Courseiva

CCNA Plan Manage Azure Ai Questions

75 of 149 questions · Page 1/2 · Plan Manage Azure Ai topic · Answers revealed

1
MCQeasy

You need to restrict access to an Azure AI Language resource so that only a specific virtual network can call the endpoint. Which configuration should you use?

A.Rotate the shared access keys
B.Enable a service endpoint or private endpoint for the resource
C.Assign a managed identity to the resource
D.Configure an IP firewall rule with the VNet's public IP range
AnswerB

A service endpoint or private endpoint binds the Azure AI Language resource to a specific virtual network, so only traffic from that network reaches the endpoint. This directly enforces the network restriction the scenario requires.

Why this answer

Azure AI Language resources can be isolated to a specific virtual network by enabling either a service endpoint (via the Microsoft.CognitiveServices service tag) or a private endpoint (using Azure Private Link). This configuration ensures that only traffic originating from the designated VNet can reach the resource's endpoint, effectively blocking all public internet access. Service endpoints provide a direct, optimized route from the VNet to the resource, while private endpoints assign a private IP from the VNet to the resource, making it accessible only within the VNet.

Exam trap

The trap here is that candidates often confuse network-level access controls (service/private endpoints) with authentication mechanisms (keys, managed identities) or IP-based firewalls, mistakenly believing that rotating keys or using managed identities can restrict network access, or that a VNet's public IP range is the same as the VNet's internal address space.

How to eliminate wrong answers

Option A is wrong because rotating shared access keys changes the authentication tokens but does not restrict network-level access; any client with the new keys can still call the endpoint from anywhere on the internet. Option C is wrong because assigning a managed identity enables the resource to authenticate to other Azure services (e.g., Azure Key Vault) without storing credentials, but it does not control which networks can reach the resource's endpoint. Option D is wrong because IP firewall rules with the VNet's public IP range are ineffective for restricting access to a specific virtual network, as VNet traffic typically uses private IPs (RFC 1918) and the public IP of a VNet's NAT gateway or load balancer is not the same as the VNet's internal address space; moreover, IP firewall rules cannot distinguish traffic originating from within the VNet versus other sources using the same public IP range.

2
MCQmedium

You are designing an AI solution that uses Azure AI Document Intelligence to extract data from invoices. The solution must handle a high volume of documents with varying layouts. Which approach should you use?

A.Use a custom template model with fixed field positions
B.Train a custom neural model with labeled invoices
C.Use the prebuilt invoice model
D.Extract text using OCR and then use regex parsing
AnswerB

A custom neural model handles varying invoice layouts because it learns layout and field patterns from labelled examples rather than relying on fixed templates. This satisfies the high-volume, layout-variance constraint, whereas prebuilt models assume consistent formats and would degrade across suppliers.

Why this answer

Custom neural models in Azure AI Document Intelligence are designed to handle high volumes of documents with varying layouts. Unlike fixed template models, neural models learn from labeled examples and generalize across different invoice structures, making them ideal for diverse, high-volume scenarios.

Exam trap

The trap here is that candidates often assume the prebuilt invoice model (Option C) is sufficient for all invoice scenarios, but it only works for standard layouts and fails when invoices have custom fields or non-standard structures.

How to eliminate wrong answers

Option A is wrong because custom template models rely on fixed field positions and are brittle when layouts vary; they fail if the invoice format changes even slightly. Option C is wrong because the prebuilt invoice model is limited to standard invoice layouts and cannot adapt to custom or highly variable formats, leading to poor extraction accuracy. Option D is wrong because OCR with regex parsing is a brittle, rule-based approach that cannot handle the semantic understanding required for diverse invoice layouts and fails when fields are not in predictable positions or formats.

3
MCQhard

You are managing an Azure AI solution that uses Azure OpenAI. You need to ensure that the solution can only be accessed by applications hosted in a specific Azure Virtual Network. The solution must not be accessible from the public internet. What should you configure?

A.Azure OpenAI managed identity with role-based access control (RBAC).
B.Azure OpenAI network security group (NSG) on the resource's subnet.
C.Azure OpenAI firewall with IP restrictions for the virtual network's NAT gateway.
D.Azure OpenAI private endpoint and disable public network access.
AnswerD

A private endpoint creates a private IP address for the Azure OpenAI resource within your virtual network, and disabling public network access ensures that the resource is not reachable from the internet. This combination restricts access to only resources within the specified virtual network or connected networks, meeting the requirement for private, non-public access.

Why this answer

To restrict Azure OpenAI access to only a specific virtual network and prevent public internet access, you should configure a private endpoint for the Azure OpenAI resource and disable public network access. This ensures that the resource is only accessible via private IP addresses within the virtual network, and all public access is blocked, satisfying the strict isolation requirement.

Exam trap

The trap here is confusing authentication and authorization controls like managed identity or RBAC with network isolation, or assuming that IP restrictions based on a NAT gateway provide the same level of private access as a private endpoint with public access disabled.

4
MCQeasy

You are deploying an Azure AI solution that uses multiple Cognitive Services resources. You need to ensure that the solution can be deployed to multiple regions and that each region has its own endpoint and key. What should you use to manage the deployment?

A.A single Cognitive Services resource with multiple endpoints configured in the application code.
B.Azure Resource Manager (ARM) templates with parameters for region-specific values.
C.Azure Policy definitions that enforce the creation of Cognitive Services resources in specific regions.
D.Azure CLI scripts that create resources in each region sequentially.
AnswerB

ARM templates allow you to define parameters that can be supplied at deployment time, enabling the same template to be used for multiple regions. You can parameterize the region, resource names, and SKUs. This provides a repeatable, consistent deployment method and supports multi-region scenarios with region-specific endpoints and keys.

Why this answer

ARM templates are the recommended infrastructure-as-code tool for deploying Azure resources consistently across multiple regions. By using parameters, you can customize region-specific settings such as location, endpoint names, and SKUs. This approach ensures repeatability and simplifies management of multi-region deployments.

Exam trap

The trap here is confusing Azure Policy (which enforces rules) with ARM templates (which deploy resources), or assuming a single resource can span regions.

5
MCQhard

You see the exhibit representing an Azure Bot resource configuration. The bot is not responding to user messages. What should you verify first?

A.Check that the endpoint URL is correct and the web app is running
B.Ensure that LUIS app IDs are provided
C.Verify that the Application Insights key is valid
D.Confirm that the msaAppId is a valid GUID
AnswerA

A bot that receives messages but never replies usually has a broken messaging endpoint. Verifying the endpoint URL and confirming the hosting web app is running tests the actual message delivery path before investigating channels, credentials, or configuration.

Why this answer

The most common reason a bot fails to respond to user messages is that the endpoint URL configured in the Azure Bot resource does not match the actual URL of the running web app, or the web app itself is stopped or unresponsive. Without a correct and reachable endpoint, the Bot Framework Service cannot forward messages to the bot's message handler, causing a complete communication breakdown.

Exam trap

The trap here is that candidates often jump to authentication or AI service configuration issues, but the most immediate and common cause of a non-responsive bot is a simple connectivity or endpoint misconfiguration.

How to eliminate wrong answers

Option B is wrong because LUIS app IDs are only required if the bot uses Language Understanding for intent detection; they are not necessary for basic message handling. Option C is wrong because Application Insights is used for telemetry and monitoring, not for core message routing; an invalid key would not prevent the bot from responding. Option D is wrong because the msaAppId (Microsoft App ID) is used for authentication with the Bot Framework Service, but if it were invalid, the bot would typically fail to register or authenticate, not silently ignore messages; the endpoint and web app availability are more fundamental.

6
MCQmedium

You are a lead AI engineer for a global retail company. The company is building an AI-powered customer support chatbot using Microsoft Foundry. The chatbot must answer product questions, process returns, and escalate to human agents when needed. The solution uses Azure AI Language for intent recognition and Azure AI Bot Service for bot orchestration. During testing, the chatbot fails to understand customer queries about return policies. The intents 'ProductInquiry' and 'ReturnRequest' are defined, but the model often confuses them. You need to improve intent classification accuracy. The development team has already collected 500 sample utterances for each intent. You have a budget to collect additional data. What should you do?

A.Use Azure AI Translator to translate utterances into multiple languages
B.Collect additional utterances that are similar to the confusing ones and retrain
C.Increase the confidence threshold in the bot configuration
D.Create a new custom language project and retrain from scratch
AnswerB

Confusion between ProductInquiry and ReturnRequest stems from insufficient utterance coverage near the decision boundary. Adding utterances similar to the misclassified examples gives the model discriminative training signal on that boundary, improving classification accuracy more effectively than unrelated data.

Why this answer

Collecting additional utterances that are similar to the confusing ones directly addresses the ambiguity between the 'ProductInquiry' and 'ReturnRequest' intents. By providing more representative examples of edge cases where the intents overlap, the Azure AI Language model can better learn the subtle linguistic patterns that distinguish them, thereby improving classification accuracy without requiring a complete retraining from scratch.

Exam trap

The trap here is that candidates often assume increasing the confidence threshold (Option C) will fix misclassifications, but this only adjusts the prediction cutoff and does not improve the underlying model's ability to differentiate intents, which is a data quality issue, not a threshold tuning issue.

How to eliminate wrong answers

Option A is wrong because translating utterances into multiple languages does not resolve confusion between two intents in the same language; it only adds multilingual support, which is irrelevant to the core issue of intent ambiguity. Option C is wrong because increasing the confidence threshold would only reject more low-confidence predictions, not improve the model's ability to distinguish between similar intents; it could actually increase false negatives by requiring higher confidence for correct classifications. Option D is wrong because creating a new custom language project and retraining from scratch is unnecessary and wasteful; the existing project already has 500 utterances per intent, and the problem is specifically about confusing utterances, not a fundamental flaw in the project setup.

7
MCQhard

Your team is developing a chatbot using Azure AI Bot Service with Language Understanding (LUIS). You need to improve intent recognition for user queries that contain typos. What should you recommend?

A.Add synonym lists for common misspellings
B.Use Azure Cognitive Search to correct typos
C.Enable Bing Spell Check in the LUIS app settings
D.Train the model with many examples containing typos
AnswerC

Enabling Bing Spell Check in the LUIS app settings corrects typographical errors in incoming utterances before intent classification, directly satisfying the stem's requirement to improve recognition of queries containing typos. LUIS then evaluates the corrected text against its trained intents, raising confidence scores that misspellings would otherwise depress.

Why this answer

Enabling Bing Spell Check in the LUIS app settings allows the service to automatically correct typos in user utterances before they are processed for intent recognition. This built-in feature integrates directly with LUIS at the endpoint, correcting misspelled words to improve the accuracy of intent and entity extraction without requiring manual data augmentation or external services.

Exam trap

The trap here is that candidates often assume training with typos (Option D) is the best way to handle misspellings, but Microsoft explicitly recommends using Bing Spell Check as a separate preprocessing layer rather than bloating the training data with error-prone examples.

How to eliminate wrong answers

Option A is wrong because synonym lists in LUIS are used to map different words that have the same meaning (e.g., 'car' and 'automobile'), not to handle typos or misspellings; they do not correct character-level errors. Option B is wrong because Azure Cognitive Search is a search indexing and query service, not a spell-checking tool; it cannot be used to correct typos in real-time LUIS utterances. Option D is wrong because while training with many examples containing typos might help the model learn some patterns, it is inefficient and does not generalize well to unseen typos; LUIS's built-in Bing Spell Check is the recommended and more robust approach.

8
Multi-Selecthard

You are designing an Azure AI solution that uses an Azure AI services multi-service account. The solution must call the service from an Azure Kubernetes Service (AKS) cluster without embedding account keys in application code. You need to configure authentication and authorization so that the workload identity used by the pods can be granted access. (Choose two.)

Select 2 answers
A.Store the account key in an Azure Key Vault secret and reference it from the pod.
B.Assign the Cognitive Services User role to the managed identity.
C.Create a service principal with a client secret and mount the secret into the pod.
D.Configure the AKS cluster to use workload identity federation with Microsoft Entra ID.
E.Enable local authentication on the Azure AI services account.
AnswersB, D

Granting the Cognitive Services User role to the managed identity gives the workload the data-plane permissions needed to call the Azure AI services endpoints. This is the recommended way to authorize API calls without keys, because role assignments are evaluated by Azure RBAC and can be scoped to the specific Azure AI services resource. It directly supports the requirement to avoid embedding account keys in application code.

Why this answer

Keyless access from AKS pods requires two things: the cluster must federate the pod identity with Microsoft Entra ID, and that identity must be granted a role on the Azure AI services resource. Workload identity federation provides the token acquisition mechanism, while the Cognitive Services User role provides the authorization. Together they let the application call the service without storing or handling account keys.

Exam trap

The trap here is thinking that storing the key in Key Vault satisfies a no-keys-in-code requirement, when the application still has to retrieve and use that key.

9
MCQmedium

You are planning a new Azure AI solution that will use several Azure AI services, including Azure AI Vision and Azure AI Language. The solution must allow developers to authenticate by using their Microsoft Entra ID credentials without storing service keys in code. You need to configure the Azure AI services resource to support this authentication method. What should you do?

A.Enable local authentication on the Azure AI services resource and distribute the keys to developers.
B.Store the Azure AI services keys in Azure Key Vault and provide developers access to the vault.
C.Create a managed identity for the Azure AI services resource and assign it the Cognitive Services User role.
D.Configure the Azure AI services resource to disable local authentication and grant developers the Cognitive Services User role on the resource.
AnswerD

Disabling local authentication forces authentication through Microsoft Entra ID. Granting developers the Cognitive Services User role allows them to use their Entra ID credentials to obtain tokens for accessing the service. This achieves keyless authentication and adheres to the requirement.

Why this answer

To allow developers to authenticate with Microsoft Entra ID, you must disable key-based authentication on the Azure AI services resource and assign the appropriate role, such as Cognitive Services User, to the developers. This ensures that access is granted through Entra ID tokens rather than shared keys, aligning with security best practices.

Exam trap

The trap here is assuming that a managed identity assigned to the Azure AI services resource can be used by developers to authenticate, overlooking that managed identities are for resource-to-resource authentication, not user access.

10
MCQmedium

You are deploying an Azure AI Language resource that will process customer feedback. The resource must be accessible only from a specific Azure virtual network and must allow access from an on-premises network via a site-to-site VPN. You need to configure network security for the resource. What should you do?

A.Use Azure Private Link to create a private endpoint for the Azure AI Language resource and enable public access for on-premises clients.
B.Configure a private endpoint for the Azure AI Language resource and disable public access.
C.Enable public access and configure IP firewall rules to allow only the on-premises public IP address.
D.Configure a service endpoint for Azure AI Language on the virtual network subnet and enable public access for on-premises clients.
AnswerB

A private endpoint creates a private IP address for the Azure AI Language resource within your virtual network, enabling secure access from the VNet and on-premises via VPN. Disabling public access ensures no exposure to the internet. This meets the requirement for restricted access and integrates with your existing network infrastructure.

Why this answer

A private endpoint is the correct solution because it assigns a private IP address from your virtual network to the Azure AI Language resource, allowing secure access from both the VNet and on-premises via VPN. Disabling public access ensures the resource is not reachable from the internet. This configuration satisfies the network isolation requirements.

Exam trap

The trap here is confusing service endpoints with private endpoints; service endpoints do not provide private IP connectivity for on-premises clients and do not disable public access.

11
MCQhard

You are responsible for managing costs for multiple Azure AI services in your organization. You notice that provisioned throughput units (PTUs) for Azure OpenAI are not fully utilized. What is the most cost-effective action to optimize spending?

A.Configure auto-scaling to reduce PTUs during low usage
B.Move the resource to a different region with lower pricing
C.Stop the Azure OpenAI service when not in use
D.Reduce the number of provisioned PTUs or switch to pay-as-you-go
AnswerD

Underutilised provisioned throughput units incur cost regardless of consumption, so reducing the PTU count or reverting to pay-as-you-go token billing eliminates spend on idle capacity. This directly addresses the stem's unused-PTU constraint, matching cost to actual demand.

Why this answer

Provisioned throughput units (PTUs) represent a fixed capacity commitment. If PTUs are underutilized, the most cost-effective action is to reduce the number of PTUs or switch to the pay-as-you-go (PAYG) model, which charges only for tokens consumed. This directly aligns with cost optimization by eliminating the fixed cost of unused capacity.

Exam trap

The trap here is that candidates confuse PTUs with standard Azure auto-scaling concepts (like VM scale sets) and assume auto-scaling is available for PTUs, when in fact PTUs are a fixed-capacity model that requires manual adjustment or a switch to PAYG for cost optimization.

How to eliminate wrong answers

Option A is wrong because Azure OpenAI does not support auto-scaling for PTUs; PTUs are a fixed, pre-provisioned capacity model, and scaling must be done manually via quota adjustments. Option B is wrong because moving to a different region does not address underutilization of PTUs; regional pricing differences are typically minimal and do not solve the core issue of paying for unused capacity. Option C is wrong because stopping the Azure OpenAI service (e.g., via the Azure portal) is not a supported operation for the resource itself; you can only pause or delete the resource, which would lose all configurations and data, making it impractical for intermittent use.

12
MCQmedium

You see the exhibit from an Azure OpenAI chat completion request. The assistant is not calling the get_weather function when asked about the weather. What is the most likely reason?

A.The required parameter 'location' is missing from the user message
B.Function calling is not supported in the current Azure OpenAI version
C.The function definition is malformed
D.The function is defined in the system message but not in the 'tools' array
AnswerD

Function calling requires each function declared in the request's 'tools' array, which the model inspects to decide when to emit a tool call. Describing get_weather only in the system message leaves no callable tool, so the assistant answers in text instead of invoking it.

Why this answer

D is correct because in Azure OpenAI, functions must be defined in the 'tools' array of the chat completion request to be available for the model to call. Defining a function only in the system message does not register it as a callable tool; the model can see the description but cannot invoke it. Without the function in 'tools', the assistant will ignore the request to call get_weather.

Exam trap

The trap here is that candidates assume listing a function in the system message is sufficient for the model to call it, but Azure OpenAI requires the function definition to be explicitly included in the 'tools' parameter of the API request.

How to eliminate wrong answers

Option A is wrong because the user message does not need to contain the 'location' parameter; the model is expected to extract or prompt for it from the conversation context. Option B is wrong because function calling is fully supported in current Azure OpenAI versions (e.g., gpt-4, gpt-35-turbo with API version 2023-12-01-preview or later). Option C is wrong because a malformed function definition would typically cause an API error or validation failure, not a silent refusal to call the function.

13
MCQmedium

You are deploying an Azure AI Document Intelligence solution to process invoices. The solution must extract line-item details such as product code, quantity, and unit price. Which prebuilt model should you use?

A.prebuilt-receipt
B.prebuilt-invoice
C.prebuilt-idDocument
D.prebuilt-layout
AnswerB

The prebuilt-invoice model returns structured fields including line items, each with product code, quantity, unit price, and amount, satisfying the stem's line-item extraction requirement. Unlike the general document model, it applies invoice-specific training to locate and label these fields without custom training.

Why this answer

The prebuilt-invoice model is specifically designed to extract line-item details such as product code, quantity, and unit price from invoices. It uses deep learning models trained on thousands of invoice samples to identify and extract structured data, including tables and line items, making it the correct choice for this requirement.

Exam trap

The trap here is that candidates might choose prebuilt-layout thinking it can extract any table data, but it lacks the specialized field mapping and labeling that prebuilt-invoice provides for invoice-specific line items.

How to eliminate wrong answers

Option A is wrong because prebuilt-receipt is optimized for receipt documents, focusing on fields like merchant name, transaction date, and total amount, not the detailed line-item structure (product code, quantity, unit price) found in invoices. Option C is wrong because prebuilt-idDocument is designed to extract information from government-issued identification documents (e.g., driver's licenses, passports), such as ID number, name, and date of birth, and has no capability for invoice line-item extraction. Option D is wrong because prebuilt-layout extracts text, tables, and selection marks from documents without specialized field extraction for invoices; it returns raw table data but lacks the pre-trained model logic to identify and label specific invoice fields like product code or unit price.

14
MCQmedium

You need to analyze images to detect objects and read text from documents using a single Azure AI service. Which service should you use?

A.Azure AI Vision
B.Azure AI Document Intelligence (Form Recognizer)
C.Azure AI Custom Vision
D.Azure AI Language Service
AnswerA

Azure AI Vision bundles both capabilities: object detection and OCR via the Image Analysis and Read features. A single resource therefore satisfies the requirement to detect objects and read document text without provisioning separate services.

Why this answer

Azure AI Vision is the correct choice because it provides both image analysis (object detection) and optical character recognition (OCR) for reading text from documents within a single service. Its Read API and Analyze Image API cover both requirements without needing separate services.

Exam trap

The trap here is that candidates often confuse Azure AI Document Intelligence (Form Recognizer) as the only service for text extraction, overlooking that Azure AI Vision also provides OCR for general document text reading.

How to eliminate wrong answers

Option B is wrong because Azure AI Document Intelligence (Form Recognizer) is specialized for extracting structured data from forms and documents, not general object detection in images. Option C is wrong because Azure AI Custom Vision is designed for training custom image classification and object detection models, not for reading text from documents. Option D is wrong because Azure AI Language Service focuses on natural language processing tasks like sentiment analysis and key phrase extraction, not image analysis or OCR.

15
MCQeasy

You are planning to use Azure AI Content Safety to moderate user-generated content in a social media application. The solution must detect hate speech and self-harm content. Which Content Safety features should you enable?

A.Severity levels for all categories
B.Hate and self-harm content filters
C.Custom categories for hate speech and self-harm
D.Image moderation
AnswerB

Enabling the hate and self-harm content filters directly satisfies the stem's requirement to detect both categories. Azure AI Content Safety classifies text against these severity-based harm categories, so the moderation pipeline can flag or block the specified content types without additional custom models.

Why this answer

Azure AI Content Safety provides pre-built filters for specific harm categories, including hate speech and self-harm. Enabling the 'Hate and self-harm content filters' directly activates the detection models for these categories, meeting the requirement without needing custom categories or additional features.

Exam trap

The trap here is that candidates might think custom categories are needed for specific harm types like self-harm, but Azure AI Content Safety already includes these as built-in categories, so enabling the pre-built filters is the correct approach.

How to eliminate wrong answers

Option A is wrong because severity levels are a configuration setting within each category filter, not a feature to enable; they adjust sensitivity but don't activate detection for specific categories. Option C is wrong because custom categories are for defining new harm types not covered by built-in filters, but hate speech and self-harm are already supported as standard categories, so custom categories are unnecessary and add complexity. Option D is wrong because image moderation is a separate feature for analyzing visual content, but the question focuses on text-based hate speech and self-harm detection; enabling it alone wouldn't address the text requirement.

16
MCQhard

You are developing a bot using Microsoft Bot Framework and Azure AI Language. The bot must handle user intents that change mid-conversation. Which feature should you implement?

A.Prompt dialogs
B.Waterfall dialogs
C.Adaptive dialogs
D.QnA Maker knowledge base
AnswerC

Adaptive dialogs satisfy the mid-conversation intent change by dynamically evaluating language understanding results at each turn, allowing the dialog stack to be restructured or interrupted without restarting the conversation. Their event-driven, declarative model handles context switches that rigid waterfall dialogs cannot, directly meeting the stem's requirement.

Why this answer

Adaptive dialogs are designed for dynamic, event-driven conversations where user intents can change mid-conversation. They use a trigger-based model (e.g., onIntent, onTurn) that allows the bot to react to new intents at any point, unlike linear dialog models. This makes them ideal for handling mid-conversation intent shifts without requiring predefined dialog flows.

Exam trap

The trap here is that candidates often confuse waterfall dialogs (which are sequential and rigid) with adaptive dialogs (which are event-driven and flexible), assuming any dialog can handle mid-conversation changes, but only adaptive dialogs support dynamic interruption and re-routing.

How to eliminate wrong answers

Option A is wrong because prompt dialogs are simple, reusable components for collecting a single piece of input (e.g., text, number) and do not handle intent changes mid-conversation. Option B is wrong because waterfall dialogs follow a fixed, sequential step-by-step flow and cannot dynamically redirect to a different intent once started; they are designed for linear, predictable interactions. Option D is wrong because QnA Maker knowledge base is a question-answering service that matches user queries to predefined Q&A pairs; it does not manage conversational state or handle intent routing.

17
MCQmedium

Refer to the exhibit. You are reviewing a Bicep template for deploying an Azure AI Language resource. After deployment, you need to ensure that the resource uses a private endpoint to block public access. Which additional resource should you include in the template?

A.A service endpoint for Microsoft.CognitiveServices
B.A virtual network peering connection
C.A virtual network gateway
D.A Private Endpoint resource linked to the Cognitive Services account
AnswerD

A Private Endpoint resource creates a private IP address within your virtual network and connects it to the Cognitive Services account via a private link, removing public exposure. This satisfies the requirement to block public access after deployment.

Why this answer

A Private Endpoint resource, when linked to the Cognitive Services account via the `privateLinkServiceId` property, assigns a private IP address from a virtual network to the Azure AI Language resource. This blocks all public access by default when the resource's `publicNetworkAccess` property is set to 'Disabled', ensuring traffic only flows over the Microsoft backbone network through Azure Private Link.

Exam trap

The trap here is that candidates confuse service endpoints (which only filter source traffic but leave the public endpoint active) with private endpoints (which completely remove public accessibility), leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because a service endpoint for Microsoft.CognitiveServices does not block public access; it only restricts source traffic to a specific virtual network subnet while still allowing public endpoints to be reachable from the internet. Option B is wrong because virtual network peering connects two virtual networks but does not provide a private IP address or block public access to an Azure AI resource. Option C is wrong because a virtual network gateway is used for site-to-site VPN or ExpressRoute connections, not for creating a private endpoint to an Azure PaaS service.

18
MCQeasy

You are deploying an Azure AI solution that uses multiple Azure AI services. You need to monitor the solution and receive alerts when the service quota for transactions per second (TPS) is exceeded. What should you use?

A.Azure Service Health
B.Azure Advisor
C.Azure Cost Management
D.Azure Monitor metrics and alerts
AnswerD

Azure Monitor collects metrics from Azure AI services, including transaction counts and throttling events. You can create alert rules based on metrics such as TotalCalls or Throttling to notify when TPS limits are approached or exceeded. This provides proactive monitoring and alerting.

Why this answer

Azure Monitor metrics and alerts allow you to track the transaction rate and configure alerts when thresholds are breached. By using metrics such as TotalCalls or Throttling, you can receive notifications when TPS limits are exceeded, enabling timely action.

Exam trap

The trap here is confusing service-level monitoring with resource-level monitoring; Azure Service Health reports on Azure-wide issues, not your resource's quota usage.

19
MCQhard

Your Azure AI Language custom entity recognition model incorrectly extracts 'Microsoft' as an organization when it refers to the company, but fails to extract 'Microsoft' as a product when it refers to the software. How should you improve the model?

A.Reduce the amount of training data to avoid confusion
B.Remove the 'Organization' entity type from the model
C.Add more training sentences without labeling the entity type
D.Label 'Microsoft' as both 'Organization' and 'Product' in different training sentences with appropriate context
AnswerD

Custom entity recognition learns from labelled context, so the same surface form can map to different entity types. Labelling 'Microsoft' as Organization in company-context sentences and Product in software-context sentences teaches the model to disambiguate by surrounding words.

Why this answer

Custom entity recognition models in Azure AI Language learn to distinguish entity types based on context. By labeling 'Microsoft' as 'Organization' in sentences where it refers to the company and as 'Product' in sentences where it refers to the software, you provide the model with the contextual clues needed to disambiguate the same token across different uses. This supervised learning approach directly addresses the model's failure to recognize the product entity.

Exam trap

The trap here is that candidates may think reducing data or removing entity types simplifies the problem, but Azure AI Language models require diverse, labeled examples with context to handle polysemy (same word, different meanings).

How to eliminate wrong answers

Option A is wrong because reducing training data would likely worsen model performance by removing valuable examples, not resolve the ambiguity. Option B is wrong because removing the 'Organization' entity type would prevent the model from correctly extracting 'Microsoft' as an organization, which is a valid extraction in many contexts, and does not solve the product extraction issue. Option C is wrong because adding training sentences without labeling the entity type provides no supervised signal for the model to learn the distinction between 'Organization' and 'Product' for the same token.

20
MCQmedium

You are designing an Azure AI solution that uses an Azure OpenAI resource. The solution must allow developers to call the model from a web app without embedding API keys in client-side code. You need to ensure that the web app can authenticate to the Azure OpenAI resource. What should you implement?

A.Configure the web app to use the Azure OpenAI API key and rotate it every 24 hours using Azure Automation.
B.Store the Azure OpenAI key in Azure Key Vault and have the web app retrieve it at runtime.
C.Generate a shared access signature (SAS) token for the Azure OpenAI resource and pass it in the request header.
D.Enable managed identity on the web app and assign the Cognitive Services OpenAI User role to the identity on the Azure OpenAI resource.
AnswerD

Managed identity allows the web app to authenticate to Azure OpenAI without storing credentials. Assigning the Cognitive Services OpenAI User role grants the necessary permissions to call the model. This is the recommended approach for keyless authentication and integrates with Azure RBAC, eliminating secret management in code or configuration.

Why this answer

Using a managed identity with the appropriate Azure RBAC role allows the web app to authenticate to Azure OpenAI without any secrets. The Cognitive Services OpenAI User role provides the necessary permissions to invoke the model. This approach is secure, scalable, and aligns with Azure best practices for keyless authentication.

Exam trap

The trap here is assuming that storing the API key in Key Vault is sufficient for client-side security, when in fact the key can still be exposed if the client retrieves it.

21
Multi-Selectmedium

Which THREE components are part of the Azure AI Bot Service?

Select 3 answers
A.Azure AI Search
B.Azure Bot Service (hosting)
C.Azure AI Language (CLU)
D.Bot Framework SDK
E.Bot Framework Composer
AnswersB, D, E

Azure Bot Service provides the hosting runtime that executes bot logic and exposes messaging endpoints, satisfying the requirement for a deployable bot component. It registers channels and manages connectivity between your bot and services such as Teams or web chat, forming the core platform element alongside the Bot Framework SDK and channel registration.

Why this answer

Azure Bot Service (hosting) (B) is correct because the Azure AI Bot Service provides the hosting/registration resource that exposes a messaging endpoint and connects bots to channels such as Microsoft Teams, Web Chat, and Direct Line. Bot Framework SDK (D) is correct because it is the core development library (for C#, JavaScript/TypeScript, Python, and Java) used to build bots that handle activities, turns, dialogs, and channel connectors. Bot Framework Composer (E) is correct because it is the visual authoring tool included in the Bot Framework tooling for designing, testing, and publishing conversational bots.

Azure AI Search (A) is not part of the Bot Service; it is a separate cognitive search service for indexing and querying content. Azure AI Language (CLU) (C) is also not part of the Bot Service; it is a separate Azure AI Language capability for conversational language understanding that a bot may call but that is not a Bot Service component.

Exam trap

The trap here is that candidates often confuse external AI services like Azure AI Search or Azure AI Language (CLU) as being part of the Azure AI Bot Service, when they are actually separate services that can be integrated but are not core components of the bot service itself.

22
MCQeasy

You are building a chatbot using Azure AI Bot Service and Language Service. The bot must recognize user intent for 'check order status'. How should you configure the Language Service?

A.Create a custom intent classification project
B.Deploy a QnA Maker knowledge base
C.Configure a sentiment analysis endpoint
D.Use the prebuilt entity extraction model
AnswerA

A custom intent classification project in Azure AI Language trains a model on your labelled utterances, returning the top intent for 'check order status'. This satisfies the stem's requirement to recognise user intent, since conversational language understanding maps utterances to intents rather than extracting entities or answering questions.

Why this answer

To recognize user intent for 'check order status', you need a custom intent classification project in Azure Language Service. This project type uses a trained model to map utterances to specific intents, such as 'CheckOrderStatus', which is exactly what the chatbot requires. Prebuilt models or QnA Maker do not provide custom intent recognition.

Exam trap

The trap here is that candidates confuse intent recognition with entity extraction or QnA, assuming any Language Service feature can handle intents, but only custom intent classification (or conversational language understanding) is designed for this purpose.

How to eliminate wrong answers

Option B is wrong because QnA Maker is designed for question-answering over a knowledge base, not for classifying user intent from natural language utterances. Option C is wrong because sentiment analysis determines the emotional tone of text, not the user's intent or goal. Option D is wrong because prebuilt entity extraction identifies named entities like dates or locations but does not classify the overall intent of a user message.

23
MCQmedium

You are deploying an Azure AI Language service solution for a multilingual customer support chatbot. The solution must support real-time translation between English, Spanish, and French. Which Azure resource should you provision?

A.Azure AI Speech
B.Azure OpenAI Service
C.Azure AI Language
D.Azure AI Translator
AnswerD

Azure AI Translator provides real-time text translation across English, Spanish and French, satisfying the multilingual chatbot requirement. It is the dedicated translation resource, unlike Azure AI Language, which handles entity extraction and sentiment rather than cross-language rendering.

Why this answer

Azure AI Translator is the correct resource because it provides real-time text translation across multiple languages, including English, Spanish, and French, via a dedicated REST API. The scenario specifically requires translation between languages, not speech recognition or generative AI, making Azure AI Translator the precise service for this task.

Exam trap

The trap here is that candidates confuse Azure AI Language with Azure AI Translator, assuming the 'Language' service includes translation, when in fact translation is a separate service under the Azure AI Services umbrella.

How to eliminate wrong answers

Option A is wrong because Azure AI Speech handles speech-to-text, text-to-speech, and speech translation, but it is not optimized for pure text translation between multiple languages without audio input. Option B is wrong because Azure OpenAI Service is designed for generative AI tasks like content creation and conversation, not for direct, real-time text translation between specific languages. Option C is wrong because Azure AI Language provides natural language processing capabilities such as sentiment analysis and entity recognition, but it does not include a dedicated real-time translation API; translation is handled by Azure AI Translator.

24
MCQhard

You are deploying a custom text classification model using Azure AI Language. The model must be retrained monthly with new labeled data. You need to automate the retraining process with minimal manual intervention. Which approach should you use?

A.Create an Azure DevOps pipeline that manually retrains the model every month
B.Retrain the model manually using Language Studio each month
C.Use the Azure AI Language REST API to trigger training and deployment on a schedule using Azure Logic Apps
D.Use Azure Machine Learning to host the custom model and automate retraining
AnswerC

Scheduled REST API calls from Logic Apps trigger training and deployment without human input, satisfying the monthly retraining requirement with minimal manual intervention. The API exposes training and deployment operations directly, so the workflow can orchestrate both steps automatically.

Why this answer

Azure Logic Apps can schedule HTTP requests to the Azure AI Language REST API to trigger training and deployment of a custom text classification model. This approach automates the monthly retraining process without manual intervention, using the API's capabilities for model creation, training, and deployment.

Exam trap

The trap here is that candidates may confuse Azure Machine Learning with Azure AI Language, thinking that Azure Machine Learning is the appropriate service for hosting and retraining custom text classification models, when in fact Azure AI Language provides its own REST API for this purpose and is the correct service for custom text classification.

How to eliminate wrong answers

Option A is wrong because an Azure DevOps pipeline that manually retrains the model every month still requires manual intervention to trigger the pipeline, contradicting the requirement for minimal manual intervention. Option B is wrong because retraining manually using Language Studio each month is entirely manual and does not automate the process. Option D is wrong because Azure Machine Learning is not designed to host custom text classification models built with Azure AI Language; it is a separate platform for building and deploying machine learning models, and using it would introduce unnecessary complexity and integration overhead.

25
MCQeasy

You are designing a solution that uses Azure AI Language to analyze customer feedback. The solution must detect sentiment, extract key phrases, and identify named entities. Which feature should you use?

A.Azure AI Language service
B.Azure AI Speech service
C.Azure AI Computer Vision
D.Translator API
AnswerA

Azure AI Language consolidates sentiment analysis, key phrase extraction and named entity recognition within one resource, so a single call satisfies all three requirements without stitching separate services together. Its prebuilt models return sentiment scores, key phrases and entity categories directly, matching the stem's combined detection, extraction and identification constraints.

Why this answer

The Azure AI Language service provides pre-built capabilities for sentiment analysis, key phrase extraction, and named entity recognition (NER) as part of its text analytics features. These three tasks are directly supported by the service's Analyze API, making it the correct choice for analyzing customer feedback text.

Exam trap

The trap here is that candidates may confuse Azure AI Language with other Azure AI services that have overlapping names (e.g., Translator API for language tasks) or assume Speech or Vision services can perform text analysis, but only the Language service provides the specific trio of sentiment, key phrases, and NER.

How to eliminate wrong answers

Option B is wrong because Azure AI Speech service is designed for speech-to-text, text-to-speech, and speech translation, not for analyzing text sentiment, key phrases, or named entities. Option C is wrong because Azure AI Computer Vision focuses on image and video analysis (e.g., object detection, OCR), not on natural language processing tasks like sentiment or entity extraction. Option D is wrong because Translator API is specifically for machine translation between languages and does not include sentiment analysis, key phrase extraction, or named entity recognition.

26
MCQeasy

Your organization wants to implement a document processing pipeline that extracts text from scanned PDFs and identifies named entities. Which two Azure AI services should you use?

A.Azure AI Language
B.Azure AI Custom Vision
C.Azure AI Document Intelligence
D.Azure AI Translator
E.Azure AI Speech
AnswerA, C

Azure AI Language provides the Named Entity Recognition feature, identifying people, places, organisations and other entities within text. It satisfies the stem's entity-identification requirement, consuming text that Document Intelligence has already extracted from the scanned PDFs.

Why this answer

Azure AI Document Intelligence (formerly Form Recognizer) is used to extract text from scanned PDFs via OCR, while Azure AI Language provides pre-built named entity recognition (NER) to identify entities like people, organizations, and locations. Together, they form a complete pipeline: Document Intelligence handles the image-to-text conversion, and Language processes the extracted text for entity extraction.

Exam trap

The trap here is that candidates often confuse Azure AI Document Intelligence with Azure AI Custom Vision, thinking Custom Vision can perform OCR, but Document Intelligence is the dedicated service for document text extraction and layout analysis.

How to eliminate wrong answers

Option B is wrong because Azure AI Custom Vision is designed for image classification and object detection, not for OCR or text extraction from scanned documents. Option D is wrong because Azure AI Translator is a machine translation service that converts text between languages, not for extracting text from images or identifying named entities. Option E is wrong because Azure AI Speech handles speech-to-text and text-to-speech, not OCR or NER from scanned PDFs.

27
MCQmedium

You are testing an Azure OpenAI Service chat completion with function calling. The assistant returned null content and a tool call. What does this indicate?

A.The model is unable to answer the question and returned an error
B.The system message is preventing the model from responding
C.The model is using a tool to answer the question, so content is null
D.The function call syntax is invalid and the model skipped it
AnswerC

With function calling, the model returns a tool call instead of a natural-language reply, so the content field is null. Your code must execute the named function and send its result back for a final completion.

Why this answer

In Azure OpenAI Service function calling, when the model determines that it needs to invoke a tool (e.g., an external API or database query) to fulfill the user's request, it returns a `tool_calls` object with `content` set to `null`. This is the expected behavior—the model is signaling that it is delegating the response to the tool, not that it has failed or is blocked.

Exam trap

The trap here is that candidates often misinterpret a null content as a model failure or error, when in fact it is a standard indicator that the model is actively using a tool to fulfill the request.

How to eliminate wrong answers

Option A is wrong because a null content with a tool call is not an error; it is a deliberate design pattern in function calling where the model defers to the tool for the answer. Option B is wrong because the system message does not prevent the model from responding; the model actively chooses to return a tool call instead of text content. Option D is wrong because if the function call syntax were invalid, the model would either ignore the function definitions entirely or return an error, not a valid tool call with null content.

28
MCQeasy

You are developing a chatbot that uses Azure AI Language to understand user intents. The chatbot must handle multiple languages and direct users to the appropriate support team based on the detected intent. Which Azure AI Language feature should you use?

A.Text Analytics
B.Conversational language understanding (CLU)
C.QnA Maker
D.Translator
AnswerB

Conversational language understanding (CLU) extracts intents and entities from utterances, and its multilingual training lets one project recognise the same intent across several languages. That satisfies the stem's requirement to detect intent and route users to the correct support team, which plain language detection or translation alone cannot do.

Why this answer

Conversational language understanding (CLU) is the correct feature because it is specifically designed to extract intents and entities from user utterances in a multi-language conversational context. CLU enables the chatbot to detect the user's intent (e.g., 'billing', 'technical support') and route them to the appropriate support team, while also supporting multiple languages through its language-agnostic model training and per-language project configurations.

Exam trap

The trap here is that candidates often confuse 'Text Analytics' (pre-built NLP) with 'Conversational language understanding' (custom intent/entity extraction), mistakenly thinking that Text Analytics can be trained to classify intents, when in fact it only provides pre-built capabilities like sentiment and key phrases.

How to eliminate wrong answers

Option A is wrong because Text Analytics (now part of Azure AI Language) provides pre-built sentiment analysis, key phrase extraction, and entity recognition, but it does not offer custom intent classification or entity extraction for conversational flows — it is not designed for building a chatbot's intent routing logic. Option C is wrong because QnA Maker (now Azure AI Language's custom question answering) is optimized for providing direct answers from a knowledge base of FAQ-style Q&A pairs, not for detecting user intents and routing to different support teams; it lacks the intent classification engine required for multi-intent conversational scenarios. Option D is wrong because Translator is a pure machine translation service that translates text between languages without any capability to detect intents or entities — it cannot interpret the user's goal or route them to a support team.

29
MCQeasy

You need to enforce that only users from your Microsoft Entra ID tenant can call your Azure AI Language API endpoint. Which security mechanism should you configure?

A.Microsoft Entra ID authentication
B.API key authentication
C.IP whitelist
D.Azure Firewall
AnswerA

Microsoft Entra ID authentication validates bearer tokens issued by your tenant, so only principals within that tenant can call the endpoint. This enforces the tenant restriction directly, unlike key-based access which any key holder can use.

Why this answer

Microsoft Entra ID authentication (formerly Azure AD) allows you to enforce that only users and applications from your specific Entra ID tenant can call the Azure AI Language API. This is achieved by configuring a managed identity or service principal and assigning it the Cognitive Services User role, which ensures that tokens issued by your tenant are required for access. API keys and IP whitelists do not provide tenant-level identity enforcement, and Azure Firewall is a network-level control that does not authenticate individual users or applications.

Exam trap

The trap here is that candidates often confuse network-level controls (IP whitelist, Azure Firewall) with identity-level controls, mistakenly thinking that restricting by IP address or network firewall is sufficient to enforce tenant-specific access, when in fact only Entra ID authentication can validate the caller's tenant membership.

How to eliminate wrong answers

Option B is wrong because API key authentication uses a static key that can be shared or leaked, and it does not verify the caller's identity or tenant membership, so any user with the key can access the endpoint regardless of their Entra ID tenant. Option C is wrong because an IP whitelist only restricts access based on source IP addresses, which does not authenticate the user or ensure they belong to a specific Entra ID tenant; an attacker could spoof an IP or use a VPN from an allowed range. Option D is wrong because Azure Firewall is a network security service that filters traffic at the network layer, not at the application or identity layer, and it cannot enforce tenant-specific authentication for API calls.

30
MCQhard

You executed the Azure CLI command to list Azure OpenAI resources. You need to programmatically access the endpoint of the resource named 'gpt4' in a script. What is the most reliable way to extract the endpoint?

A.Use Azure PowerShell Get-AzCognitiveServicesAccount cmdlet
B.Parse the table output using string manipulation
C.Use az cognitiveservices account show with --query to filter by name
D.Deploy a new Azure OpenAI resource with a known endpoint
AnswerC

Using `az cognitiveservices account show` with `--query` retrieves the endpoint directly from the resource's properties, satisfying the need for programmatic extraction in a script. Unlike parsing list output, querying the named account returns `properties.endpoint` deterministically, avoiding ambiguity when multiple Azure OpenAI resources exist in the subscription.

Why this answer

`az cognitiveservices account show` with the `--query` parameter allows you to retrieve the specific endpoint property for a named resource using JMESPath filtering. This approach is reliable, scriptable, and avoids parsing unstructured output, which is error-prone. The Azure CLI returns structured JSON, and `--query` extracts the exact value without manual string manipulation.

Exam trap

The trap here is that candidates may default to parsing the default table output (Option B) because it looks human-readable, but the exam tests understanding that structured JSON queries are the reliable, production-grade method for programmatic access.

How to eliminate wrong answers

Option A is wrong because `Get-AzCognitiveServicesAccount` retrieves all cognitive services accounts, but does not directly filter by resource name in a single cmdlet; you would need additional piping or filtering, and it returns the entire object, not just the endpoint. Option B is wrong because parsing table output with string manipulation is fragile, depends on column alignment, and breaks if the CLI output format changes or if the resource name contains special characters. Option D is wrong because deploying a new resource is unnecessary, wasteful, and does not solve the requirement to access an existing resource's endpoint.

31
MCQeasy

You are using Azure AI Content Safety to moderate user-generated content in a social media app. The solution must detect and block hate speech and self-harm content in real time. Which Content Safety feature should you use?

A.Custom category management
B.Severity analysis
C.Image moderation
D.Text moderation
AnswerD

Text moderation applies Azure AI Content Safety's classification models to written user content, returning severity scores for hate and self-harm categories so the app can block them in real time. It directly satisfies the stated requirement to detect and block those two harm types.

Why this answer

Text moderation is the correct choice because Azure AI Content Safety's text moderation API is specifically designed to detect and block hate speech and self-harm content in real time. It analyzes text for severity levels across multiple categories, including hate and self-harm, and returns a severity score to trigger blocking actions. This directly meets the requirement for real-time detection of these specific content types in user-generated text.

Exam trap

The trap here is that candidates may confuse severity analysis as a standalone feature, but it is actually a sub-component of text moderation; the question asks for the feature that performs the detection, not the analysis of the detection results.

How to eliminate wrong answers

Option A is wrong because custom category management allows you to define your own content categories (e.g., brand-specific terms), but it does not replace the built-in hate speech and self-harm detection; the question requires using existing Azure AI Content Safety features, not custom definitions. Option B is wrong because severity analysis is a component of the moderation process (it assigns a severity score to detected content), not a standalone feature; you must use text moderation to first detect the content before severity analysis can be applied. Option C is wrong because image moderation is used to analyze visual content (images) for inappropriate content, but the question specifically mentions user-generated content that includes hate speech and self-harm, which are primarily text-based; image moderation does not analyze text within images by default.

32
MCQmedium

You are planning an Azure AI solution that uses Azure OpenAI. You need to ensure that the solution can be deployed to multiple regions for high availability. The solution must automatically route requests to the nearest available region and fail over if a region becomes unavailable. What should you use?

A.Azure Front Door with latency-based routing
B.Azure Load Balancer with availability zones
C.Azure Application Gateway with multi-site listeners
D.Azure Traffic Manager with priority routing
AnswerA

Azure Front Door is a global HTTP load balancer that supports latency-based routing, which directs requests to the lowest-latency endpoint. It also provides automatic failover if an endpoint becomes unhealthy. This meets the requirements for multi-region deployment, nearest-region routing, and failover for Azure OpenAI.

Why this answer

Azure Front Door is the appropriate service because it provides global HTTP load balancing with latency-based routing and automatic failover. It can route requests to the nearest available Azure OpenAI endpoint across multiple regions and detect unhealthy endpoints to redirect traffic. The other options are either regional load balancers or do not support latency-based global routing.

Exam trap

The trap here is selecting a regional load balancer like Azure Load Balancer or Application Gateway for a multi-region scenario, or choosing Traffic Manager with priority routing when latency-based routing is required.

33
MCQeasy

You need to monitor the performance of an Azure AI Language service custom entity recognition model. Which metric should you track to evaluate the model's ability to correctly identify entities?

A.Throughput
B.Response latency
C.F1 score
D.Accuracy
AnswerC

F1 score is the harmonic mean of precision and recall, so it captures both missed entities and false positives. That balance directly measures how correctly the custom entity recognition model identifies entities, unlike accuracy or latency metrics.

Why this answer

The F1 score is the standard metric for evaluating custom entity recognition models in Azure AI Language, as it balances precision (correctly identified entities) and recall (missed entities). Unlike accuracy, which can be misleading due to class imbalance in entity labeling, F1 provides a harmonic mean that reflects the model's ability to correctly identify entities without bias toward the majority class.

Exam trap

The trap here is that candidates confuse accuracy (a common metric in classification) with the specialized F1 score required for entity recognition, where class imbalance makes accuracy a poor indicator of model performance.

How to eliminate wrong answers

Option A is wrong because throughput measures the number of requests processed per second, not the quality of entity identification. Option B is wrong because response latency measures the time taken to return a prediction, not the correctness of entity predictions. Option D is wrong because accuracy (ratio of correct predictions to total predictions) is misleading for entity recognition tasks where the number of non-entity tokens vastly outnumbers entity tokens, leading to inflated accuracy even if the model fails to identify entities.

34
MCQhard

Your Azure AI solution uses multiple AI services including Computer Vision and Language. To reduce costs, you want to share a single key and endpoint across services. Which Azure resource type should you deploy?

A.Separate single-service resources for each AI service
B.Azure Key Vault for storing keys
C.Azure API Management gateway
D.Azure AI services multi-service resource
AnswerD

A multi-service resource provisions one key and endpoint spanning Computer Vision, Language and other Azure AI services, so every call authenticates against the same credentials. This directly satisfies the cost-reduction constraint of sharing a single key and endpoint rather than deploying separate per-service resources.

Why this answer

D is correct because Azure AI services multi-service resource provides a single endpoint and key that can be used across multiple AI services (e.g., Computer Vision, Language, Face, etc.), reducing management overhead and cost by consolidating billing. This resource type is designed specifically for scenarios where you want to share credentials across services without deploying separate single-service instances.

Exam trap

The trap here is that candidates may confuse Azure API Management (Option C) as a way to share endpoints, but it is a gateway for API management, not a shared AI resource; the correct answer is the multi-service resource that natively provides a single key and endpoint for multiple AI services.

How to eliminate wrong answers

Option A is wrong because deploying separate single-service resources for each AI service would require managing multiple keys and endpoints, increasing complexity and cost, which contradicts the goal of reducing costs through sharing. Option B is wrong because Azure Key Vault is a service for securely storing and managing secrets (like keys), not for providing a shared endpoint or key for AI services; it does not replace the need for an AI resource. Option C is wrong because Azure API Management gateway is used to create, publish, and manage APIs, not to provide a shared key and endpoint for Azure AI services; it adds an extra layer of abstraction and cost, not a direct shared resource.

35
MCQeasy

You are planning to deploy an Azure AI Content Safety solution. What is the primary requirement for using the service?

A.Data must be stored in the same region as the service
B.All users must have Microsoft Entra ID P2 licenses
C.An active Azure subscription
D.The application must be written in C#
AnswerC

Content Safety is an Azure resource, so provisioning it requires an active Azure subscription with billing enabled. Without a subscription you cannot create the resource, obtain keys or endpoint, or call the REST API, making this the fundamental prerequisite.

Why this answer

An active Azure subscription is the primary requirement because Azure AI Content Safety is a cloud-based service that requires a valid subscription for resource provisioning, API access, and billing. Without an Azure subscription, you cannot create the Content Safety resource or authenticate API calls, regardless of other configurations.

Exam trap

The trap here is that candidates often confuse 'primary requirement' with optional or advanced features like data residency (A), licensing (B), or specific programming languages (D), but the fundamental prerequisite is always an active Azure subscription for any Azure AI service.

How to eliminate wrong answers

Option A is wrong because data does not need to be stored in the same region as the service; Azure AI Content Safety processes content in the region where the resource is deployed, but data residency requirements are separate and not a primary prerequisite. Option B is wrong because Microsoft Entra ID P2 licenses are not required; Azure AI Content Safety uses standard Azure AD authentication (free tier) or API keys, and P2 licenses are only relevant for advanced identity protection features unrelated to this service. Option D is wrong because the application does not need to be written in C#; the service is language-agnostic and can be accessed via REST APIs, SDKs in Python, Java, JavaScript, .NET, and other languages.

36
MCQhard

You are planning an Azure AI solution that will process documents containing personal data. The solution uses Azure AI Document Intelligence and Azure OpenAI in the same subscription. Corporate governance requires that data processed by these services never leave a specified geographic region and that you can audit which operations were performed on the data. You need to select a deployment approach that meets these requirements with the least administrative effort. What should you do?

A.Deploy all resources in the required region and enable diagnostic settings to send logs to a Log Analytics workspace in the same region.
B.Deploy resources in the required region and configure customer-managed keys stored in a key vault in a different region.
C.Deploy resources in the required region and enable soft delete on all storage accounts used by the solution.
D.Deploy resources in multiple regions and use Azure Traffic Manager to route requests to the closest region.
AnswerA

Deploying every resource in the required region keeps data processing within that geography, and diagnostic settings capture resource logs and metrics for auditing. This is a built-in capability that requires minimal ongoing administration while satisfying both the data residency and auditability requirements.

Why this answer

Placing all resources in the required region ensures data is processed within that geography, and diagnostic settings stream resource logs and metrics to Log Analytics for auditing. This uses native platform features with little ongoing effort. Multi-region routing, cross-region key vaults, and soft delete do not satisfy both residency and auditability.

Exam trap

The trap here is confusing data durability features such as soft delete or key management with data residency and audit logging, which are governed by deployment location and diagnostic settings.

37
Multi-Selectmedium

Which THREE factors should be considered when choosing a region for deploying Azure AI services?

Select 3 answers
A.Number of Azure data centers in the region.
B.Service availability and feature support.
C.Compliance and data residency requirements.
D.Latency to end users.
E.Cost of the services in each region.
AnswersB, C, D

Not all services are available in all regions.

Why this answer

Service availability and feature support (Option B) is a critical factor because not all Azure AI services are available in every region; for example, certain Cognitive Services like Azure OpenAI or Computer Vision OCR may be in preview or fully supported only in specific regions. Choosing a region without the required service or feature would prevent deployment or limit functionality, directly impacting solution design.

Exam trap

Microsoft often tests the misconception that the number of data centers or cost are primary region selection factors, but the exam emphasizes that service availability, compliance, and latency are the three key considerations for Azure AI services.

38
MCQhard

You are designing an Azure AI solution that uses Azure AI Search. The solution must ensure that only authorized users can query the search index, and that users can only access documents they are permitted to see. You need to implement document-level access control. What should you do?

A.Enable Azure Private Link for the search service and restrict access to the corporate network.
B.Implement security filters in queries by using the user's identity and a field in the index that maps to allowed groups.
C.Use customer-managed keys (CMK) to encrypt the index and control access to the keys.
D.Use Azure role-based access control (RBAC) to assign the Search Index Data Reader role to users.
AnswerB

Azure AI Search supports document-level security through security filters. You can include a field in the index that contains the allowed groups or users for each document, and at query time, filter results based on the authenticated user's group memberships. This ensures users only see documents they are authorized to access.

Why this answer

To enforce document-level access control in Azure AI Search, you must implement security filters. This involves adding a field to the index that specifies which users or groups can access each document, and then applying a filter in queries based on the authenticated user's identity. This ensures that users only retrieve documents they are permitted to see.

Exam trap

The trap here is assuming that Azure RBAC or network security can provide document-level security; they control service access, not per-document access.

39
MCQmedium

Your Azure AI Document Intelligence model is failing to extract tables from scanned PDFs. The PDFs are low-quality images. What should you do first?

A.Verify that the Read OCR step is extracting text correctly.
B.Use Azure AI Computer Vision to enhance the image.
C.Retrain the model with more table examples.
D.Use a higher resolution scanner for input PDFs.
AnswerA

Verifying the Read OCR output comes first because Document Intelligence's layout and table extraction depend entirely on that OCR layer. Low-quality scans degrade character and word recognition, so tables cannot be reconstructed reliably. Confirming whether the Read model extracts text correctly isolates the OCR constraint before tuning table extraction.

Why this answer

The Read OCR step is the foundational layer for table extraction in Azure AI Document Intelligence. If the OCR cannot accurately recognize text from low-quality images, subsequent table extraction models will fail regardless of training or image enhancement. Verifying OCR output first isolates whether the issue is at the text recognition stage or the table parsing stage, following a systematic troubleshooting approach.

Exam trap

The trap here is that candidates often jump to retraining or image enhancement without realizing that Document Intelligence's table extraction is entirely dependent on the quality of the OCR output, and the first diagnostic step must be to check that foundational layer.

How to eliminate wrong answers

Option B is wrong because Azure AI Computer Vision image enhancement does not improve OCR accuracy for Document Intelligence; the service already applies its own preprocessing, and external enhancement may introduce artifacts. Option C is wrong because retraining the model with more table examples will not fix the root cause if the OCR step cannot correctly extract text from low-quality images; the model relies on accurate OCR input. Option D is wrong because using a higher resolution scanner is a hardware solution that may not be feasible for existing PDFs and does not address the immediate diagnostic need; the first step should be software-based verification of OCR output.

40
MCQmedium

Your organization is using Azure AI Search with semantic ranking. Users report that search results are not showing relevant documents at the top. You need to improve relevance. What should you configure?

A.Add synonyms to the index
B.Define a custom scoring profile
C.Enable semantic search configuration on the index
D.Change the index analyzer to a different language analyzer
AnswerC

Semantic ranking only reorders results when a semantic configuration is defined on the index and referenced in the query. Without it, scoring falls back to BM25 keyword relevance, so enabling the semantic configuration is what lifts relevant documents to the top.

Why this answer

Semantic search configuration is required to enable semantic ranking, which uses deep learning models to re-rank search results based on contextual relevance rather than just keyword matching. Without this configuration, the index cannot leverage semantic ranking even if the service tier supports it, so enabling it directly addresses the user's complaint about irrelevant documents appearing at the top.

Exam trap

Microsoft often tests the misconception that enabling semantic ranking is automatic with the service tier, but candidates must explicitly configure a semantic configuration on the index and specify it in the query request to activate the feature.

How to eliminate wrong answers

Option A is wrong because adding synonyms expands query matching but does not re-rank results based on semantic understanding; it only broadens recall, not precision. Option B is wrong because custom scoring profiles operate on lexical term frequency and field weights, not on the deep neural network models that semantic ranking uses to understand query intent. Option D is wrong because changing the index analyzer affects tokenization and language-specific stemming, not the semantic re-ranking stage that determines which documents are most contextually relevant.

41
MCQmedium

A company is using Azure AI Vision to analyze images from a manufacturing line. The solution must detect defects in real-time. The team discovers that the model's accuracy drops significantly when images are captured under different lighting conditions. What is the best approach to improve the model's robustness?

A.Apply image pre-processing to normalize lighting before sending to the model.
B.Increase the number of training images without varying lighting conditions.
C.Retrain the model using images captured under various lighting conditions, using data augmentation.
D.Use a pre-built model from Azure AI Vision instead of a custom model.
AnswerC

Accuracy drops because the model has not learned invariance to illumination, a covariate shift between training and inference data. Retraining with images spanning varied lighting, plus augmentation that synthesises those variations, exposes the model to the real-world distribution it must handle, directly restoring robustness under the differing lighting conditions the stem describes.

Why this answer

The accuracy drop is caused by a domain shift: the model was trained on images with limited lighting variation but is deployed under diverse lighting. Retraining with images captured under various lighting conditions and applying data augmentation (brightness, contrast, exposure jitter) teaches the model to be invariant to those variations, directly improving robustness. This addresses the root cause rather than masking it at inference time.

Exam trap

The trap is choosing inference-time preprocessing (normalize lighting) as a quick fix instead of addressing the training data distribution, which is the actual cause of the robustness gap.

How to eliminate wrong answers

Option A is wrong because pre-processing to normalize lighting is a partial mitigation that can lose defect-relevant detail and does not improve the model's learned invariance; it also adds a fragile hand-tuned step. Option B is wrong because adding more images without varying lighting reinforces the same bias and will not improve performance under new lighting conditions. Option D is wrong because a pre-built Azure AI Vision model is generic and not trained on the company's specific defect classes, so it cannot outperform a properly retrained custom model for this task.

42
MCQmedium

Your team is building a custom question-answering solution using Azure AI Language. The solution must be able to answer questions based on a set of PDF documents. You need to import the documents and create a knowledge base. What should you do first?

A.Use Azure AI Foundry to create a project and upload the documents
B.Create an index in Azure AI Search and upload the documents
C.Use the Azure AI Language service with the custom question answering feature and import the documents
D.Deploy an Azure AI Bot Service and connect it to the documents
AnswerC

Custom question answering ingests PDF documents as sources and builds the knowledge base from them. Importing the documents into the Azure AI Language custom question answering project is the prerequisite step before training and publishing the knowledge base.

Why this answer

The custom question answering feature of Azure AI Language is specifically designed to ingest documents (including PDFs) and build a knowledge base that can be used for question-answering. This feature provides a built-in pipeline to extract question-answer pairs from documents, create a knowledge base, and deploy it as a service without needing additional search indexing or bot orchestration.

Exam trap

The trap here is that candidates often confuse Azure AI Search (a general-purpose search service) with the custom question answering feature, which is purpose-built for extracting and managing QnA pairs from documents, leading them to choose Option B incorrectly.

How to eliminate wrong answers

Option A is wrong because Azure AI Foundry is a development environment for building and managing AI models, but it does not directly import documents into a question-answering knowledge base; the custom question answering feature is the correct service for this task. Option B is wrong because creating an index in Azure AI Search is used for full-text or vector search, not for the structured question-answer pair extraction and management that custom question answering provides. Option D is wrong because Azure AI Bot Service is a framework for building conversational bots, not a tool for importing documents and creating a knowledge base; the knowledge base must be created first using the custom question answering feature before a bot can consume it.

43
MCQhard

You are designing an Azure AI solution that uses multiple Azure AI services, including Azure AI Vision and Azure AI Language. You need to ensure that the solution can be deployed in a way that minimizes latency between services and provides a single endpoint for management. What should you use?

A.Deploy a single Azure AI Services resource for each service and use private endpoints to connect them.
B.Deploy each service as a separate resource in the same region and use Azure API Management to aggregate them.
C.Deploy a single Azure AI Services multi-service resource that includes both Vision and Language capabilities.
D.Deploy each service as a separate resource in different regions and use Azure Front Door to route requests.
AnswerC

An Azure AI Services multi-service resource allows you to access multiple AI services, such as Vision and Language, through a single endpoint and key. Deploying this resource in one region ensures that all services are co-located, minimizing network latency between them. It also simplifies management by providing a single resource for billing and access control.

Why this answer

A multi-service Azure AI Services resource bundles multiple AI capabilities into a single Azure resource with one endpoint and key. Deploying it in one region ensures all services are co-located, reducing latency. It also simplifies management by consolidating billing and access control, meeting both requirements.

Exam trap

The trap here is assuming that using API Management or private endpoints alone can achieve a single endpoint and minimal latency, when actually a multi-service resource is the native solution for co-located services with unified management.

44
MCQmedium

Your team develops a document translation solution using Azure AI Translator. The solution must translate documents while preserving formatting and layout. Which feature should you use?

A.Azure AI Translator Custom Translator
B.Azure AI Translator Document Translation
C.Azure AI Document Intelligence
D.Azure AI Translator Text Translation
AnswerB

Document Translation is the Translator feature that translates whole documents while preserving their original formatting and layout, returning translated files in the source format. Plain text translation APIs discard structure, so they cannot satisfy the layout-preservation constraint.

Why this answer

Azure AI Translator Document Translation is specifically designed to translate entire documents while preserving the original formatting, structure, and layout. Unlike Text Translation, which handles only plain text strings, Document Translation processes files (e.g., PDF, Word, Excel) and returns a translated version with the same formatting, making it the correct choice for this requirement.

Exam trap

The trap here is that candidates often confuse Document Translation with Text Translation, assuming that any translation feature can handle documents, but Text Translation only processes plain text strings and cannot preserve formatting or layout.

How to eliminate wrong answers

Option A is wrong because Custom Translator is a feature for building custom translation models tailored to specific domain terminology, not for preserving document formatting or layout. Option C is wrong because Azure AI Document Intelligence (formerly Form Recognizer) is used for extracting text, key-value pairs, and tables from documents, not for translating them. Option D is wrong because Text Translation only handles plain text strings and cannot preserve the formatting or layout of an entire document.

45
MCQhard

You are responsible for an Azure AI multi-agent system built on Microsoft Foundry. The system experiences frequent timeout errors when agents call external APIs. You need to implement a resilient pattern. What should you do?

A.Implement retry logic with exponential backoff in the agent tool definitions
B.Disable retry attempts to avoid duplicate requests
C.Increase the global timeout for all agents
D.Switch to synchronous agent calls
AnswerA

Retry logic with exponential backoff in the agent tool definitions absorbs transient external API failures and rate limiting, preventing them from surfacing as timeouts. Spacing retries avoids hammering the dependency, which is the resilient pattern for intermittent call failures.

Why this answer

Implementing retry logic with exponential backoff in agent tool definitions is a standard resilience pattern for transient failures when calling external APIs. This approach, often using the Retry-After header or a custom backoff strategy, reduces load on the API and prevents cascading timeouts in a multi-agent system built on Microsoft Foundry. It aligns with the recommended practices for building robust AI solutions that depend on external services.

Exam trap

The trap here is that candidates often confuse increasing timeouts with solving transient failures, but timeouts only mask the problem and do not provide resilience against intermittent API errors.

How to eliminate wrong answers

Option B is wrong because disabling retry attempts entirely would cause the system to fail on any transient error, making it less resilient and increasing the likelihood of incomplete agent tasks. Option C is wrong because increasing the global timeout for all agents does not address the root cause of transient API failures; it only delays the timeout, potentially masking underlying issues and wasting resources. Option D is wrong because switching to synchronous agent calls would block agent execution, reducing concurrency and potentially worsening timeout issues by making the system less responsive to failures.

46
MCQmedium

A company is deploying a solution using Azure AI Vision to analyze images of products on a retail website. They need to ensure that the image analysis is performed within a specific geographic boundary for data residency compliance. What should they configure?

A.Deploy the Azure AI Vision resource in the desired Azure region
B.Create a private endpoint for the Vision resource
C.Enable multi-region replication on the Vision resource
D.Use the Free tier of Azure AI Vision
AnswerA

Deploying the Azure AI Vision resource in the target Azure region keeps image processing and stored data within that geography, satisfying the data residency constraint. Regional deployment determines where inference occurs; unlike global endpoints, no cross-geography replication happens. Microsoft Entra ID governs access but does not affect processing location.

Why this answer

Azure AI Vision resources are regional Azure resources, meaning all data processing and storage occur within the Azure region where the resource is deployed. By deploying the resource in the desired geographic region, you ensure that image analysis and any derived data remain within that boundary, satisfying data residency compliance requirements. This is the fundamental mechanism for controlling data location in Azure AI services.

Exam trap

The trap here is that candidates confuse network isolation (private endpoints) with data residency, or assume that replication or tier changes can alter where data is stored, when in fact the region of the resource itself is the sole determinant for compliance.

How to eliminate wrong answers

Option B is wrong because a private endpoint restricts network access to the resource via a private IP address in your virtual network, but it does not control the geographic location where data is processed or stored. Option C is wrong because Azure AI Vision does not support multi-region replication; that feature is available for Azure Storage and Cosmos DB, not for AI services. Option D is wrong because the Free tier imposes usage limits (e.g., 20 transactions per minute) and does not provide any data residency guarantees; it still processes data in the region where the resource is created.

47
MCQhard

Your Azure AI Search index is experiencing high query latency. You have enabled semantic search and custom scoring profiles. You need to reduce latency without degrading search quality. Which action should you take?

A.Remove custom scoring profiles.
B.Increase the number of replicas.
C.Reduce the number of partitions.
D.Disable semantic search.
AnswerB

Query latency stems from limited compute, not index size. Replicas add query-processing capacity and enable load balancing across nodes, reducing latency while preserving semantic ranking and scoring profiles. Partition changes would affect storage and indexing, not query throughput.

Why this answer

Increasing the number of replicas distributes query load across multiple copies of the index, allowing parallel processing of search requests. This directly reduces query latency without altering the search logic, scoring profiles, or semantic enrichment, thus preserving search quality.

Exam trap

The trap here is that candidates confuse partitions (which affect storage and indexing speed) with replicas (which affect query throughput), leading them to incorrectly reduce partitions or disable features instead of scaling query capacity.

How to eliminate wrong answers

Option A is wrong because removing custom scoring profiles would degrade search quality by eliminating relevance tuning, and it does not address the root cause of high latency (insufficient query capacity). Option C is wrong because reducing partitions decreases the index's data capacity and can increase latency by forcing more data per partition, while partitions primarily affect indexing speed and storage, not query throughput. Option D is wrong because disabling semantic search would degrade search quality by removing AI-powered ranking and relevance features, and it does not address the underlying query load issue that replicas solve.

48
Multi-Selecthard

You are deploying an Azure AI solution that uses Azure AI Language and Azure AI Vision. You need to ensure that the solution can be deployed repeatedly to multiple environments with consistent configuration and that secrets are managed securely. (Choose two.)

Select 2 answers
A.Use Azure Key Vault to store the Azure AI service keys and reference the secrets from the ARM template.
B.Store the Azure AI service keys in the ARM template parameters file.
C.Use the Azure portal to manually create the Azure AI resources in each environment.
D.Store the Azure AI service keys in a Git repository and use a pipeline to inject them during deployment.
E.Use an ARM template to define the Azure AI resources and their configurations.
AnswersA, E

Azure Key Vault provides secure storage for secrets. By referencing Key Vault secrets from an ARM template, you avoid hardcoding keys in the template or parameters. This allows the same template to be deployed to multiple environments while retrieving environment-specific secrets from Key Vault, meeting both consistency and security requirements.

Why this answer

To achieve repeatable deployments with consistent configuration, use infrastructure as code such as ARM templates. To manage secrets securely, store keys in Azure Key Vault and reference them from the templates. Combining these two practices allows the same deployment process to be used across environments while keeping secrets out of source control and deployment definitions.

Exam trap

The trap here is assuming that storing secrets in a parameters file or Git repository is acceptable if access is restricted, when in fact secrets should always be stored in a dedicated secure store like Azure Key Vault.

49
MCQmedium

You manage an Azure AI Search solution that indexes documents from Azure Blob Storage. The index must support real-time updates when documents are added or modified. Which approach should you use?

A.Use the push API to manually upload documents.
B.Configure an indexer with a short schedule and change tracking.
C.Manually reset and rerun the indexer after each change.
D.Add a cognitive skillset to process new documents.
AnswerB

A blob indexer with change tracking detects new and modified documents via the storage layer's timestamps, so each scheduled run reindexes only changed content. A short schedule keeps latency low, satisfying the real-time update constraint without rebuilding the index or reindexing unchanged blobs.

Why this answer

Azure AI Search indexers can be configured with a short schedule (e.g., every 5 minutes) and change tracking (using high-water mark or integrated change detection on Azure Blob Storage) to automatically index new or modified documents without manual intervention. This provides near-real-time updates while leveraging the indexer's built-in change detection capabilities.

Exam trap

The trap here is that candidates often confuse the push API (Option A) as the only way to achieve real-time updates, overlooking that indexers with change tracking and a short schedule can provide automated near-real-time indexing without custom code.

How to eliminate wrong answers

Option A is wrong because the push API requires manual coding to upload documents, which does not automatically detect changes in Azure Blob Storage and is not a 'configured' approach for real-time updates from a data source. Option C is wrong because manually resetting and rerunning the indexer after each change is not automated and does not support real-time updates; it is a manual, batch-oriented process. Option D is wrong because a cognitive skillset enriches documents with AI transformations (e.g., OCR, entity recognition) but does not handle the scheduling or change tracking needed for real-time indexing of new or modified documents.

50
MCQhard

You are developing an Azure AI solution that uses Azure Cognitive Search. The solution must index documents from an Azure Blob Storage container. You need to ensure that the indexer can access the Blob Storage container securely without storing credentials in the indexer definition. What should you do?

A.Use a shared access signature (SAS) token for the Blob Storage container and include it in the indexer's data source connection string.
B.Store the Blob Storage account key in Azure Key Vault and reference it in the indexer definition using a Key Vault secret URI.
C.Enable a managed identity for the Azure Cognitive Search service and grant it access to the Blob Storage container.
D.Configure the indexer to use the Azure Cognitive Search service's API key to authenticate to Blob Storage.
AnswerC

Using a managed identity for Azure Cognitive Search allows the indexer to authenticate to Blob Storage without storing credentials. You grant the managed identity the necessary role, such as Storage Blob Data Reader, on the storage account. This is a secure and recommended approach. The indexer can then use the managed identity to access the container. This eliminates the need for connection strings with keys.

Why this answer

A managed identity for Azure Cognitive Search is the correct approach because it allows the indexer to authenticate to Blob Storage without storing any credentials in the indexer definition. You assign the managed identity the appropriate role on the storage account. This is a secure, Azure-native method.

The other options either store credentials (SAS token or account key) or use the wrong key for authentication.

Exam trap

The trap here is assuming that Azure Key Vault can be directly integrated with Cognitive Search indexers to retrieve secrets at runtime.

51
MCQeasy

Your organization needs to monitor Azure AI services for unusual activity patterns that might indicate a security threat. Which Microsoft security solution should you use?

A.Microsoft Intune
B.Microsoft Defender XDR
C.Microsoft Purview
D.Microsoft Sentinel
AnswerD

Microsoft Sentinel is a cloud-native SIEM and SOAR platform that ingests logs from Azure AI services and applies analytics rules and machine learning to detect anomalous activity patterns, satisfying the requirement to monitor for unusual behaviour indicating a security threat.

Why this answer

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution. It is specifically designed to ingest logs from Azure AI services, apply analytics to detect unusual activity patterns, and generate alerts for potential security threats, making it the correct choice for monitoring AI services for security anomalies.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel with Microsoft Defender XDR, assuming that 'security monitoring' always falls under Defender, but Sentinel is the SIEM solution required for ingesting and analyzing logs from Azure AI services, while Defender XDR focuses on endpoint and identity protection.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution, focused on managing endpoints and enforcing compliance policies, not on monitoring cloud service activity for security threats. Option B is wrong because Microsoft Defender XDR (Extended Detection and Response) is designed to correlate signals across endpoints, email, and identities, but it does not natively ingest and analyze logs from Azure AI services for SIEM-style threat detection. Option C is wrong because Microsoft Purview is a data governance and compliance solution, primarily used for data cataloging, classification, and policy enforcement, not for real-time security monitoring or threat detection.

52
Multi-Selectmedium

You are managing an Azure AI solution that uses Azure OpenAI and Azure AI Search. You need to ensure that the solution can be deployed to multiple environments with different configurations while minimizing manual steps. Which two actions should you take? (Choose two.)

Select 2 answers
A.Store environment-specific values in a parameter file for each environment.
B.Manually create resources in the Azure portal for each environment.
C.Use a single hard-coded connection string for all environments.
D.Use Azure Policy to enforce naming conventions and tags after deployment.
E.Define the deployment as a Bicep module and reference it from environment-specific main files.
AnswersA, E

Parameter files allow you to separate environment-specific values such as SKU, location, and capacity from the template logic. By maintaining a parameter file per environment, you can deploy the same template repeatedly with the correct settings for development, test, and production without editing the template itself.

Why this answer

To deploy the same solution to multiple environments with minimal manual steps, you should parameterize environment-specific values using parameter files and modularize the deployment using Bicep modules referenced by environment-specific main files. This combination ensures consistency, reduces duplication, and allows automated, repeatable deployments across development, test, and production.

Exam trap

The trap here is focusing on post-deployment governance tools like Azure Policy or manual portal steps instead of the core infrastructure-as-code practices that actually automate and parameterize multi-environment deployments.

53
Multi-Selecthard

You are architecting an Azure AI solution that uses Azure AI Language to analyze text for sentiment and key phrases. The solution must handle bursts of up to 500 requests per second but average only 50 requests per second. You need to ensure cost efficiency while meeting performance requirements. Which THREE actions should you take?

Select 3 answers
A.Use Azure Queue Storage to buffer requests during spikes
B.Select the Free tier and implement queuing
C.Use the S0 pricing tier
D.Implement client-side throttling and retry logic
E.Deploy the service in multiple regions
AnswersA, C, D

Queue Storage decouples ingestion from processing, absorbing the 500 requests-per-second bursts so the Language service is called at a sustainable rate. This smooths spikes and avoids provisioning for peak throughput, keeping costs aligned with the 50 requests-per-second average.

Why this answer

Option A is correct because Azure Queue Storage decouples the request producers from the Azure AI Language service, buffering the burst of up to 500 requests per second so the service can process them at a sustainable rate rather than being overwhelmed. Option C is correct because the S0 (Standard) pricing tier is the paid tier that supports the throughput and quota needed for production workloads, whereas the Free tier is limited to 5,000 transactions per month at 20 transactions per minute, which cannot handle 50 requests per second on average. Option D is correct because client-side throttling and retry logic (for example, honoring HTTP 429 responses and using exponential backoff) prevents the application from exceeding the service's rate limits and gracefully handles transient throttling during spikes.

Option B is not correct because the Free tier's low transaction and rate limits make it unsuitable for this workload even with queuing. Option E is not correct because deploying in multiple regions increases cost and complexity without addressing the burst-handling and cost-efficiency requirements, since the service's per-region rate limits would still apply.

Exam trap

The trap here is that candidates often assume a higher pricing tier (like S0) alone can handle bursts, but without queuing and retry logic, the service will still throttle requests, leading to failures or the need for costly over-provisioning.

54
MCQhard

Your company is deploying an Azure AI solution that uses multiple AI services. You need to ensure that all API calls are authenticated securely using managed identities. Which of the following steps is required to enable managed identity authentication for an Azure AI service?

A.Enable system-assigned managed identity at the subscription level
B.Assign a managed identity to the Azure AI service and grant it the required RBAC role
C.Store the authentication key in Azure Key Vault and reference it in the application
D.Configure a shared access key in the Azure AI service
AnswerB

Managed identity authentication requires two elements: a managed identity assigned to the Azure AI resource, plus an RBAC role assignment granting that identity access to the target service. Without the role grant, token acquisition succeeds but authorisation fails.

Why this answer

Managed identity authentication for Azure AI services requires assigning either a system-assigned or user-assigned managed identity to the resource, and then granting that identity the appropriate RBAC role (e.g., Cognitive Services User) on the target AI service. This eliminates the need for keys or secrets in the code and leverages Azure AD tokens for secure, passwordless authentication.

Exam trap

The trap here is that candidates often confuse managed identity with key management solutions like Key Vault, or assume that enabling a managed identity at a higher scope (subscription) automatically applies to all resources, when in fact the identity must be explicitly assigned to each resource and granted RBAC permissions.

How to eliminate wrong answers

Option A is wrong because managed identities are assigned at the resource level, not the subscription level; enabling a system-assigned identity at the subscription scope is not a valid operation. Option C is wrong because storing the authentication key in Key Vault is a valid security practice but does not use managed identity authentication—it still relies on a static key, not an Azure AD token. Option D is wrong because shared access keys are the traditional key-based authentication method, which managed identities are designed to replace; configuring a shared access key does not enable managed identity authentication.

55
MCQhard

You are deploying an Azure AI solution that uses Azure AI Search. The solution must be able to access the search service from an Azure virtual network without traversing the public internet. You need to configure the search service to meet this requirement. What should you do?

A.Configure the search service to use an IP firewall and add the virtual network's public IP address.
B.Create a private endpoint for the search service and configure the virtual network to use it.
C.Deploy the search service with a public endpoint and use Azure Front Door to route traffic privately.
D.Enable a service endpoint for Azure AI Search on the virtual network subnet.
AnswerB

A private endpoint creates a network interface in your virtual network, allowing private connectivity to Azure AI Search. This enables access from within the virtual network without going over the public internet. You must also configure the search service to deny public access and allow the private endpoint. This satisfies the requirement for private network access.

Why this answer

To access Azure AI Search privately from a virtual network, you must use a private endpoint, which assigns a private IP address from your subnet to the search service. This ensures all traffic remains within the Azure backbone. Other options either use public internet or do not provide a private IP.

Exam trap

The trap here is assuming that service endpoints or IP firewalls provide private connectivity, when they actually still use public IP addresses.

56
MCQhard

You are responsible for an Azure AI solution that uses Custom Vision to classify manufacturing defects. The model must achieve high recall to avoid missing defects. The current model has high precision but low recall. Which action should you take?

A.Add more images of non-defective items to the training set
B.Increase the number of training iterations
C.Lower the probability threshold for the defect class
D.Increase the probability threshold for the defect class
AnswerC

Lowering the probability threshold classifies more samples as defects, raising recall by catching defects previously missed, at the cost of some precision. This directly addresses the high-precision, low-recall imbalance, prioritising detection of defects over avoiding false positives.

Why this answer

Lowering the probability threshold for the defect class means the model will classify an image as defective even when its confidence score is lower. This increases the number of true positives (defects caught), directly improving recall at the cost of potentially more false positives. In Custom Vision, the default probability threshold is 50%, and adjusting it downward is the standard technique to prioritize recall over precision.

Exam trap

The trap here is that candidates confuse precision and recall, often assuming that increasing the threshold (making the model stricter) will improve overall performance, when in fact it reduces recall by missing more defects.

How to eliminate wrong answers

Option A is wrong because adding more images of non-defective items would bias the model toward the non-defective class, likely reducing recall further by making the model more conservative in predicting defects. Option B is wrong because increasing the number of training iterations (epochs) primarily helps the model converge better on the training data but does not directly control the precision-recall trade-off; it may even lead to overfitting without improving recall. Option D is wrong because increasing the probability threshold for the defect class would require higher confidence to classify a defect, which reduces false positives but also reduces true positives, thereby lowering recall even further.

57
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You are building an AI solution that uses Azure AI Vision to analyze images. The solution must use managed identities to authenticate to the Vision resource. Which RBAC role should you assign to the managed identity?

A.Owner
B.Cognitive Services User
C.Reader
D.Contributor
AnswerB

Cognitive Services User grants data-plane access to call Azure AI Vision's analyse operations without granting key management or resource administration. Assigning it to the managed identity lets the solution authenticate to the Vision resource via Microsoft Entra ID, meeting the managed-identity constraint.

Why this answer

The Cognitive Services User role (B) is the correct RBAC role because it grants the minimum required permissions for a managed identity to call Azure AI Vision APIs (e.g., analyze image, OCR) without allowing any write or management operations. This role is specifically designed for accessing Azure Cognitive Services endpoints, and it aligns with the principle of least privilege for authentication via managed identities.

Exam trap

The trap here is that candidates often confuse the Reader role (which grants read access to the resource's Azure Resource Manager properties) with the ability to read data from the service, but Reader does not include data-plane permissions for Cognitive Services APIs.

How to eliminate wrong answers

Option A (Owner) is wrong because it grants full control over the Vision resource, including the ability to delete or modify the resource itself, which is excessive and violates security best practices for a managed identity that only needs to call APIs. Option C (Reader) is wrong because it only allows read access to the resource's metadata and configuration (e.g., viewing keys or endpoints) but does not grant permission to call the Vision API endpoints for image analysis. Option D (Contributor) is wrong because it allows creating and managing resources (e.g., deploying models or changing settings) but does not include the specific 'Cognitive Services User' data-plane permission required to authenticate and invoke the Vision API.

58
MCQeasy

You are planning an Azure AI solution that will use several Azure AI services, including Azure AI Vision and Azure AI Language. The solution must be deployed to multiple regions and must provide a single endpoint and key for all the services. Which Azure resource type should you create?

A.An Azure API Management instance with a backend for each service
B.An Azure Machine Learning workspace with online endpoints
C.An Azure AI services multi-service account
D.A separate Azure AI services resource for each service in each region
AnswerC

A multi-service account provides one endpoint and one key that can be used across supported Azure AI services such as Vision and Language. It also supports multi-region deployment by creating the account in each region while keeping a consistent management model. This directly satisfies the requirement for a single endpoint and key across several services.

Why this answer

A multi-service account is designed to expose several Azure AI services through one endpoint and one key. It supports deployment in multiple regions while keeping a consistent management and authentication model. Separate resources or an API Management layer would still leave you managing per-service credentials, so they do not satisfy the single-key requirement.

Exam trap

The trap here is confusing an API gateway such as API Management with a unified Azure AI services key, when the gateway still requires managing a separate credential for each backend.

59
Multi-Selecteasy

A company is planning to use Azure AI services. They require the ability to audit all API calls for compliance. Which THREE components should they enable?

Select 3 answers
A.Azure Monitor
B.Log Analytics workspace
C.Diagnostic settings for the AI service
D.Azure RBAC roles for the service
E.Managed identity for the service
AnswersA, B, C

Azure Monitor captures diagnostic logs and activity logs for Azure AI services, recording every API call with caller identity, timestamp and operation. Enabling diagnostic settings routes these logs to a Log Analytics workspace, satisfying the compliance requirement to audit all API calls. It also supports alerting on suspicious access patterns.

Why this answer

Azure Monitor (A) is correct because it is the platform that collects, stores, and surfaces activity and resource logs, enabling the audit trail of API calls required for compliance. A Log Analytics workspace (B) is correct because it is the destination where diagnostic logs are ingested and queried with KQL, allowing retention and analysis of all API call records. Diagnostic settings for the AI service (C) is correct because it is the mechanism that routes the service's resource logs (e.g., Audit, RequestResponse) and metrics to Azure Monitor/Log Analytics, which is what actually captures the API calls.

Azure RBAC roles (D) only control authorization to the resource and do not record API call history, and a managed identity (E) only provides an authentication credential for the service, so neither produces the audit data required.

Exam trap

The trap here is that candidates often confuse auditing (logging API calls) with security controls like RBAC or Managed Identity, mistakenly thinking that controlling access or identity automatically provides an audit trail, whereas auditing requires explicit diagnostic logging and a monitoring pipeline.

60
MCQhard

Your Azure AI Search index stores customer support tickets. You need to implement a search feature that returns semantically similar results even if the query uses different wording. Which configuration should you enable?

A.Use simple query parsing with searchMode=any
B.Add a synonym map with custom entries
C.Enable semantic search and configure a semantic configuration
D.Enable fuzzy search on the index
AnswerC

Semantic search applies a reranking model over results, using a semantic configuration that maps title, content and keyword fields. This lets queries match by meaning rather than exact terms, satisfying the requirement for semantically similar results despite different wording.

Why this answer

Semantic search in Azure AI Search uses deep neural networks to understand the intent and context of a query, returning results that are semantically similar even when the wording differs. By enabling semantic search and configuring a semantic configuration, you define which fields are used for summarization and ranking, which directly addresses the requirement for meaning-based matching rather than keyword matching.

Exam trap

The trap here is that candidates often confuse synonym maps (which handle predefined word equivalence) with semantic search (which handles contextual meaning), leading them to choose synonym maps when the question explicitly requires handling of different wording beyond simple synonyms.

How to eliminate wrong answers

Option A is wrong because simple query parsing with searchMode=any only controls how terms are combined (OR logic) and does not provide any semantic understanding or synonym expansion. Option B is wrong because a synonym map expands queries to include predefined equivalent terms, but it cannot handle novel or context-dependent paraphrasing that semantic search can. Option D is wrong because fuzzy search corrects for typos and minor spelling variations by using Levenshtein distance, but it does not capture semantic similarity between different words or phrases.

61
MCQeasy

You are deploying an Azure AI solution that uses Azure AI Language and Azure AI Vision. You need to ensure that the solution can be monitored for performance and health. You want to collect metrics and logs from these services and analyze them in a central location. What should you use?

A.Azure Resource Health
B.Azure Service Health
C.Azure Advisor
D.Azure Monitor
AnswerD

Azure Monitor is the centralized platform for collecting, analyzing, and acting on telemetry from Azure resources. It can collect metrics and logs from Azure AI Language and Azure AI Vision, and allows you to create alerts, dashboards, and queries using Log Analytics. This satisfies the requirement for centralized monitoring of performance and health.

Why this answer

Azure Monitor is the correct choice because it is the comprehensive monitoring solution for Azure resources. It can collect metrics and logs from Azure AI Language and Azure AI Vision, store them in Log Analytics, and enable analysis, alerting, and visualization. The other services provide health advisories or recommendations but do not offer centralized telemetry collection and analysis.

Exam trap

The trap here is confusing Azure Monitor with services like Azure Service Health or Azure Advisor, which provide health status and recommendations but do not collect resource-level metrics and logs for performance analysis.

62
Multi-Selecthard

You are managing an Azure AI services resource that is used by several departments. The security team requires that you monitor the resource for unusual access patterns and receive alerts when the number of failed authentication attempts exceeds a threshold. You need to configure the appropriate Azure Monitor components. Which two actions should you take? (Choose two.)

Select 2 answers
A.Enable Azure Defender for AI services to detect anomalies and generate security alerts.
B.Create a metric alert on the TotalCalls metric for the Azure AI services resource.
C.Configure a private endpoint for the Azure AI services resource to restrict access to a virtual network.
D.Create an alert rule in Azure Monitor that triggers when the count of failed authentication events in the Log Analytics workspace exceeds a threshold.
E.Enable diagnostic settings on the Azure AI services resource to send logs to a Log Analytics workspace.
AnswersD, E

After logs are in Log Analytics, you can create an alert rule that evaluates a log query periodically. The alert rule can count failed authentication events and trigger when the count exceeds your defined threshold. This directly fulfills the requirement to receive alerts on excessive failed authentication attempts. It is the action that turns the collected data into actionable notifications.

Why this answer

To monitor failed authentication attempts, you must first enable diagnostic settings to collect logs into a Log Analytics workspace. Then, you can create an alert rule that queries those logs and triggers when the count of failed authentication events exceeds a threshold. The other options either address network security, provide general threat detection, or use an unrelated metric, so they do not meet the specific monitoring and alerting requirement.

Exam trap

The trap here is assuming that enabling a private endpoint or Azure Defender automatically provides threshold-based alerts on failed authentication attempts, when they serve different security purposes.

63
MCQeasy

Your company is developing an AI-powered document processing solution using Azure AI Document Intelligence. The solution must extract data from scanned PDF forms. The forms are in a custom format not supported by prebuilt models. You have 10,000 labeled forms for training. The solution must be deployed in a region that supports Document Intelligence and must be accessible via a REST API. You need to ensure the solution can process forms with high accuracy. What should you do?

A.Use Azure AI Language to extract entities from the text
B.Train a custom extraction model using the labeled forms
C.Use a prebuilt model and map fields manually
D.Use the Read model and write custom logic to extract fields
AnswerB

Custom extraction models learn the layout and field patterns of your specific form type from labelled samples, which prebuilt models cannot handle. Training with 10,000 labelled forms yields the high accuracy the custom format demands, and the model is callable via REST API.

Why this answer

Azure AI Document Intelligence supports training custom extraction models using labeled forms, which is essential for handling custom form layouts not covered by prebuilt models. With 10,000 labeled forms, you have sufficient data to train a high-accuracy model that extracts specific fields via the REST API, meeting the deployment and accessibility requirements.

Exam trap

The trap here is that candidates may confuse Azure AI Language's entity extraction with Document Intelligence's form extraction, or assume that a prebuilt model can be adapted via manual mapping, when in reality custom training is mandatory for unsupported formats.

How to eliminate wrong answers

Option A is wrong because Azure AI Language is designed for text analytics and entity extraction from unstructured text, not for structured field extraction from scanned forms, and it cannot learn custom form layouts. Option C is wrong because prebuilt models are designed for standard form types (e.g., invoices, receipts) and cannot be manually mapped to extract fields from a custom format, leading to poor accuracy. Option D is wrong because the Read model only performs OCR (optical character recognition) to extract raw text and layout, requiring custom logic to identify and extract specific fields, which is error-prone and does not leverage the labeled training data for high accuracy.

64
MCQeasy

You are deploying a custom Azure AI Language question answering project. The solution must only answer questions based on a specific set of internal FAQ documents. Which data source type should you use when creating the project?

A.URLs or files containing FAQ content
B.Prebuilt model from Azure AI Language
C.Azure SQL Database with a QnA Maker schema
D.Azure Cognitive Search index
AnswerA

Custom question answering grounds answers strictly in supplied content, so URLs or files containing FAQ content constrain the knowledge base to those internal documents. This satisfies the requirement that responses derive only from the specified FAQ set, excluding general or external knowledge.

Why this answer

Azure AI Language custom question answering is designed to ingest structured FAQ content from URLs or files. When you create a custom project, selecting 'URLs or files containing FAQ content' as the data source type allows the service to automatically extract question-answer pairs from the provided documents, ensuring the solution only answers questions based on that specific set of internal FAQs.

Exam trap

The trap here is that candidates may confuse the data source types for creating a custom project with the broader integration options (like Cognitive Search or SQL), leading them to select a wrong option that is technically possible but not the correct data source type for the initial project creation.

How to eliminate wrong answers

Option B is wrong because a prebuilt model from Azure AI Language is a general-purpose, pretrained model that does not use your specific FAQ documents; it answers based on general knowledge, not your internal content. Option C is wrong because Azure SQL Database with a QnA Maker schema is a legacy approach from the deprecated QnA Maker service; Azure AI Language custom question answering does not support direct ingestion from a SQL database with that schema. Option D is wrong because an Azure Cognitive Search index is a separate search service that can be used as a custom answer source via the 'Custom question answering' feature, but it is not a data source type for creating the project itself; the project creation requires FAQ URLs or files as the initial data source.

65
Drag & Dropmedium

Drag and drop the steps to create a custom question answering project in Azure Language Service into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, create the Azure resource. Then access Language Studio, create the project, add QnA pairs, and finally train and deploy.

66
MCQeasy

You are planning to deploy an Azure AI solution that uses multiple Azure AI services. You need to monitor the solution for performance and operational issues. You want to collect metrics and logs from all the services and analyze them in a central location. What should you use?

A.Azure Advisor
B.Azure Monitor
C.Azure Service Health
D.Azure Cost Management
AnswerB

Azure Monitor collects metrics and logs from Azure resources, including Azure AI services. It provides a centralized platform to analyze and alert on performance and operational data. By using Azure Monitor, you can create dashboards, set up alerts, and query logs across multiple services, meeting the requirement for central monitoring.

Why this answer

Azure Monitor is the correct choice because it is the comprehensive monitoring solution for collecting and analyzing metrics and logs from Azure resources, including AI services. It enables centralized monitoring, alerting, and diagnostics, which are essential for maintaining the performance of a multi-service AI solution.

Exam trap

The trap here is confusing Azure Monitor with other Azure governance or advisory services that do not provide resource-level telemetry.

67
Multi-Selectmedium

Which TWO actions should you take when designing an Azure AI solution that uses Microsoft Foundry to ensure responsible AI practices?

Select 2 answers
A.Implement a human-in-the-loop review for critical decisions
B.Optimize the model for maximum throughput
C.Run an AI fairness assessment on the model
D.Store all training data indefinitely for auditability
E.Remove all explainability metrics to simplify the model
AnswersA, C

Human-in-the-loop review places a person in the decision path for high-impact outcomes, catching errors and harmful outputs before they affect users. This directly satisfies the responsible AI requirement by ensuring critical decisions receive human oversight rather than fully automated action.

Why this answer

Option A is correct because implementing a human-in-the-loop review for critical decisions ensures that high-impact or sensitive outcomes are validated by a person before action is taken, which is a core responsible AI safeguard against harmful or erroneous automated decisions. Option C is correct because running an AI fairness assessment on the model systematically evaluates performance across demographic groups and helps detect and mitigate bias, directly supporting Microsoft's responsible AI principles of fairness and inclusiveness. Option B does not belong because optimizing for maximum throughput is a performance and cost concern, not a responsible AI practice, and can even conflict with safety if it bypasses safeguards.

Option D does not belong because retaining all training data indefinitely raises privacy, data minimization, and compliance risks rather than promoting responsible AI. Option E does not belong because removing explainability metrics reduces transparency and accountability, which is the opposite of responsible AI design.

Exam trap

The trap is selecting performance or data-retention options that sound operationally beneficial but violate responsible AI principles — candidates must distinguish responsible AI practices (fairness, human oversight, transparency) from general engineering optimizations.

68
MCQmedium

A developer is building a chatbot using Azure Bot Service and Language Understanding (LUIS). The bot needs to handle multiple intents, including 'BookFlight', 'CancelFlight', and 'CheckWeather'. During testing, the bot frequently confuses 'BookFlight' and 'CancelFlight' intents. What is the most effective way to improve intent classification accuracy?

A.Reduce the number of intents by merging similar ones.
B.Increase the confidence threshold for intent predictions.
C.Add more entities to the utterances.
D.Add more varied training utterances for 'BookFlight' and 'CancelFlight' intents.
AnswerD

LUIS learns intent boundaries from labelled utterances, so adding varied, representative examples for BookFlight and CancelFlight sharpens the model's discrimination between them. This addresses the root cause: insufficient or overlapping training data for the confused intents.

Why this answer

Adding more varied training utterances for the 'BookFlight' and 'CancelFlight' intents directly addresses the root cause of confusion: insufficient or overlapping training data. LUIS relies on diverse utterance patterns to distinguish between semantically similar intents; increasing the quantity and variety of labeled examples improves the model's ability to learn discriminative features, thereby boosting classification accuracy.

Exam trap

The trap here is that candidates often confuse confidence thresholds with model improvement, thinking that raising the threshold will fix misclassifications, when in reality it only masks the problem by rejecting more utterances instead of improving the model's discriminative power.

How to eliminate wrong answers

Option A is wrong because merging similar intents would reduce the bot's functionality and is not a best practice for improving accuracy—it avoids the problem rather than fixing the model's discrimination. Option B is wrong because increasing the confidence threshold only filters out low-confidence predictions but does not improve the underlying model's ability to distinguish between intents; it may cause more utterances to be misclassified or rejected. Option C is wrong because entities are used to extract specific data from utterances, not to differentiate between intents; adding more entities does not help the model learn which intent an utterance belongs to.

69
MCQhard

You are designing a solution that uses Azure AI Vision to analyze images for moderation. The solution must detect adult content and identify text in images. You need to minimize latency and cost. Which approach should you recommend?

A.Call the Analyze Image API twice: once for adult content and once for OCR
B.Use the Computer Vision 3.2 API with the 'adult' and 'OCR' parameters
C.Call the Analyze Image API with the 'adult' and 'read' visual features
D.Use the Read API for text and the Content Moderator API for adult content
AnswerC

Requesting the 'adult' and 'read' visual features in a single Analyze Image call returns both moderation and OCR results together, avoiding a second request. This satisfies the latency and cost constraints by consolidating processing into one API transaction.

Why this answer

The Analyze Image API in Azure AI Vision supports multiple visual features in a single call, including 'adult' for adult content detection and 'read' for OCR (text extraction). This minimizes latency by avoiding multiple API calls and reduces cost since you are billed per API call, not per feature.

Exam trap

The trap here is that candidates may think separate API calls or older API versions (like Computer Vision 3.2) are required for different tasks, but the Analyze Image API supports multiple visual features in a single call, which is the most efficient approach.

How to eliminate wrong answers

Option A is wrong because calling the Analyze Image API twice doubles both latency and cost, as each call incurs a separate charge and network round-trip. Option B is wrong because the Computer Vision 3.2 API does not support an 'OCR' parameter; OCR is handled via the 'read' visual feature in the Analyze Image API or the dedicated Read API. Option D is wrong because using separate APIs (Read API for text and Content Moderator API for adult content) increases latency and cost due to multiple calls, and the Content Moderator API is a separate service that is not optimized for the same single-call efficiency as the Analyze Image API.

70
Matchingmedium

Match each Azure AI scenario to the appropriate service.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Computer Vision

Speech Translation

Form Recognizer

Text Analytics

QnA Maker

Why these pairings

Correct matches: Chatbot -> Bot Service, Image moderation -> Computer Vision, Sentiment -> Text Analytics. Common confusions include associating Bot Service with image tasks or mistaking Cognitive Search for text analytics.

71
MCQeasy

You are planning a new Azure AI solution that will use Azure AI Language, Azure AI Vision, and Azure OpenAI. The security team requires that all service credentials be managed centrally, rotated automatically, and never stored in source code or application configuration files. You need to configure the application to retrieve the endpoint and key for each service at runtime. What should you use?

A.Store the keys in an Azure Storage account table and retrieve them by using a shared access signature.
B.Store the keys in environment variables on each Azure App Service instance and read them by using the configuration API.
C.Store the keys in an Azure App Configuration store and load them on application startup by using the App Configuration provider.
D.Store the keys in Azure Key Vault and retrieve them at runtime by using the Azure Key Vault SDK with a managed identity.
AnswerD

Azure Key Vault stores secrets centrally and supports automatic rotation through versioning. A managed identity assigned to the application authenticates to Key Vault without embedded credentials, and the Azure Key Vault SDK retrieves the current secret version at runtime. This satisfies central management, rotation, and no secrets in code or configuration files for all three Azure AI services.

Why this answer

Central secret management with automatic rotation and credential-free access is provided by Azure Key Vault combined with managed identities. Retrieving secrets at runtime through the Key Vault SDK means no key material is ever written into source code or configuration files. The other options either store secrets in non-secret stores or rely on credentials that themselves must be protected.

Exam trap

The trap here is assuming any configuration service that can store strings is an acceptable secret store, when only Azure Key Vault provides the managed rotation and access control required for credentials.

72
MCQmedium

Your organization is migrating on-premises machine learning models to Azure. The models are used for real-time inference. You need to choose a service that provides managed endpoints with autoscaling and supports custom containers. Which service should you use?

A.Azure Machine Learning managed online endpoints
B.Azure Functions
C.Azure Kubernetes Service (AKS) with manual scaling
D.Azure AI Services custom vision
AnswerA

Azure Machine Learning managed online endpoints satisfy the real-time inference constraint by providing autoscaling managed endpoints that deploy custom containers. Unlike batch endpoints, which process asynchronous jobs, managed online endpoints expose a REST URI for low-latency scoring, and Microsoft Entra ID handles authentication, meeting the migration requirement without managing infrastructure.

Why this answer

Azure Machine Learning managed online endpoints are the correct choice because they provide fully managed, autoscaling endpoints specifically designed for real-time inference. They support custom container images, allowing you to deploy any model packaged as a Docker container, and handle traffic splitting, health checks, and scaling automatically without managing underlying infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Kubernetes Service (AKS) as the only option for custom containers, overlooking that Azure Machine Learning managed endpoints natively support custom containers with autoscaling, eliminating the operational burden of managing a Kubernetes cluster.

How to eliminate wrong answers

Option B (Azure Functions) is wrong because Azure Functions is a serverless compute service for event-driven, short-lived tasks, not optimized for real-time ML inference with custom containers; it lacks native autoscaling for ML workloads and does not provide managed endpoints with traffic splitting or model versioning. Option C (Azure Kubernetes Service with manual scaling) is wrong because while AKS can host custom containers, the requirement specifies 'managed endpoints with autoscaling'—manual scaling contradicts autoscaling, and AKS requires significant cluster management overhead, unlike the fully managed endpoint service. Option D (Azure AI Services custom vision) is wrong because Custom Vision is a pre-built AI service for image classification and object detection, not a general-purpose platform for deploying custom ML models with custom containers; it does not support arbitrary custom containers or managed endpoints for real-time inference.

73
MCQeasy

Your company uses Azure OpenAI Service to generate marketing content. You need to ensure that the generated content does not contain offensive language. Which feature should you enable?

A.Azure AI Content Safety filters.
B.Audit logging for all API calls.
C.Data encryption at rest.
D.Rate limiting on the endpoint.
AnswerA

Azure AI Content Safety filters run on both prompts and completions, scoring hate, violence, sexual and self-harm categories and blocking them. Enabling them enforces the requirement that generated marketing content must not contain offensive language, without altering the model itself.

Why this answer

Azure AI Content Safety filters are specifically designed to detect and block offensive, inappropriate, or harmful language in text and images. By enabling these filters on your Azure OpenAI Service deployment, you can configure severity thresholds for categories like hate, self-harm, sexual, and violence content, ensuring generated marketing content meets safety policies.

Exam trap

The trap here is that candidates confuse operational features like logging or rate limiting with content moderation, assuming any security-related setting can filter offensive language, when only Azure AI Content Safety provides the specific content filtering capability.

How to eliminate wrong answers

Option B is wrong because audit logging records API calls for monitoring and compliance but does not actively filter or block offensive content in responses. Option C is wrong because data encryption at rest protects stored data from unauthorized access but has no role in analyzing or moderating generated text for offensive language. Option D is wrong because rate limiting controls the number of requests per time period to prevent abuse or overload, not to inspect or filter the content of responses.

74
Multi-Selectmedium

Which TWO Azure AI services can be used together to build a solution that transcribes customer service calls and detects sentiment?

Select 2 answers
A.Azure AI Language (sentiment analysis)
B.Azure AI Speech (speech-to-text)
C.Azure AI Translator
D.Azure AI Speech (text-to-speech)
E.Azure AI Language (conversational language understanding)
AnswersA, B

Azure AI Language's sentiment analysis returns per-sentence and document-level scores, which suits transcribed call audio where emotion shifts mid-conversation. Combined with speech-to-text transcription, it satisfies the stem's requirement to detect sentiment across customer service calls, operating on the text output rather than the audio itself.

Why this answer

Azure AI Speech (option B) is correct because its speech-to-text capability transcribes the audio of customer service calls into text, which is the required first step for this solution. Azure AI Language (option A) is correct because its sentiment analysis feature evaluates the transcribed text and returns sentiment scores/labels (positive, negative, neutral, mixed), satisfying the detection requirement. Together, B feeds transcription output into A for sentiment evaluation.

Option C (Azure AI Translator) is not needed since the scenario does not require language translation. Option D (text-to-speech) is the reverse of what is needed—it synthesizes speech from text rather than transcribing calls. Option E (conversational language understanding) extracts intents and entities for conversational apps, not sentiment, so it does not fulfill the requirement.

Exam trap

The trap here is that candidates may confuse Azure AI Speech's text-to-speech with speech-to-text, or mistakenly think Azure AI Translator or conversational language understanding can perform sentiment analysis, when in fact only the specific sentiment analysis feature of Azure AI Language is designed for that task.

75
MCQmedium

You are deploying an Azure AI Services resource by using an ARM template as part of an automated pipeline. The template must create the resource, a key vault, and a role assignment that allows a specific managed identity to read the resource key from the key vault. The deployment fails with an authorization error when creating the role assignment. You need to resolve the failure. What should you do?

A.Assign the User Access Administrator role to the pipeline service principal at the target scope before the deployment.
B.Add the Contributor role to the pipeline service principal at the subscription scope.
C.Enable the key vault for template deployment and add the pipeline identity to the key vault access policy.
D.Change the template to use a system-assigned managed identity for the Azure AI Services resource instead of the key vault.
AnswerA

Creating role assignments requires the Microsoft.Authorization/roleAssignments/write permission, which is included in User Access Administrator or Owner. Granting that role to the pipeline identity at the deployment scope lets the ARM template create the role assignment successfully, resolving the authorization failure.

Why this answer

Role assignment creation is a privileged operation that requires permissions such as Microsoft.Authorization/roleAssignments/write, provided by Owner or User Access Administrator. Contributor and key vault access policies do not include that permission, so granting User Access Administrator to the pipeline identity at the target scope is what allows the template to complete.

Exam trap

The trap here is assuming Contributor is sufficient for every deployment action, when Contributor deliberately excludes the ability to grant access to others.

Page 1 of 2 · 149 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Plan Manage Azure Ai questions.