity for the resource

    Why it's wrong here

    A managed identity authenticates the resource to other Azure services; it does not authorise a local machine's API call, which uses a key or Microsoft Entra ID token. The network ACL must permit the local public IP. Managed identity suits keyless access from Azure compute to Azure resources.

  • ✓

    Add your public IP address to the ipRules array in the networkAcls

    Why this is correct

    The networkAcls ipRules array is the ARM property controlling which public addresses may reach the endpoint when default action is Deny. Adding your public IP permits local API calls without redeploying or disabling the firewall, satisfying the test-from-local-machine constraint.

  • ✗

    Change the defaultAction to Allow

    Why it's wrong here

    Changing defaultAction to Allow opens the network ACL to every source, not just the local machine, and the template's key authentication setting is what blocks the call. Adding the local public IP to the IP rules permits testing while retaining the deny default. Allow suits publicly reachable endpoints.

  • ✗

    Use Azure CLI to enable the resource

    Why it's wrong here

    Enabling the resource is unnecessary because an Azure AI Services resource is already provisioned and enabled by the ARM deployment; the blocker is retrieving its endpoint and key for local calls. Azure CLI is genuinely useful for scripting deployments or querying keys, but it does not itself authorise API requests.

About these practice questions

Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.