Courseiva

CCNA Plan Manage Azure Ai Questions

74 of 149 questions · Page 2/2 · Plan Manage Azure Ai topic · Answers revealed

76
MCQeasy

You are planning to deploy an Azure AI Services multi-service resource. You need to ensure that the resource can be used by applications running in an Azure Kubernetes Service (AKS) cluster without embedding keys in the application code. What should you do?

A.Store the Azure AI Services key in a Kubernetes secret and mount it as an environment variable in the application pods.
B.Configure Azure AD Pod Identity or Workload Identity for the AKS cluster and assign the Cognitive Services User role to the identity on the Azure AI Services resource.
C.Enable a system-assigned managed identity on the AKS cluster and assign the Cognitive Services User role to it on the Azure AI Services resource.
D.Use Azure Key Vault to store the Azure AI Services key and retrieve it at runtime by using the AKS cluster's managed identity.
AnswerB

Workload Identity (or the older Pod Identity) allows Kubernetes pods to use a managed identity to authenticate to Azure services. By assigning the Cognitive Services User role to that identity on the Azure AI Services resource, the application can obtain a token from Microsoft Entra ID and call the service without any keys. This meets the keyless requirement.

Why this answer

To enable keyless authentication for applications in AKS, you should use Azure AD Workload Identity (or Pod Identity) to associate a managed identity with the pods. That identity must be granted the Cognitive Services User role on the Azure AI Services resource. The application can then use DefaultAzureCredential to obtain a token and call the service without any keys.

Exam trap

The trap here is assuming that enabling a managed identity on the AKS cluster is enough, when in fact you must configure workload identity to make that identity available to the pods.

77
MCQhard

Refer to the exhibit. You are reviewing a content safety policy for an Azure AI Foundry deployment. The policy rate limits to 20 requests per minute. A user submits 50 requests in one minute. How many requests are allowed?

A.20
B.50
C.100
D.None, all are blocked.
AnswerA

The rate limit caps throughput at 20 requests per minute, so only the first 20 submissions are processed; the remaining 30 are rejected with HTTP 429 responses. This satisfies the policy's stated constraint directly, regardless of how many requests the user submits within that window.

Why this answer

The content safety policy enforces a rate limit of 20 requests per minute. When a user submits 50 requests in one minute, the rate limiter allows only the first 20 requests and blocks the remaining 30. This is a standard token-bucket or sliding-window rate-limiting behavior in Azure AI Foundry, where exceeding the limit results in HTTP 429 (Too Many Requests) for excess requests.

Exam trap

Microsoft often tests the misconception that exceeding a rate limit blocks all requests, when in fact the limit is a threshold that allows the first N requests and denies the rest.

How to eliminate wrong answers

Option B is wrong because it assumes all 50 requests are allowed, ignoring the explicit rate limit of 20 per minute. Option C is wrong because 100 is not related to any limit in the policy; it may confuse the rate limit with a burst or quota value. Option D is wrong because the policy does not block all requests; it allows up to the limit (20) and then blocks the excess.

78
Multi-Selecteasy

You are developing an Azure AI solution that uses pre-built models from Azure AI Vision to analyze images. The solution must be able to detect objects and read printed text. Which TWO capabilities should you use?

Select 2 answers
A.OCR (legacy)
B.Facial detection
C.Object detection
D.Image tagging
E.Read (OCR)
AnswersC, E

Object detection returns bounding boxes and labels for multiple objects within an image, directly satisfying the requirement to detect objects. Azure AI Vision's pre-built model provides this without training, meeting the scenario's use of standard capabilities.

Why this answer

Object detection (C) is correct because it is the Azure AI Vision pre-built capability that locates and classifies multiple objects within an image, returning bounding boxes and labels, which directly satisfies the requirement to detect objects. Read (OCR) (E) is correct because it is the modern Azure AI Vision OCR engine that extracts printed and handwritten text from images and documents, satisfying the requirement to read printed text. The legacy OCR (A) option is an older, deprecated recognition model with weaker accuracy and limited language support, so it is not the recommended choice for new solutions.

Facial detection (B) only returns face locations and attributes and does not detect general objects or read text, and image tagging (D) produces descriptive labels for the overall image rather than object locations or extracted text, so neither meets the stated requirements.

Exam trap

The trap here is that candidates often confuse Image Tagging (which only provides labels) with Object Detection (which provides both labels and spatial localization), and may mistakenly choose the legacy OCR API instead of the modern Read API for text extraction.

79
MCQhard

Your company uses Azure OpenAI Service to generate product descriptions. You need to ensure that the generated content does not include offensive language and adheres to responsible AI principles. What should you implement?

A.Enable customer-managed key encryption
B.Configure content filters in Azure OpenAI
C.Fine-tune the model with a curated dataset
D.Set usage limits and throttling
AnswerB

Configuring content filters in Azure OpenAI applies severity-based screening across hate, violence, sexual and self-harm categories on both prompts and completions, blocking offensive output before it reaches users. This directly satisfies the stem's requirement to prevent offensive language and uphold responsible AI principles, unlike prompt engineering or moderation applied after generation.

Why this answer

Content filters in Azure OpenAI allow you to define categories (e.g., hate, violence, self-harm) and severity levels (low, medium, high) to automatically block or flag offensive language in generated outputs. This directly enforces responsible AI principles by preventing harmful content from being surfaced to users, without requiring model retraining or encryption changes.

Exam trap

The trap here is that candidates often confuse data security controls (like encryption or throttling) with content safety controls, assuming any 'security' feature can filter offensive language, when in fact only purpose-built content filters can analyze and block harmful text in real time.

How to eliminate wrong answers

Option A is wrong because customer-managed key encryption (CMK) protects data at rest but does not inspect or filter the semantic content of model outputs for offensive language. Option C is wrong because fine-tuning with a curated dataset can reduce but not guarantee the absence of offensive outputs; it cannot dynamically block real-time content violations and requires ongoing dataset maintenance. Option D is wrong because usage limits and throttling control API request rates and quotas, not the quality or safety of the generated text.

80
MCQeasy

You are designing an Azure AI solution that uses Azure AI Language to analyze customer support transcripts. The solution must identify key phrases, detect sentiment, and extract custom entities specific to your product catalog. Which two Azure AI Language features should you enable?

A.PII Detection
B.Key Phrase Extraction
C.Summarization
D.Custom Entity Extraction
AnswerB, D

Key Phrase Extraction satisfies the requirement to identify key phrases within customer support transcripts. It returns salient noun phrases from unstructured text via the Microsoft Entra ID–authenticated Language resource, complementing sentiment analysis and custom entity extraction. It does not, however, cover sentiment or custom entities, so it is only one of the two features required.

Why this answer

Key Phrase Extraction (Option B) is correct because it identifies the main points and important terms in customer support transcripts, such as 'refund request' or 'account issue,' which directly supports analyzing the content. Custom Entity Extraction (Option D) is correct because it allows you to define and extract domain-specific entities from your product catalog, such as product names or model numbers, using a trained custom entity extraction model. Together, these two features enable both general insight extraction and tailored, product-specific data extraction from the transcripts.

Exam trap

Microsoft often tests the distinction between pre-built features (like Key Phrase Extraction) and custom features (like Custom Entity Extraction), and the trap here is that candidates may incorrectly choose Summarization or PII Detection because they sound relevant to 'analyzing transcripts,' but they do not fulfill the specific requirements of key phrase identification and custom entity extraction.

How to eliminate wrong answers

Option A is wrong because PII Detection is designed to identify and redact personally identifiable information (e.g., names, phone numbers, credit card numbers) for privacy compliance, not to analyze key phrases or extract custom product entities. Option C is wrong because Summarization generates a concise summary of the transcript's main points, which is useful for overview but does not perform key phrase identification or custom entity extraction as required by the question.

81
MCQeasy

You run the above Azure CLI command. What is the expected output?

A.The primary and secondary keys along with the endpoint
B.The primary and secondary keys
C.A list of endpoints for the service
D.An error because the command is incorrect
AnswerB

The Azure CLI command regenerates or lists the resource's access keys, so the output contains the primary and secondary keys. These credentials authenticate requests to the Azure AI service, matching the expected key pair returned by the operation.

Why this answer

The Azure CLI command `az cognitiveservices account keys list` retrieves only the primary and secondary API keys for the Cognitive Services account. The endpoint is not included in the output; it must be obtained separately using `az cognitiveservices account show`. Therefore, the expected output contains the primary key and secondary key only.

Exam trap

The trap is that candidates may assume `az cognitiveservices account keys list` returns the endpoint along with the keys, but it only returns the primary and secondary keys. The endpoint is obtained via `az cognitiveservices account show`.

How to eliminate wrong answers

Option A is wrong because the command does not return the endpoint; it only returns the keys. Option C is wrong because the command returns keys, not a list of endpoints. Option D is wrong because the command is syntactically correct and will execute successfully.

82
MCQeasy

You are planning a solution that uses Azure AI Language to analyze customer feedback from social media posts. The solution must: - Detect sentiment (positive, negative, neutral) for each post. - Extract key phrases. - Support English and Spanish languages. - Run asynchronously for a batch of 10,000 posts. - Use the least expensive option that meets requirements. What should you do?

A.Use the Azure AI Language service with the built-in sentiment analysis and key phrase extraction capabilities. Process posts in batches using the async API.
B.Build a custom text classification model in Azure AI Language to detect sentiment and extract key phrases.
C.Use the Azure AI Language service with the single-document API for each post.
D.Use Azure AI Translator to translate all posts to English, then use Azure AI Language for analysis.
AnswerA

The built-in sentiment analysis and key phrase extraction capabilities cover both required tasks and support English and Spanish. The async API handles the 10,000-post batch, and using built-in features avoids the higher cost of custom models.

Why this answer

Azure AI Language's built-in sentiment analysis and key phrase extraction natively support both English and Spanish, and the async batch API is designed for high-volume processing (e.g., 10,000 posts) at a lower cost than per-document calls. This approach meets all requirements without custom models or translation overhead.

Exam trap

The trap here is that candidates often assume custom models are required for multilingual support or that translation is necessary, when in fact Azure AI Language's built-in capabilities already cover English and Spanish natively.

How to eliminate wrong answers

Option B is wrong because building a custom text classification model is unnecessary and more expensive; the built-in capabilities already handle sentiment and key phrase extraction for the required languages. Option C is wrong because using the single-document API for each of 10,000 posts would incur higher costs and slower performance compared to the async batch API, which is designed for bulk processing. Option D is wrong because translating all posts to English adds unnecessary cost and latency, and Azure AI Language already supports Spanish natively for both sentiment analysis and key phrase extraction.

83
MCQeasy

You are planning to use Azure AI Vision to analyze images for a retail inventory management application. The solution must detect products on shelves and read expiration dates. Which two Azure AI Vision capabilities should you use?

A.Image Captioning
B.Object Detection
C.Face Detection
D.Optical Character Recognition (OCR)
AnswerB, D

Object Detection returns bounding boxes and labels for multiple distinct items within an image, which is what locating products on shelves requires. OCR reads text but cannot identify product instances, so object detection covers the shelf-detection half of the scenario.

Why this answer

Object Detection (B) is correct because it identifies and locates products on shelves by drawing bounding boxes around each detected item, which is essential for inventory tracking. Optical Character Recognition (OCR) (D) is correct because it extracts text from images, enabling the reading of expiration dates printed on product labels or packaging.

Exam trap

The trap here is that candidates may confuse Image Captioning with Object Detection, assuming a descriptive caption could identify products, or overlook OCR because they think expiration dates are purely numeric and can be handled by simpler methods, but Azure AI Vision's OCR is specifically designed for text extraction from images.

How to eliminate wrong answers

Option A is wrong because Image Captioning generates a natural language description of the entire image scene, not specific object locations or text extraction, so it cannot detect products on shelves or read expiration dates. Option C is wrong because Face Detection is designed to locate human faces in images, not products or text, and has no relevance to retail inventory management tasks.

84
MCQhard

Your Azure AI Search solution uses a custom skill to call an external API. The skill runs locally but fails when deployed to the search service. What is the most likely cause?

A.The skill's output field mappings are missing.
B.The skill's input field mappings are incorrect.
C.The indexer name is misspelled in the skillset.
D.The skill endpoint is not publicly accessible via HTTPS.
AnswerD

Custom skills execute server-side within Azure AI Search, so the external API must be reachable over public HTTPS; localhost or private endpoints work locally but fail once deployed. This satisfies the stem's deployment constraint, where the skill's endpoint becomes unreachable from the search service's network context.

Why this answer

When a custom skill runs locally but fails after deployment to Azure AI Search, the most common cause is that the skill's endpoint is not publicly accessible via HTTPS. Azure AI Search indexers execute skills in the cloud and must be able to reach the external API over the internet using a secure HTTPS connection; localhost or HTTP endpoints will fail.

Exam trap

The trap here is that candidates assume the skill logic is faulty (input/output mappings) rather than recognizing that the network connectivity and HTTPS requirement is the fundamental difference between local testing and cloud execution.

How to eliminate wrong answers

Option A is wrong because missing output field mappings would cause the skill to execute successfully but fail to write results to the index, not prevent the skill from running. Option B is wrong because incorrect input field mappings would cause the skill to receive wrong or missing data but would not prevent the skill from being invoked or the endpoint from being called. Option C is wrong because a misspelled indexer name would cause the indexer to fail to run, but the skillset itself would still be valid and the custom skill endpoint would be reachable; the error would occur at the indexer level, not the skill execution.

85
Multi-Selecteasy

Which TWO of the following are best practices for securing Azure AI services?

Select 2 answers
A.Expose endpoints publicly to simplify client access.
B.Disable diagnostic logging to reduce data exposure.
C.Enable diagnostic settings to audit usage and detect anomalies.
D.Share API keys among multiple applications for simplicity.
E.Use managed identities to authenticate to Azure AI services.
AnswersC, E

Enabling diagnostic settings streams resource logs and metrics to Log Analytics, Storage or Event Hubs, giving the audit trail needed to spot anomalous calls against your Azure AI services. This directly satisfies the stem's security-monitoring requirement, since usage auditing and anomaly detection depend on that telemetry being captured and retained.

Why this answer

Option C is correct because enabling diagnostic settings on Azure AI services streams resource logs and metrics to destinations such as Log Analytics, Azure Storage, or Event Hubs, which supports auditing usage, monitoring for anomalies, and meeting compliance requirements. Option E is correct because managed identities let applications authenticate to Azure AI services via Microsoft Entra ID tokens, eliminating the need to store or rotate API keys in code or configuration. Option A is incorrect since publicly exposing endpoints increases the attack surface; access should be restricted with private endpoints, network ACLs, or Azure Private Link.

Option B is incorrect because disabling diagnostic logging removes the audit trail needed to detect misuse and investigate incidents. Option D is incorrect because sharing API keys across applications prevents per-app revocation and least-privilege scoping, so keys should be unique, stored in Key Vault, and rotated regularly.

Exam trap

The trap here is that candidates may think exposing endpoints publicly is acceptable for simplicity (Option A) or that sharing API keys is harmless (Option D), but Azure's security model emphasizes least privilege and credential isolation.

86
Matchingmedium

Match each Azure AI service to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Build conversational AI bots

AI-powered cloud search

Extract information from documents

Analyze video and audio content

Monitor metrics and detect anomalies

Why these pairings

The correct matches pair each service with its primary function. Computer Vision analyzes images/videos; Language Service processes text; Speech Service handles audio; Cognitive Search provides AI search. Common confusions include swapping Speech with Computer Vision or Language with Cognitive Search.

87
MCQmedium

You are an Azure AI engineer at Fabrikam Inc. The company has developed a custom vision model using Azure Custom Vision to detect defects on a manufacturing assembly line. The model is deployed as a Docker container to an on-premises edge device using Azure IoT Edge. Recently, the model's inference accuracy has decreased. The operations team reports that the edge device is running low on memory and CPU. The model was trained with images from a specific camera angle, but the camera angle has been changed slightly due to maintenance. You need to improve the model's accuracy. What should you do?

A.Upgrade the edge device to have more memory and CPU.
B.Reduce the image resolution to lower memory usage.
C.Retrain the model with new images captured from the current camera angle.
D.Convert the model to use grayscale images.
AnswerC

The camera angle shift changed the input distribution, so the model now infers on images unlike its training data. Retraining with images captured from the current angle realigns the model with production input, addressing the accuracy drop at its source.

Why this answer

The decrease in accuracy is most likely due to the change in camera angle, which introduces a domain shift between the training images and the new inference images. Retraining the model with images captured from the current camera angle will realign the training data distribution with the production environment, directly addressing the root cause of the accuracy drop. This is a standard practice in Custom Vision when deployment conditions change.

Exam trap

The trap here is that candidates focus on the resource constraints (low memory/CPU) as the primary cause of accuracy loss, but the question explicitly states the camera angle changed, making retraining the only option that addresses the domain shift.

How to eliminate wrong answers

Option A is wrong because upgrading hardware (more memory/CPU) addresses resource constraints but does not fix the accuracy degradation caused by the camera angle change; the model's inference logic remains unchanged. Option B is wrong because reducing image resolution may lower memory usage but will likely further degrade accuracy by removing fine-grained defect details, and it does not correct the domain shift from the new camera angle. Option D is wrong because converting to grayscale discards color information that may be critical for defect detection (e.g., color-based anomalies), and it does not address the camera angle change.

88
MCQmedium

Refer to the exhibit. You are creating a Custom Vision project using the Azure AI Custom Vision API. The training data is stored in Azure Blob Storage with a SAS URI. The project creation fails with an authorization error. What is the most likely reason?

A.The domain 'general' is invalid
B.The exportModelContainerUri is missing
C.The SAS token is expired or has insufficient permissions
D.The project type 'Classification' is not supported
AnswerC

The Custom Vision API reads training images from the blob container using the supplied SAS URI. If that token has expired or lacks read and list permissions on the container, the project creation request fails authorisation, which matches the reported error exactly.

Why this answer

The Custom Vision project creation fails because the SAS URI used to access training data in Azure Blob Storage has an expired token or lacks sufficient permissions (e.g., read/list). Custom Vision requires a valid SAS token with at least read and list permissions to import images from the container. An expired or under-permissioned SAS token results in an authorization error when the service attempts to access the blob storage.

Exam trap

The trap here is that candidates may confuse a SAS authorization error with a missing container URI or an invalid domain, when in fact the SAS token's expiry or insufficient permissions is the direct cause of the 403 error during blob access.

How to eliminate wrong answers

Option A is wrong because 'general' is a valid and commonly used domain for Custom Vision projects; it is not invalid. Option B is wrong because exportModelContainerUri is only required when exporting a trained model to a container, not for project creation or importing training data. Option D is wrong because 'Classification' is a fully supported project type in Custom Vision; the error is authorization-related, not about unsupported project types.

89
MCQeasy

You are planning to use Azure AI Document Intelligence to process a large volume of mixed document types (invoices, receipts, and purchase orders). The solution must automatically classify each document type and extract relevant fields. What should you configure?

A.Use the Form Recognizer service with neural models
B.Create a custom classification model to identify document types, then use extraction models
C.Use prebuilt models for each document type and route based on filename
D.Use the Read model to extract all text and then use regular expressions to classify
AnswerB

A custom classification model is trained on labelled samples of invoices, receipts and purchase orders, so it identifies each document's type before routing. Extraction models then run per type, satisfying the requirement to classify automatically and pull the relevant fields from mixed documents.

Why this answer

Azure AI Document Intelligence (formerly Form Recognizer) requires a two-step process for mixed document types: first, a custom classification model identifies each document type (invoice, receipt, purchase order), then separate extraction models (custom or prebuilt) extract the relevant fields from each classified type. This approach ensures accurate routing and field extraction without relying on filenames or brittle regex patterns.

Exam trap

The trap here is that candidates assume a single model (like neural or prebuilt) can both classify and extract, but Azure AI Document Intelligence requires a separate classification step before extraction for mixed document types.

How to eliminate wrong answers

Option A is wrong because neural models are a type of extraction model (for improved accuracy on complex documents) but do not provide document-type classification; they cannot automatically distinguish between invoices, receipts, and purchase orders without a separate classifier. Option C is wrong because routing based on filename is unreliable and not a supported feature of Document Intelligence; filenames can be inconsistent or missing, and the service requires explicit classification logic. Option D is wrong because the Read model only extracts raw text and layout, not structured fields, and using regular expressions to classify document types is error-prone and not scalable for mixed document types with varying formats.

90
Multi-Selecthard

You are designing a solution that uses Azure AI Document Intelligence to extract data from invoices. The solution must handle high throughput and process documents in batch. Which TWO configuration options should you use?

Select 2 answers
A.Use the synchronous API for each invoice
B.Train a custom model for invoice extraction
C.Provision a standard (S0) tier Document Intelligence resource
D.Implement batch processing using the async document analysis API
E.Store output directly in Azure Blob Storage without API calls
AnswersC, D

Provisioning a standard (S0) tier resource satisfies the high-throughput requirement, since the free (F0) tier enforces strict request and page limits unsuitable for batch workloads. S0 removes those throttling caps, letting the batch pipeline submit many concurrent invoice analyses without hitting quota ceilings.

Why this answer

Option C is correct because the standard (S0) tier is the production-grade Document Intelligence pricing tier that supports high request volumes and higher transactions-per-second throughput, whereas the free (F0) tier is limited to low-volume testing and would throttle a high-throughput batch workload. Option D is correct because the asynchronous document analysis API (e.g., POST to /documentModels/{modelId}:analyze followed by polling the Operation-Location header) is specifically designed for large-scale, batch processing of many documents without blocking on each request, which is required for high throughput. Option A is wrong because the synchronous API processes one document per blocking call and does not scale well for batch, high-throughput scenarios.

Option B is wrong because training a custom model addresses extraction accuracy for specialized document layouts, not throughput or batch processing capability. Option E is wrong because storing output in Blob Storage without API calls bypasses Document Intelligence entirely, so no extraction would occur.

Exam trap

The trap here is that candidates often confuse the synchronous API (which is simpler but not scalable) with the async API (which is designed for batch and high throughput), and they may also overlook that the free tier (F0) cannot handle production-level batch loads.

91
MCQhard

You are an AI engineer at Contoso. Contoso has a Microsoft Copilot for Microsoft 365 deployment. They want to build a custom copilot in Microsoft Copilot Studio that can answer questions about their internal IT support knowledge base stored in a SharePoint Online document library. The knowledge base includes hundreds of PDF and Word documents. Requirements: - The copilot must only answer from the approved knowledge base documents. - Responses must be grounded in the documents and include citations. - The solution must use generative answers with a prebuilt AI model (no custom model training). - Authentication must be via Microsoft Entra ID with single sign-on (SSO). - The copilot should be published to a Microsoft Teams channel. You need to recommend the minimal configuration steps. What should you do?

A.Create a custom Azure AI Language model using the documents. Then build a bot with Azure Bot Service and connect it to Copilot Studio.
B.Use Power Virtual Agents to create a bot. Add a custom entity to map document content. Use Power Automate to retrieve documents.
C.Use Azure AI Search to index the documents. Create a custom connector in Copilot Studio to query the search index. Configure authentication and publish to Teams.
D.In Copilot Studio, create a new copilot. Add the SharePoint document library as a knowledge source. Configure authentication with Microsoft Entra ID. Enable generative answers. Publish to the Teams channel.
AnswerD

Adding the SharePoint library as a knowledge source with generative answers grounds responses in approved documents and returns citations, while Microsoft Entra ID authentication delivers SSO. No custom model training is needed, and Teams publishing meets the channel requirement.

Why this answer

The minimal configuration is to create a copilot in Copilot Studio, add the SharePoint document library as a knowledge source, configure authentication with Microsoft Entra ID, enable generative answers, and publish to Teams. This uses built-in capabilities, requires no custom model training, and meets all requirements including grounding with citations and SSO.

Exam trap

AI-102 often tests the misconception that custom AI models or Azure AI Search are required for document Q&A, but Copilot Studio's native SharePoint knowledge source provides a no-code solution.

How to eliminate wrong answers

Option A is wrong because it involves creating a custom Azure AI Language model and Azure Bot Service, which is overkill and not minimal; it also may not support generative answers with citations as required. Option B is wrong because Power Virtual Agents (now part of Copilot Studio) with custom entities and Power Automate is not the recommended approach for document-based generative answers; it lacks the native knowledge source integration. Option C is wrong because using Azure AI Search with a custom connector adds unnecessary complexity and does not leverage the built-in SharePoint knowledge source in Copilot Studio, which automatically handles indexing and citations.

92
MCQeasy

A company needs to implement a chatbot that answers customer queries using a knowledge base. Which Azure AI service should be used to build the knowledge base?

A.Azure AI Language (Question Answering)
B.Azure Bot Service
C.Azure AI Translator
D.Azure AI Speech
AnswerA

Azure AI Language's Question Answering feature builds a knowledge base from documents or FAQs and returns precise answers to natural-language queries, which the chatbot consumes. It directly satisfies the requirement to construct the knowledge base.

Why this answer

Azure AI Language's Question Answering feature is specifically designed to create a knowledge base from structured or unstructured content (e.g., FAQs, product manuals, support documents). It uses a custom question-answering model that can be trained and published as a REST API endpoint, which a chatbot can then query to retrieve precise answers. This makes it the correct service for building the knowledge base itself.

Exam trap

The trap here is that candidates often confuse the chatbot orchestration service (Azure Bot Service) with the knowledge base service itself, forgetting that the Bot Service is a host for the bot logic and channel integration, while the knowledge base must be built using a dedicated AI service like Question Answering.

How to eliminate wrong answers

Option B (Azure Bot Service) is wrong because it is a framework for building, deploying, and managing chatbots, not for creating or storing a knowledge base; it would consume a knowledge base built by another service. Option C (Azure AI Translator) is wrong because it provides real-time text translation between languages, not a question-answering knowledge base. Option D (Azure AI Speech) is wrong because it handles speech-to-text and text-to-speech capabilities, not the storage or retrieval of factual answers from a knowledge base.

93
MCQeasy

A team is building a chatbot using Azure Bot Service and Language Understanding (LUIS). The chatbot must handle multiple languages. What should you configure?

A.Configure a single LUIS app with multilingual utterances
B.Use Azure AI Search to index translated content
C.Use Azure Translator to translate utterances before calling LUIS
D.Create separate LUIS applications for each language
AnswerD

Separate LUIS applications per language satisfy the multilingual constraint because LUIS models are trained on a single language's utterances; a model cannot interpret intents across languages. Each app holds its own intents, entities and utterances, and the bot routes utterances to the matching app based on detected locale.

Why this answer

LUIS does not natively support multilingual models within a single app. Each LUIS application is designed for a single language, so to handle multiple languages, you must create separate LUIS apps—one per language—and route user utterances to the appropriate app based on the detected language. This ensures accurate intent and entity recognition tailored to each language's linguistic patterns.

Exam trap

The trap here is that candidates assume a single LUIS app can handle multiple languages by simply adding multilingual utterances, but LUIS explicitly requires separate apps per language because its models are language-specific and cannot generalize across languages.

How to eliminate wrong answers

Option A is wrong because a single LUIS app cannot be configured with multilingual utterances; LUIS apps are monolingual by design, and mixing languages in one app degrades prediction accuracy. Option B is wrong because Azure AI Search is a cognitive search service for indexing and querying content, not a tool for language detection or intent recognition in a chatbot; it does not replace the need for language-specific LUIS apps. Option C is wrong because while Azure Translator can translate utterances, translating before calling LUIS introduces latency, potential loss of nuance, and is not a recommended pattern—LUIS expects native-language utterances for optimal performance, and translation is better handled at the application layer if needed.

94
MCQeasy

You are planning to deploy an Azure AI solution that uses Azure Cognitive Services. You need to ensure that the solution can be deployed to multiple regions and that each region uses a separate endpoint. What should you do?

A.Deploy a single Cognitive Services account and enable the multi-region feature.
B.Deploy a single Cognitive Services account and use the same endpoint for all regions.
C.Deploy multiple Cognitive Services accounts, one per region, and configure the application to use the appropriate endpoint.
D.Deploy a single Cognitive Services account and use Azure Traffic Manager to route requests to different regions.
AnswerC

Each Cognitive Services account is created in a specific region and provides a unique endpoint. By deploying one account per region, you ensure that each region has its own endpoint, enabling regional isolation and compliance. The application can select the endpoint based on the user's location or other logic.

Why this answer

To have separate endpoints per region, you must deploy a Cognitive Services account in each region. Each account provides a unique endpoint and key. This approach also allows for regional failover if needed.

The application must be designed to select the correct endpoint based on the region.

Exam trap

The trap here is assuming that a single Cognitive Services account can serve multiple regions or that a feature like multi-region exists.

95
MCQhard

Your Azure AI Search indexer is failing to index documents from an Azure Blob Storage container. The error message shows 'AccessDenied'. What is the most likely cause?

A.The blob container name is misspelled in the datasource.
B.The indexer execution interval is set too high.
C.The search service's managed identity lacks 'Storage Blob Data Reader' role.
D.The index schema does not match the blob metadata.
AnswerC

Blob indexers authenticate to storage using the search service's managed identity. Without the Storage Blob Data Reader role assignment on the container or account, the indexer cannot read blobs, producing the AccessDenied error described in the stem.

Why this answer

The 'AccessDenied' error indicates that the Azure AI Search service lacks the necessary permissions to read data from the Azure Blob Storage container. The most likely fix is to assign the 'Storage Blob Data Reader' role to the search service's system-assigned managed identity, which grants read access to blob containers and their contents.

Exam trap

Microsoft often tests the distinction between authentication (who you are) and authorization (what you can do), leading candidates to confuse a missing role assignment with a configuration error like a misspelled container name or schema mismatch.

How to eliminate wrong answers

Option A is wrong because a misspelled container name would cause a 'ContainerNotFound' or 'InvalidContainerName' error, not an 'AccessDenied' error. Option B is wrong because the indexer execution interval affects scheduling, not authentication or authorization; a high interval would simply delay indexing, not cause an access denial. Option D is wrong because schema mismatches between the index and blob metadata result in indexing failures with errors like 'FieldNotFound' or 'CannotConvertValue', not 'AccessDenied'.

96
MCQmedium

You are deploying an Azure AI solution that uses Azure AI Search. The solution must be able to index data from an Azure SQL database and provide search results to an application. You need to ensure that the search service can access the database securely without storing credentials in the indexer definition. What should you do?

A.Configure the Azure AI Search service to use a managed identity and grant it access to the Azure SQL database.
B.Store the Azure SQL database connection string in Azure Key Vault and reference it in the indexer definition.
C.Use SQL authentication with a username and password, and encrypt the connection string using Azure AI Search's built-in encryption.
D.Configure the Azure SQL database to allow access from all Azure services and use a firewall rule.
AnswerA

By enabling a managed identity on the Azure AI Search service and granting that identity the appropriate permissions (such as db_datareader) on the Azure SQL database, you can avoid storing credentials in the indexer. The indexer can then use the managed identity to authenticate to the database, providing secure access without secrets.

Why this answer

Using a managed identity for the Azure AI Search service and granting it access to the Azure SQL database allows the indexer to authenticate without storing credentials. This is the most secure and recommended approach for service-to-service authentication in Azure.

Exam trap

The trap here is thinking that storing credentials in Key Vault eliminates the need for a managed identity, but the search service still requires an identity to access Key Vault, and the indexer would need to reference the secret, which is a form of credential storage.

97
Multi-Selecteasy

Which TWO Azure services are used together to build a custom question-answering solution?

Select 2 answers
A.Azure AI Language (Custom Question Answering)
B.Azure AI Computer Vision
C.Azure AI Speech
D.Azure AI Search
E.Azure AI Translator
AnswersA, D

Azure AI Language's Custom Question Answering feature holds the question-and-answer knowledge base, project, and trained model that matches user queries to answers. It satisfies the scenario by supplying the language understanding and answer-generation component of the custom question-answering solution.

Why this answer

Azure AI Language (Custom Question Answering) is correct because it provides the natural-language processing layer that ingests FAQ documents, URLs, and structured sources to create a knowledge base and returns precise answers to user questions. Azure AI Search is correct because it is the underlying retrieval engine that indexes the knowledge base content and performs the semantic/keyword search that Custom Question Answering relies on to match questions to answers. Together they form the standard architecture for a custom question-answering solution: AI Language builds and manages the knowledge base, while AI Search stores and queries the indexed content.

Azure AI Computer Vision is for image analysis (OCR, object detection), Azure AI Speech handles speech-to-text/text-to-speech, and Azure AI Translator performs language translation, none of which are required components for building the question-answering knowledge base and retrieval pipeline.

Exam trap

The trap here is that candidates often assume Azure AI Speech or Azure AI Translator are needed for a 'custom' solution, but the core requirement is a searchable knowledge base, which is provided by Azure AI Search, not by speech or translation services.

98
MCQeasy

A company wants to use Azure AI services to extract text from scanned PDF documents. Which Azure AI service should they use?

A.Azure AI Language Understanding (LUIS)
B.Azure AI Document Intelligence
C.Azure AI Computer Vision API
D.Azure Cognitive Search
AnswerB

Scanned PDFs contain images, not embedded text, so optical character recognition is required. Azure AI Document Intelligence's prebuilt read model performs OCR and layout extraction, returning text and structure from image-only documents, which satisfies the extraction requirement.

Why this answer

Azure AI Document Intelligence (formerly Form Recognizer) is the correct service because it is specifically designed for extracting text, tables, and key-value pairs from scanned PDFs and images using optical character recognition (OCR) and deep learning models. Unlike general OCR APIs, Document Intelligence can handle complex layouts and preserve document structure, making it ideal for this use case.

Exam trap

The trap here is that candidates often confuse the general-purpose Computer Vision OCR API with the specialized Document Intelligence service, overlooking that Document Intelligence offers superior layout understanding and prebuilt models for document-centric extraction tasks.

How to eliminate wrong answers

Option A is wrong because Azure AI Language Understanding (LUIS) is a conversational language understanding service for intent and entity extraction from natural language utterances, not for extracting text from scanned documents. Option C is wrong because while Azure AI Computer Vision API includes OCR capabilities, it is a general-purpose image analysis service that lacks the specialized layout analysis, table extraction, and form understanding features that Document Intelligence provides for scanned PDFs. Option D is wrong because Azure Cognitive Search is a search indexing and query service that can index extracted text but does not perform the initial extraction from scanned PDFs itself.

99
MCQeasy

You plan to use Azure AI Content Safety to detect hate speech in user-generated content. Which type of content safety is most appropriate for this scenario?

A.Custom categories
B.Image moderation
C.Prompt Shields
D.Text moderation
AnswerD

Text moderation analyses written user-generated content and returns severity scores for hate, violence, self-harm and sexual categories. This satisfies the stem's requirement to detect hate speech in text, unlike image moderation, which only classifies visual content.

Why this answer

Text moderation is the correct choice because Azure AI Content Safety's text moderation API is specifically designed to detect and filter hate speech, along with other harmful content categories like violence and self-harm, in user-generated text. It uses machine learning classifiers trained on a vast corpus to assign severity scores across predefined categories, making it the direct and most appropriate tool for this scenario.

Exam trap

The trap here is that candidates may confuse the broad 'text moderation' capability with the more specialized 'Prompt Shields' feature, mistakenly thinking prompt injection protection is the same as hate speech detection, or assume 'custom categories' are needed when the built-in hate category already suffices.

How to eliminate wrong answers

Option A is wrong because custom categories allow you to define your own specific terms or patterns for blocking, but they are not the primary or most appropriate method for detecting broad, nuanced hate speech; the service's built-in text moderation categories already cover hate speech comprehensively. Option B is wrong because image moderation is designed to analyze visual content for adult, racy, or violent imagery, not to detect hate speech in text. Option C is wrong because Prompt Shields are a feature of Azure AI Content Safety that protects against prompt injection attacks in generative AI applications, not for detecting hate speech in general user-generated content.

100
MCQmedium

A company is using Azure Form Recognizer to extract data from invoices. The prebuilt model does not correctly extract a custom field that is specific to the company's invoices. What is the most appropriate action to improve extraction accuracy for this field?

A.Use the prebuilt model with a custom field mapping.
B.Train a custom model using labeled invoices that include the custom field.
C.Adjust the confidence threshold for the prebuilt model.
D.Retrain the prebuilt model with additional invoices.
AnswerB

A custom model trained on labelled invoices teaches Form Recognizer the layout and semantics of the company-specific field, which the prebuilt invoice model cannot infer. Labelled samples supply the field's position and value patterns, directly improving extraction accuracy for that field.

Why this answer

The prebuilt Form Recognizer model is designed for common invoice layouts and may not recognize company-specific fields. Training a custom model with labeled invoices that include the custom field allows the model to learn the field's location and semantics, significantly improving extraction accuracy for that specific field.

Exam trap

The trap here is that candidates may think prebuilt models can be customized via mapping or retraining, but Azure Form Recognizer prebuilt models are immutable and only custom models can be trained to recognize new fields.

How to eliminate wrong answers

Option A is wrong because prebuilt models do not support custom field mapping; they extract only predefined fields based on their training data. Option C is wrong because adjusting the confidence threshold only filters results based on confidence scores, it does not teach the model to recognize a new field. Option D is wrong because prebuilt models cannot be retrained; they are fixed by Microsoft and only custom models can be trained with additional data.

101
MCQmedium

A healthcare organization uses Azure AI Language to extract medical entities from clinical notes. The solution must comply with HIPAA and data residency requirements. Which configuration is essential?

A.Enable diagnostic logging for all operations.
B.Use a customer-managed key (CMK) for encryption.
C.Enable private endpoint for the AI resource.
D.Create the AI resource in the required Azure region.
AnswerD

Data residency requires the Azure AI resource to reside in the mandated geography, because Azure AI Language processes and stores data in the resource's region. Creating the resource in the required region satisfies the residency constraint; HIPAA compliance is then addressed through the resulting regional deployment.

Why this answer

Data residency requirements dictate that the Azure AI Language resource must be physically located in the specific Azure region where the clinical notes and extracted medical entities are permitted to reside. Creating the resource in the required Azure region ensures that all data at rest and in transit stays within that geographic boundary, which is a fundamental compliance step for HIPAA and data residency. Other configurations like encryption keys or private endpoints enhance security but do not satisfy the core residency requirement.

Exam trap

The trap here is that candidates often confuse network-level security (private endpoints) or encryption controls (CMK) with data residency, assuming any security measure automatically satisfies geographic compliance requirements.

How to eliminate wrong answers

Option A is wrong because enabling diagnostic logging captures operational telemetry but does not enforce data residency or HIPAA compliance; it may even introduce additional data handling concerns. Option B is wrong because using a customer-managed key (CMK) controls encryption keys but does not control where the data is stored or processed; data residency is a separate requirement. Option C is wrong because enabling a private endpoint restricts network access to the AI resource via a VNet but does not change the physical region where the resource and its data reside.

102
MCQmedium

You are deploying an Azure AI solution that must process images stored in an Azure Blob Storage account. The solution uses the Computer Vision API and must be able to access the images without exposing storage account keys in code. You need to configure authentication. What should you do?

A.Store the storage account key in Azure Key Vault and retrieve it at runtime using the application's service principal.
B.Assign a managed identity to the Azure resource hosting the solution and grant it the Storage Blob Data Reader role on the storage account.
C.Use a shared access signature (SAS) token generated with the storage account key and embed it in the application configuration.
D.Enable anonymous read access on the blob container and configure the Computer Vision client to use the public URLs of the images.
AnswerB

Assigning a managed identity to the compute resource (e.g., Azure Function, VM) allows it to authenticate to Blob Storage without storing credentials. Granting the Storage Blob Data Reader role provides read access to blobs. This approach eliminates secrets in code and follows Azure security best practices for service-to-service authentication.

Why this answer

Using a managed identity with the appropriate RBAC role allows the solution to authenticate to Blob Storage without embedding secrets. The Storage Blob Data Reader role grants the necessary read access. This method is secure, requires no credential management, and aligns with Azure best practices for passwordless authentication.

Exam trap

The trap here is assuming that storing keys in Key Vault is as secure as using managed identities, but Key Vault still requires handling secrets at runtime.

103
Multi-Selecteasy

Which TWO Azure AI services can you use to implement a custom question-answering system?

Select 2 answers
A.Azure OpenAI Service
B.Azure AI Bot Service
C.Azure AI Translator
D.Azure AI Language
E.Azure AI Search
AnswersA, D

Azure OpenAI Service supports custom question answering by grounding a model on your own data, typically via the On Your Data feature or retrieval augmentation, returning generated answers rather than only extracted passages. This satisfies the requirement for a custom question-answering system.

Why this answer

Azure OpenAI Service (A) is correct because it lets you build a custom question-answering system by grounding a chat/completions model on your own data (e.g., via the On Your Data feature or by supplying retrieved context), enabling natural-language answers over proprietary content. Azure AI Language (D) is correct because it includes the Custom Question Answering feature (formerly QnA Maker), which builds a knowledge base from documents, URLs, and question-answer pairs and exposes it through a REST API for question answering. Azure AI Bot Service (B) is a framework for hosting and connecting conversational bots, not a question-answering knowledge service, so it does not itself implement custom Q&A.

Azure AI Translator (C) only performs text translation between languages and has no question-answering capability. Azure AI Search (E) is a search/indexing service that can retrieve relevant documents but does not generate or manage question-answer pairs on its own, so it is not one of the two services for implementing custom question answering.

Exam trap

The trap here is that candidates often confuse Azure AI Search (a retrieval service) with a full question-answering system, forgetting that it only returns raw documents or passages and does not generate natural language answers, which requires a language model like Azure OpenAI Service or the custom question-answering feature in Azure AI Language.

104
MCQeasy

Your chatbot uses Azure Bot Service and QnA Maker. Users can ask questions in natural language, and the bot returns answers from a knowledge base. Users report that the bot sometimes returns irrelevant answers. What should you do first?

A.Create multiple QnA Maker knowledge bases for different topics
B.Integrate LUIS to detect user intent
C.Use Azure AI Search to index the knowledge base
D.Review and edit the QnA pairs to add alternative phrasings
AnswerD

Editing QnA pairs to add alternative phrasings directly improves matching, because QnA Maker ranks answers by comparing the user's utterance against each question's stored wording. Irrelevant responses stem from weak lexical overlap, so enriching question variants raises confidence scores for the intended pair, satisfying the stem's requirement to fix irrelevant answers first.

Why this answer

The core issue is that the bot returns irrelevant answers because the QnA Maker knowledge base lacks sufficient alternative phrasings to match the variety of user questions. By reviewing and editing QnA pairs to add alternative phrasings, you directly improve the synonym and paraphrase coverage, which increases the confidence score for correct matches and reduces irrelevant responses. This is the first and most fundamental troubleshooting step before considering more complex integrations.

Exam trap

The trap here is that candidates often jump to integrating LUIS or Azure AI Search as a 'smart' fix, but the exam expects you to first optimize the existing QnA Maker knowledge base by enriching it with alternative phrasings, which is the simplest and most direct solution for irrelevant answers.

How to eliminate wrong answers

Option A is wrong because creating multiple knowledge bases for different topics does not address the root cause of irrelevant answers; it may fragment the knowledge and still fail to match varied phrasings within each topic. Option B is wrong because integrating LUIS for intent detection is an advanced enhancement that adds complexity and is not the first step; the problem is with QnA Maker's own matching logic, not with missing intent recognition. Option C is wrong because Azure AI Search is used for indexing and full-text search over large datasets, but QnA Maker already has its own ranking and matching engine; adding Azure AI Search would not fix the core issue of insufficient alternative phrasings in the QnA pairs.

105
MCQhard

You manage an Azure AI Search service that indexes legal documents. The search latency is high, and you need to improve query performance without reducing index size. Which action should you take?

A.Upgrade to a higher pricing tier
B.Increase the number of partitions
C.Reduce the number of searchable fields
D.Increase the number of replicas
AnswerD

Replicas serve query execution, so adding them distributes search load across more nodes and lowers latency while leaving index size untouched. Partitions would increase storage and index capacity instead, which the stem explicitly rules out.

Why this answer

Increasing the number of replicas distributes query load across multiple copies of the index, which directly improves query throughput and reduces latency. Replicas are designed for scaling query operations without changing the index size or storage capacity.

Exam trap

The trap here is that candidates often confuse partitions (which scale storage and indexing) with replicas (which scale query performance), leading them to incorrectly choose increasing partitions when the real need is to reduce query latency.

How to eliminate wrong answers

Option A is wrong because upgrading to a higher pricing tier increases both storage and compute capacity, but it is an overkill when the goal is specifically to improve query performance without reducing index size; partitions are the correct scaling unit for storage and indexing throughput. Option B is wrong because increasing the number of partitions improves indexing throughput and storage capacity, not query latency; partitions do not help with query concurrency or response time. Option C is wrong because reducing the number of searchable fields would shrink the index size, which violates the requirement to not reduce index size, and it may degrade search relevance rather than directly address query latency.

106
MCQeasy

You are deploying a chatbot using Azure AI Bot Service and Language Understanding (LUIS). The bot must understand user intent from free-text input. Which component should you train?

A.Language Understanding (LUIS) model
B.Speech-to-text model
C.QnA Maker knowledge base
D.Computer Vision model
AnswerA

LUIS is the component that maps free-text utterances to intents, so its model must be trained with example utterances and labelled intents. Azure AI Bot Service only orchestrates conversation; it performs no intent classification itself.

Why this answer

The Language Understanding (LUIS) model is the correct component to train because the bot needs to interpret free-text user input and extract intent. LUIS is a natural language processing service specifically designed for intent recognition and entity extraction from conversational phrases. Training the LUIS model with labeled utterances teaches it to map user expressions to predefined intents, enabling the bot to understand and respond appropriately.

Exam trap

The trap here is that candidates may confuse the role of LUIS with QnA Maker, assuming both handle any text input, but LUIS is for intent classification from free-text conversation, while QnA Maker is for retrieving answers from a fixed knowledge base, not for understanding dynamic user intents.

How to eliminate wrong answers

Option B is wrong because a Speech-to-text model converts audio to text, but the question specifies free-text input, not spoken input; training this model would be unnecessary and irrelevant for text-based intent understanding. Option C is wrong because QnA Maker knowledge base is designed for answering factual questions from a structured FAQ or document, not for understanding free-form intents from conversational input; it lacks the intent classification capability required here. Option D is wrong because a Computer Vision model processes images and video, not text; it has no role in interpreting user intent from free-text input.

107
MCQhard

You are planning to deploy an Azure AI solution that uses an Azure AI Services multi-service resource. The solution must be deployed across multiple Azure regions to provide high availability. You need to ensure that the solution can fail over automatically if one region becomes unavailable. What should you do?

A.Deploy the Azure AI Services resource in one region and configure a custom domain with multiple CNAME records.
B.Deploy the Azure AI Services resource in two regions and configure a Traffic Manager profile with priority routing.
C.Deploy the Azure AI Services resource in two regions and use Azure Front Door with session affinity enabled.
D.Deploy the Azure AI Services resource in one region and enable geo-redundant storage for the resource.
AnswerB

Traffic Manager with priority routing directs all traffic to the primary region and automatically fails over to the secondary region if the primary becomes unavailable. This provides high availability and automatic failover for the Azure AI Services resource across regions, meeting the requirement.

Why this answer

Deploying the resource in two regions and using Traffic Manager with priority routing ensures that traffic is directed to the primary region and automatically redirected to the secondary if the primary fails. This provides the required high availability and automatic failover. Other options either replicate data without failover or rely on DNS without health checks.

Exam trap

The trap here is assuming that data replication or DNS-based load balancing alone provides automatic failover, when health-checked routing such as Traffic Manager priority routing is needed for automatic region failover.

108
MCQmedium

You are designing an Azure AI solution that uses Language Understanding (LUIS) for intent detection. The solution must handle multiple languages dynamically based on the user's locale. What should you do?

A.Use Azure Translator to translate user input to English before sending to LUIS.
B.Create separate LUIS applications for each language and route based on locale.
C.Train a single LUIS app with utterances in all languages.
D.Enable the 'Multi-Language' feature in the LUIS app.
AnswerB

LUIS applications are language-specific, so a single app cannot serve multiple locales. Creating one app per language and routing by locale satisfies the dynamic multi-language constraint, since each app trains on its own language's utterances.

Why this answer

LUIS does not natively support multi-language within a single application; each LUIS app is designed for a single language. To handle multiple languages dynamically, you must create separate LUIS applications for each language and route user utterances based on the detected locale, ensuring accurate intent and entity recognition per language.

Exam trap

The trap here is that candidates assume LUIS has a built-in multi-language feature or that translation is a viable shortcut, but Microsoft explicitly requires separate LUIS apps per language and does not support multi-language training within a single app.

How to eliminate wrong answers

Option A is wrong because translating user input to English before sending to LUIS introduces translation latency, potential loss of nuance, and inaccuracies in intent detection, as LUIS is optimized for native language patterns. Option C is wrong because training a single LUIS app with utterances in multiple languages degrades performance, as LUIS expects consistent language structure and cannot distinguish between languages during prediction. Option D is wrong because there is no 'Multi-Language' feature in LUIS; the platform requires separate apps for each language, and enabling such a feature would not resolve the fundamental single-language limitation.

109
Multi-Selecthard

Which TWO of the following are best practices for managing Azure AI services costs?

Select 2 answers
A.Use the S0 pricing tier for production workloads
B.Always use the Free tier to avoid charges
C.Scale up partitions to improve performance
D.Increase batch size to reduce number of API calls
E.Set up budget alerts in Azure Cost Management
AnswersA, E

The S0 standard tier provides the throughput, SLA and feature set required for production workloads, avoiding the rate limits and lack of SLA that constrain the free F0 tier. This satisfies the production workload requirement.

Why this answer

Option A is correct because the S0 (Standard) tier is the production-grade pricing tier for Azure AI services, offering higher throughput, SLA-backed availability, and pay-as-you-go billing that lets you match capacity to actual usage rather than being capped by Free-tier limits. Option E is correct because configuring budget alerts in Azure Cost Management (Microsoft Cost Management + Billing) proactively notifies you when spending approaches or exceeds defined thresholds, enabling early corrective action before costs escalate. Option B is incorrect because the Free tier (F0) has strict transaction and rate limits and is intended only for trials and evaluation, not production workloads.

Option C is incorrect because scaling up partitions increases provisioned capacity and therefore cost, and it is a performance/scalability action rather than a cost-management best practice. Option D is incorrect because increasing batch size is a throughput optimization for supported batch APIs, not a general cost-control practice, and it does not reduce charges for services billed per transaction in the way implied.

Exam trap

The trap here is that candidates often confuse cost-saving strategies (like using the Free tier or batching) with best practices for managing costs in production, overlooking that the Free tier is not for production and that batching may not be applicable or effective for all services.

110
MCQmedium

Your organization is using Azure OpenAI Service to generate content. You need to ensure that the content meets safety guidelines by filtering harmful outputs. What should you configure?

A.Enable the Responsible AI dashboard.
B.Configure the content filters in the Azure OpenAI Studio.
C.Use Azure AI Content Safety APIs to analyze outputs.
D.Set the system message to instruct the model to avoid harmful content.
AnswerB

Content filters in Azure OpenAI Studio apply configurable severity thresholds across hate, violence, sexual and self-harm categories, blocking or annotating harmful model outputs. This satisfies the stem's safety requirement by enforcing filtering at the deployment level before responses reach users.

Why this answer

Content filters in Azure OpenAI Studio allow you to define severity levels (safe, low, medium, high) for categories like hate, sexual, violence, and self-harm, which are enforced at the inference API level to block or flag harmful outputs before they reach the user. This is the primary configuration for filtering model-generated content in Azure OpenAI Service.

Exam trap

The trap here is that candidates often confuse the Responsible AI dashboard (a monitoring tool) with active content filtering, or they assume that system messages alone are sufficient for safety, when in fact content filters provide the only guaranteed enforcement layer at the API level.

How to eliminate wrong answers

Option A is wrong because the Responsible AI dashboard is a monitoring and reporting tool that provides visibility into model behavior and fairness metrics, but it does not actively filter or block harmful outputs in real-time. Option C is wrong because Azure AI Content Safety APIs are a separate service for analyzing user-generated or third-party content, not for filtering outputs from Azure OpenAI models directly; they would require an additional integration layer. Option D is wrong because system messages are instructional prompts that guide model behavior but are not a reliable enforcement mechanism—they can be overridden by adversarial inputs or model quirks, and they lack the deterministic filtering capabilities of content filters.

111
MCQmedium

You need to create a solution that extracts key-value pairs from scanned invoices using Azure AI Document Intelligence. The invoices have varying layouts. Which model should you use?

A.Layout model
B.Custom extraction model
C.Read model
D.Prebuilt invoice model
AnswerD

The prebuilt invoice model returns structured key-value pairs for fields such as invoice date, vendor and total, handling the layout variance that custom templates cannot. It satisfies the stem's requirement to extract key-value pairs from scanned invoices without training, since Microsoft's pretrained model already covers common invoice schemas.

Why this answer

The Prebuilt invoice model (Option D) is specifically designed to extract key-value pairs, line items, and other structured fields from invoices, even when layouts vary. It is trained on thousands of invoice samples and uses deep learning to handle diverse formats without requiring custom training, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse the Layout model's ability to extract tables and text with the specific key-value pair extraction needed for invoices, leading them to choose Option A instead of the purpose-built Prebuilt invoice model.

How to eliminate wrong answers

Option A is wrong because the Layout model extracts text, tables, and selection marks but does not extract key-value pairs or invoice-specific fields like invoice number or vendor details. Option B is wrong because a Custom extraction model requires labeled training data and is overkill when a prebuilt model already exists for invoices; it is intended for documents not covered by prebuilt models. Option C is wrong because the Read model only extracts printed and handwritten text (OCR) without any structure or key-value pair extraction.

112
MCQeasy

You need to monitor the costs of your Azure AI services across multiple subscriptions. Which Azure tool should you use to track spending and set budgets?

A.Azure Cost Management
B.Azure Portal
C.Azure Monitor
D.Azure Advisor
AnswerA

Azure Cost Management aggregates spend across subscriptions and resource groups, letting you analyse costs and configure budgets with alerts. This satisfies the requirement to track spending for Azure AI services across multiple subscriptions in one place.

Why this answer

Azure Cost Management is the dedicated tool for monitoring, analyzing, and controlling cloud spending across multiple subscriptions. It provides cost analysis, budget creation, and alerting capabilities specifically designed for tracking Azure AI services costs at scale.

Exam trap

The trap here is that candidates often confuse Azure Monitor (which tracks resource metrics and logs) with cost monitoring, but Azure Monitor has no native capability to track financial spend or set budgets.

How to eliminate wrong answers

Option B is wrong because Azure Portal is the web-based management interface for provisioning and configuring resources, not a dedicated cost tracking and budgeting tool. Option C is wrong because Azure Monitor focuses on performance metrics, logs, and alerts for resource health and application diagnostics, not financial cost tracking. Option D is wrong because Azure Advisor provides best-practice recommendations for optimizing resource usage, security, and reliability, but it does not offer direct cost tracking or budget management features.

113
MCQeasy

You are planning to deploy an Azure AI solution that uses Azure AI Language to analyze text. The solution must be able to process a high volume of requests and provide a service-level agreement (SLA) for availability. You need to choose the appropriate pricing tier. What should you do?

A.Use the Free (F0) tier for each Azure AI Language resource to minimize costs.
B.Use the Standard (S) tier only for development and switch to Free (F0) for production to save costs.
C.Use multiple Free (F0) resources and load-balance requests across them.
D.Use the Standard (S) tier for the Azure AI Language resource.
AnswerD

The Standard tier supports high-volume requests, provides an SLA for availability, and is designed for production workloads. It allows you to scale as needed and ensures that the service meets performance requirements. This is the appropriate choice for a solution that must process many requests reliably.

Why this answer

The Standard tier is designed for production workloads, offering higher throughput limits and an SLA. The Free tier is for evaluation only and lacks an SLA. Therefore, the Standard tier is necessary to meet the high-volume and availability requirements.

Exam trap

The trap here is assuming that multiple Free tier resources can collectively meet production needs, but they do not provide an SLA and have per-resource limits.

114
MCQeasy

You are deploying an Azure AI solution that uses Azure Cognitive Services. You need to ensure that the API keys are stored securely and can be rotated automatically. What should you use?

A.Azure Key Vault
B.Azure Storage account with SAS tokens
C.Environment variables in Azure App Service
D.Azure App Configuration
AnswerA

Azure Key Vault securely stores secrets such as API keys and supports automated rotation through integration with Azure services. You can configure Key Vault to manage the lifecycle of keys and rotate them on a schedule or on-demand. This meets the requirement for secure storage and automatic rotation.

Why this answer

Azure Key Vault is the correct choice because it provides secure storage for secrets and supports automated rotation. It integrates with other Azure services and allows you to manage keys centrally. The other options do not offer the same level of security and rotation capabilities.

Exam trap

The trap here is assuming App Configuration can securely store secrets; it is meant for non-sensitive configuration data.

115
MCQhard

You deploy a Custom Vision object detection model to classify vehicles. The model works well in good lighting but fails in low-light conditions. What is the most appropriate action?

A.Add images with different lighting conditions to the training set
B.Increase the probability threshold
C.Increase the number of training iterations
D.Use a domain-specific model for vehicles
AnswerA

Low-light failure is a data coverage gap, not a model or deployment fault. Custom Vision learns only from labelled examples, so adding images captured under varied lighting lets the detector learn illumination-invariant features. This directly satisfies the stem's constraint of poor performance in low-light conditions.

Why this answer

The core issue is a data distribution mismatch: the model was trained primarily on well-lit images and lacks exposure to low-light examples. Adding images with diverse lighting conditions directly addresses this by enriching the training dataset, enabling the model to learn robust features for low-light scenarios. This aligns with the fundamental principle that Custom Vision models are only as good as the training data they receive.

Exam trap

The trap here is that candidates often confuse model performance tuning (threshold, iterations) with data quality issues, mistakenly believing that adjusting hyperparameters can compensate for missing training scenarios.

How to eliminate wrong answers

Option B is wrong because increasing the probability threshold only adjusts the confidence level required to return a prediction; it does not improve the model's ability to detect objects in low light, and may actually reduce recall by filtering out correct but lower-confidence detections. Option C is wrong because increasing the number of training iterations (epochs) on the same dataset does not introduce new visual patterns; it risks overfitting to the existing well-lit images without addressing the low-light deficiency. Option D is wrong because domain-specific models in Custom Vision are pre-trained on generic vehicle images and do not inherently compensate for lighting variations; the problem is not the domain but the lack of representative lighting conditions in the training set.

116
MCQmedium

You are a security engineer for a financial services company. The company uses Azure AI Language to analyze customer communications for compliance. The solution processes sensitive personal data. You need to ensure that all data transmitted to the Azure AI Language service is encrypted in transit and that the service endpoint is not accessible from the public internet. Additionally, you must use Microsoft Entra ID for authentication. The current implementation uses API keys and the public endpoint. You need to reconfigure the solution. What should you do?

A.Configure a private endpoint and continue using the public endpoint for redundancy
B.Disable the public network access without configuring a private endpoint
C.Enable Microsoft Entra ID authentication but keep the public endpoint and API keys
D.Disable the public network access, configure a private endpoint, enable managed identity, and enforce HTTPS
AnswerD

Disabling public network access with a private endpoint removes the service from the public internet, satisfying the private connectivity constraint. Enabling managed identity replaces API keys with Microsoft Entra ID authentication, while enforced HTTPS guarantees encryption in transit for sensitive personal data.

Why this answer

It addresses all three requirements: disabling public network access removes internet exposure, configuring a private endpoint ensures traffic stays within the Azure backbone and your virtual network, enabling managed identity allows Microsoft Entra ID authentication without API keys, and enforcing HTTPS guarantees encryption in transit via TLS. This combination fully secures the Azure AI Language service for sensitive personal data.

Exam trap

The trap here is that candidates may think disabling public network access alone is sufficient (Option B), but without a private endpoint, the service becomes unreachable, and they may overlook that managed identity is required to replace API keys for Microsoft Entra ID authentication.

How to eliminate wrong answers

Option A is wrong because continuing to use the public endpoint for redundancy still exposes the service to the public internet, violating the requirement that the endpoint not be accessible from the public internet. Option B is wrong because disabling public network access without a private endpoint leaves no way to connect to the service, as the service would be unreachable. Option C is wrong because keeping the public endpoint and API keys fails to restrict public internet access and does not eliminate the use of API keys, contradicting the requirement to use Microsoft Entra ID authentication exclusively.

117
MCQmedium

You are deploying an Azure AI solution that uses Azure OpenAI Service and Azure AI Language. The solution must ensure that each service has its own managed identity and that access to keys is restricted. You need to configure authentication for the services. What should you do?

A.Configure the services to use API keys stored in Azure App Configuration and enable Azure AD authentication for the application.
B.Use Azure AD service principals with client secrets for each service and store the secrets in Azure Key Vault.
C.Store the service keys in Azure Key Vault and configure the application to retrieve them at runtime using the Azure SDK.
D.Enable managed identities for each Azure AI service and grant them access to Azure Key Vault.
AnswerD

Each Azure AI service can have a system-assigned or user-assigned managed identity. By enabling managed identities and granting them access to Key Vault, you avoid storing credentials in code and can securely retrieve secrets. This aligns with least privilege and Azure best practices for authentication.

Why this answer

Managed identities provide an identity for the service in Azure AD, allowing it to authenticate to resources like Key Vault without storing credentials. Granting each service's managed identity access to Key Vault ensures secure retrieval of secrets and aligns with the principle of least privilege. Other options either rely on shared secrets or do not provide per-service identities.

Exam trap

The trap here is confusing managed identities with service principals or assuming that storing keys in Key Vault alone satisfies the requirement for per-service identities.

118
MCQhard

A healthcare company is using Azure AI Document Intelligence to extract patient data from forms. They need to ensure that all extracted data is encrypted at rest using a customer-managed key (CMK) and that the service endpoint is restricted to a specific virtual network. Which combination of steps should they take?

A.Use a service endpoint and configure a managed identity
B.Disable public network access and enable CMK via Azure Key Vault
C.Configure IP firewall rules and enable CMK via Azure Key Vault
D.Create a private endpoint and associate a customer-managed key in the resource encryption settings
AnswerD

A private endpoint restricts the Document Intelligence endpoint to a specific virtual network, while associating a customer-managed key in the resource's encryption settings enforces CMK encryption at rest. Together these satisfy both the network isolation and key management constraints in the stem.

Why this answer

It combines a private endpoint (which restricts the service endpoint to a specific virtual network by providing a private IP address within that VNet, eliminating public internet exposure) with a customer-managed key (CMK) in the resource encryption settings, which ensures data at rest is encrypted using a key stored in Azure Key Vault that the customer controls. This directly meets both requirements: network isolation via private endpoint and CMK-based encryption at rest.

Exam trap

The trap here is that candidates often confuse 'service endpoint' or 'IP firewall rules' with 'private endpoint' for VNet-specific access, but only a private endpoint provides a fully private IP within the VNet and meets the 'restricted to a specific virtual network' requirement, while the other options either allow public exposure or do not enforce VNet-level isolation.

How to eliminate wrong answers

Option A is wrong because using a service endpoint with a managed identity only secures network access at the subnet level and provides identity-based authentication, but it does not restrict the endpoint to a specific virtual network in the same way a private endpoint does, and it does not enable CMK for encryption at rest. Option B is wrong because disabling public network access alone does not restrict access to a specific virtual network; it only blocks all public traffic, and while enabling CMK via Azure Key Vault is correct for encryption, the network requirement is not met. Option C is wrong because configuring IP firewall rules only restricts access based on source IP addresses, not to a specific virtual network, and while CMK via Azure Key Vault is correct, the network isolation is insufficient for a VNet-specific restriction.

119
MCQmedium

You are building an Azure AI solution that uses Azure OpenAI Service to generate text. You need to ensure that the solution can handle up to 10,000 requests per minute. You also need to monitor the usage and set up alerts when the request rate exceeds 80% of the quota. What should you do?

A.Configure autoscaling for the Azure OpenAI Service in the Azure portal and set up alerts using Azure Service Health.
B.Create a deployment in Azure OpenAI Service with a high tokens-per-minute (TPM) quota and configure Azure Monitor alerts on the Azure OpenAI resource metrics.
C.Deploy multiple Azure OpenAI resources in different regions and use Azure Front Door to load-balance requests.
D.Use Azure API Management to throttle requests to the Azure OpenAI Service and configure Application Insights for monitoring.
AnswerB

Azure OpenAI Service deployments have quota limits measured in tokens per minute (TPM). To handle high request rates, you need to request a quota increase and deploy a model with sufficient TPM. Azure Monitor can track metrics such as total calls and token usage. You can create alert rules based on these metrics to notify when usage approaches the quota. This approach directly addresses both capacity and monitoring.

Why this answer

To handle high request rates, you must ensure the Azure OpenAI deployment has a sufficient tokens-per-minute quota. You can request a quota increase and deploy a model with adequate TPM. Azure Monitor can track metrics like total calls and token usage, and you can create alert rules to notify when usage exceeds a threshold.

The other options do not directly address quota management and monitoring of the service.

Exam trap

The trap here is assuming that Azure OpenAI Service supports autoscaling like other Azure services, when in fact quotas are fixed and require manual increases.

120
MCQhard

You are using Azure AI Language's conversational language understanding (CLU). The above JSON is a request to a CLU endpoint. What is the purpose of this request?

A.To predict the intent and entities from the user utterance
B.To query a knowledge base for answers
C.To deploy the CLU model to production
D.To train a new CLU model
AnswerA

The request body supplies a user utterance to the CLU prediction endpoint, which returns the top-scoring intent plus any extracted entities. This satisfies the scenario's need to interpret a conversational input, since CLU's runtime API performs intent classification and entity extraction in a single call.

Why this answer

The JSON request is sent to the Azure AI Language CLU endpoint with a 'query' field containing the user utterance. The 'kind' field is set to 'Conversation', which triggers the CLU runtime to analyze the utterance against the deployed model. The purpose is to return a prediction of the top intent and any extracted entities, which is the core function of a conversational language understanding endpoint.

Exam trap

The trap here is that candidates confuse the CLU prediction endpoint with the training or deployment endpoints, mistakenly thinking a request with a 'query' field is used for model management rather than runtime inference.

How to eliminate wrong answers

Option B is wrong because querying a knowledge base for answers is the purpose of Azure AI Language's custom question answering (QnA Maker) or Azure Cognitive Search, not CLU. Option C is wrong because deploying a CLU model is a separate operation performed via the Azure portal, REST API (e.g., PUT on the deployment resource), or SDK; this request is a prediction call, not a deployment action. Option D is wrong because training a new CLU model requires a training API call (e.g., POST to the /train endpoint with a training dataset), not a prediction request to the runtime endpoint.

121
MCQhard

Your Azure AI Search index contains millions of documents. Users report that search results are slow for complex queries. You need to improve query performance without reducing result quality. Which action should you take?

A.Reduce the maximum number of results returned per query
B.Increase the number of replicas
C.Remove all facet fields from the index
D.Disable complex query types such as fuzzy and regex
AnswerB

Adding replicas increases the number of copies of the index that serve queries, distributing concurrent search load and reducing latency. This satisfies the stem's constraint of improving complex query performance without altering analysers, scoring profiles or result quality.

Why this answer

Increasing the number of replicas in Azure AI Search distributes query load across multiple copies of the index, enabling parallel processing of complex queries. This directly improves query throughput and latency without altering the index schema or reducing result quality, as replicas provide dedicated resources for query execution.

Exam trap

The trap here is that candidates confuse replicas (which improve query performance and availability) with partitions (which improve indexing speed and storage capacity), leading them to choose options that degrade functionality instead of scaling resources.

How to eliminate wrong answers

Option A is wrong because reducing the maximum number of results per query (e.g., via $top) only limits the response payload and does not address the underlying computational cost of complex queries; it can also degrade user experience by hiding relevant results. Option C is wrong because removing facet fields eliminates aggregation capabilities and does not improve query performance—facets are computed during indexing, not at query time, and their removal would reduce result quality by removing navigation aids. Option D is wrong because disabling complex query types (fuzzy, regex) restricts search functionality and may reduce result relevance; while these queries are resource-intensive, the correct approach is to scale out via replicas rather than sacrifice search capabilities.

122
MCQeasy

You are implementing a chatbot using Microsoft Copilot Studio that helps employees find company policies. The chatbot must: - Use generative answers based on a SharePoint Online site. - Only respond with information from approved policy documents. - Include citations in responses. - Be accessible from Microsoft Teams. - Require no custom code. What should you do?

A.Use Power Automate to retrieve documents and feed them to Azure OpenAI. Build a custom connector for Teams.
B.In Copilot Studio, create a new copilot. Add the SharePoint site as a knowledge source. Enable generative answers with citations. Publish to Teams.
C.Build a bot using Azure Bot Service and QnA Maker. Train it with the policy documents. Deploy to Teams.
D.Create a custom GPT in Azure OpenAI Studio. Upload the policy documents. Deploy via Azure API Management and expose to Teams.
AnswerB

Adding the SharePoint site as a knowledge source with generative answers and citations enabled restricts responses to approved policy documents, and publishing to Teams delivers the required channel. No custom code is needed, meeting every stated constraint.

Why this answer

Microsoft Copilot Studio natively supports adding a SharePoint Online site as a knowledge source, enabling generative answers that retrieve and cite only approved policy documents. It requires no custom code, automatically includes citations in responses, and can be published directly to Microsoft Teams, fulfilling all stated requirements.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Azure OpenAI or Azure Bot Service options, missing that Copilot Studio is the no-code, fully integrated tool designed specifically for this scenario with built-in SharePoint knowledge sources, citations, and Teams deployment.

How to eliminate wrong answers

Option A is wrong because it requires custom code (Power Automate flow, custom connector) and Azure OpenAI, which violates the 'no custom code' requirement and adds unnecessary complexity. Option C is wrong because QnA Maker is deprecated and does not support generative answers with citations from SharePoint; it also requires manual training and custom deployment to Teams. Option D is wrong because creating a custom GPT in Azure OpenAI Studio and deploying via Azure API Management involves custom code and infrastructure management, contradicting the 'no custom code' and 'accessible from Teams' requirements without additional integration.

123
Multi-Selecthard

Which THREE factors should you consider when choosing between Azure AI Document Intelligence prebuilt models and custom models for invoice processing?

Select 3 answers
A.Both model types can be deployed on-premises.
B.Prebuilt models require no training data.
C.Prebuilt models are always less accurate than custom models.
D.Custom models require a large set of labeled training invoices.
E.Custom models can handle non-standard invoice layouts.
AnswersB, D, E

Prebuilt models are trained by Microsoft on large document corpora, so you supply no labelled samples and can call them immediately. This removes data collection and training effort, a decisive factor when your documents match the supported schema and you need fast deployment.

Why this answer

Option B is correct because Azure AI Document Intelligence prebuilt invoice models are pretrained by Microsoft and can be invoked immediately without supplying any labeled training data, which is ideal when you want fast time-to-value on standard invoices. Option D is correct because custom models (template or neural) are trained on your own labeled invoice samples, and although the exact count varies by model type, a meaningful set of labeled invoices is required to teach the model your specific fields and layouts. Option E is correct because custom models are specifically designed to handle non-standard, supplier-specific, or unusual invoice layouts that prebuilt models may not parse accurately.

Option A is not correct because these are Azure cloud services accessed via the Document Intelligence endpoint/API, not on-premises deployable models. Option C is not correct because prebuilt models are not always less accurate than custom models; for standard invoice formats they can perform very well, and accuracy depends on the document set and training quality.

Exam trap

The trap here is that candidates assume prebuilt models are always less accurate than custom models, but accuracy depends on the document's similarity to the training data; prebuilt models can outperform custom ones on standard layouts, especially when training data is limited.

124
MCQmedium

Your company uses Azure AI Vision to analyze images. You receive an alert that the number of 429 (Too Many Requests) errors has increased significantly. What is the most likely cause?

A.The endpoint URL is incorrect.
B.The API key has expired.
C.The service principal does not have the correct role assignment.
D.The application is exceeding the transactions-per-second (TPS) limit.
AnswerD

Exceeding the transactions-per-second limit directly triggers HTTP 429 responses, since Azure AI Vision throttles requests once the assigned TPS quota is surpassed. The stem's surge in Too Many Requests errors therefore points to throughput saturation rather than authentication or payload faults. Raising the tier or implementing retry-after backoff resolves it.

Why this answer

HTTP 429 (Too Many Requests) is a rate-limiting response from Azure AI Vision when the client exceeds the allowed transactions-per-second (TPS) for the chosen pricing tier. The alert indicates the application is sending requests faster than the service's capacity, triggering throttling to protect backend resources.

Exam trap

The trap here is confusing HTTP 429 with authentication or authorization errors (401/403), leading candidates to incorrectly select options about API keys or role assignments when the real issue is rate limiting.

How to eliminate wrong answers

Option A is wrong because an incorrect endpoint URL would produce a 404 Not Found or connection error, not a 429 rate-limit error. Option B is wrong because an expired API key results in a 401 Unauthorized or 403 Forbidden response, not a 429. Option C is wrong because an incorrect role assignment on the service principal would cause 403 Forbidden errors due to missing RBAC permissions, not a 429 throttling response.

125
MCQmedium

You are building an Azure AI solution that uses Azure AI Language to analyze customer feedback stored in an Azure Blob Storage container. The container contains 500,000 small text documents. You need to minimize the total time required to analyze all documents and minimize the number of API calls. What should you do?

A.Submit a separate synchronous request for each document by using the Analyze Text API.
B.Use Azure AI Document Intelligence to extract text from each document and then call the Azure AI Language API for each extracted document.
C.Combine all documents into a single request by using the Analyze Text API with a custom text analytics task.
D.Use the Analyze Text API asynchronously by submitting a batch job that references the documents in Azure Blob Storage.
AnswerD

Asynchronous batch processing is designed for large-scale analysis of documents in Azure Blob Storage. You submit one job that points to the container, and the service processes all 500,000 documents in parallel. This minimizes both the number of API calls (submit and poll) and the total elapsed time compared with per-document synchronous calls.

Why this answer

For large volumes of documents already stored in Azure Blob Storage, the asynchronous Analyze Text API is the intended mechanism. It accepts a batch job that references the storage container, processes documents in parallel, and returns results for retrieval. This approach reduces the number of API calls to a few (submit and poll) and shortens overall processing time compared with synchronous per-document calls.

Exam trap

The trap here is assuming that combining documents into a single synchronous request can reduce API calls, when the Analyze Text API enforces document count and payload size limits that make this impossible.

126
MCQeasy

You are deploying an Azure AI solution that uses multiple Azure AI services resources. You need to ensure that all resources are deployed in a consistent manner and can be managed as a single unit. You also need to be able to assign permissions to the entire group of resources at once. What should you use?

A.Management group
B.Azure Resource Manager template
C.Azure subscription
D.Resource group
AnswerD

A resource group is a logical container for Azure resources. Deploying all Azure AI services resources into the same resource group allows you to manage them as a single unit and assign role-based access control (RBAC) permissions at the resource group scope, which applies to all resources within it. This meets both the consistent deployment and centralized permission management requirements.

Why this answer

A resource group is the fundamental logical container for Azure resources. By placing all Azure AI services resources in one resource group, you can deploy them together using a template and assign RBAC permissions at the resource group scope, which cascades to all contained resources. This provides both consistent management and centralized access control without granting overly broad permissions.

Exam trap

The trap here is confusing the deployment mechanism (ARM template) with the management boundary (resource group), or choosing a broader scope like a subscription when a resource group suffices.

127
MCQeasy

You deploy a custom vision model using Azure AI Custom Vision. After deployment, you notice the model has high accuracy on training data but low accuracy on new images. What is the most likely cause?

A.The training time was too short
B.The training dataset has too few images
C.The wrong domain was selected during training
D.The model is overfitted to the training data
AnswerD

Overfitting occurs when the model memorises training images rather than learning generalisable features, producing high training accuracy but poor performance on unseen images. The gap between training and new-image accuracy is the defining symptom, so more varied training data or augmentation is needed.

Why this answer

High accuracy on training data but low accuracy on new images is the classic symptom of overfitting, where the model has memorized the training examples (including noise and irrelevant patterns) rather than learning generalizable features. In Azure AI Custom Vision, this typically occurs when the training dataset is too small, too homogeneous, or lacks sufficient variation, causing the model to fail on unseen data.

Exam trap

The trap here is that candidates confuse 'too few images' (a contributing factor) with the direct diagnosis of 'overfitting,' but the question asks for the most likely cause of the described symptom, which is the overfitting itself, not its root cause.

How to eliminate wrong answers

Option A is wrong because training time in Custom Vision is automatically managed by the service; extending it does not directly cause overfitting—the model stops when convergence is reached. Option B is wrong because having too few images can contribute to overfitting, but the question asks for the 'most likely cause' given the symptom, and overfitting is the direct description of the behavior, not the root cause of small dataset size. Option C is wrong because selecting the wrong domain (e.g., 'General' vs. 'Food' or 'Landmarks') affects feature extraction and may reduce accuracy overall, but it does not specifically produce the pattern of high training accuracy and low test accuracy—that pattern is the hallmark of overfitting.

128
MCQhard

You are deploying an Azure AI solution that uses Azure OpenAI Service. The solution must be deployed in a way that minimizes latency for users in Asia. However, the company's data residency policy requires data to stay in the United States. What should you do?

A.Use Azure CDN to cache the model responses in Asia.
B.Deploy the Azure OpenAI Service in an Asian region and use Azure Front Door to route traffic.
C.Deploy the service in multiple regions globally and use Traffic Manager for routing.
D.Deploy the service in a US region and use Azure Front Door with caching to reduce latency.
AnswerD

Front Door provides low-latency access while keeping data in US.

Why this answer

It satisfies both requirements: data residency (deploying in a US region keeps data within the United States) and latency reduction for Asian users. Azure Front Door with caching stores frequently accessed model responses at edge locations closer to users in Asia, minimizing round-trip time without moving the origin data.

Exam trap

The trap here is that candidates assume caching (Option A) or global deployment (Option C) can solve latency without considering data residency, or they mistakenly think deploying in Asia (Option B) is acceptable despite the policy constraint.

How to eliminate wrong answers

Option A is wrong because Azure CDN caches static content, but Azure OpenAI Service responses are dynamic and often non-cacheable (e.g., unique prompts or streaming outputs); caching would not reduce latency for real-time inference. Option B is wrong because deploying in an Asian region violates the data residency policy requiring data to stay in the United States. Option C is wrong because deploying in multiple regions globally would require data replication outside the US, breaking the data residency constraint; Traffic Manager routes traffic but does not cache responses, so latency from a US region would remain high for Asian users.

129
Multi-Selectmedium

Which THREE practices should be followed to secure an Azure AI solution that uses Azure OpenAI Service and Azure AI Search?

Select 3 answers
A.Store API keys in Azure Key Vault but use them directly in application code.
B.Use managed identities to authenticate between Azure OpenAI and Azure AI Search.
C.Place all AI services in a DMZ subnet with public IP addresses.
D.Require that all client applications use HTTPS with TLS 1.2 or higher.
E.Enable firewall and private endpoints for all AI service endpoints.
AnswersB, D, E

Managed identities let Azure OpenAI authenticate to Azure AI Search without embedding keys or secrets in configuration, eliminating credential exposure and rotation overhead. This satisfies the requirement to secure service-to-service access within the AI solution.

Why this answer

Option B is correct because managed identities let Azure OpenAI and Azure AI Search authenticate to each other through Microsoft Entra ID without embedding secrets or connection strings in code, eliminating credential leakage and rotation overhead. Option D is correct because requiring HTTPS with TLS 1.2 or higher protects data in transit between client applications and the AI services, preventing interception or downgrade attacks on prompts, responses, and search queries. Option E is correct because enabling firewall rules and private endpoints on the AI service endpoints removes public internet exposure and restricts traffic to approved virtual networks, which is a core network-isolation control for Azure AI workloads.

Option A is not appropriate because using API keys directly in application code exposes secrets in source control, logs, and memory even if the keys are originally stored in Azure Key Vault. Option C is not appropriate because placing AI services in a DMZ subnet with public IP addresses increases the attack surface rather than securing the solution; private endpoints and restricted access are preferred.

Exam trap

The trap here is that candidates often think storing keys in Key Vault is sufficient for security, but the question tests whether you understand that managed identities eliminate the need to handle keys altogether, and that public endpoints (even in a DMZ) are not secure for AI services.

130
MCQmedium

You are planning a solution that uses Azure AI Document Intelligence to process invoices. The solution must be deployed to a production environment with high availability. You need to use an Azure Resource Manager (ARM) template to deploy the Document Intelligence resource. The template must ensure that the resource is deployed to two Azure regions. What should you do?

A.Use the copy element in the ARM template to deploy multiple instances of the Document Intelligence resource with the same region but different names.
B.Deploy a single Document Intelligence resource and configure geo-replication through the Azure portal after deployment.
C.Create two separate Document Intelligence resources in the ARM template, each in a different region, and use a Traffic Manager profile to distribute requests.
D.Deploy the ARM template with a single Document Intelligence resource and set the location property to a variable that contains multiple regions.
AnswerC

This approach deploys two independent Document Intelligence resources in different regions, providing high availability. Traffic Manager can route traffic based on priority or performance. This is a common pattern for multi-region deployments. The ARM template can define both resources and the Traffic Manager profile, ensuring consistent deployment. This satisfies the requirement for high availability across regions.

Why this answer

To achieve high availability across regions for Azure AI Document Intelligence, you must deploy multiple resources, each in a different region. An ARM template can define both resources, and you can use Azure Traffic Manager to route requests. This ensures that if one region fails, the other can handle the load.

The other options either do not provide cross-region redundancy or rely on non-existent features.

Exam trap

The trap here is assuming that a single Azure resource can be deployed to multiple regions by specifying multiple locations in the location property.

131
MCQmedium

You are planning to deploy an Azure AI Language resource that will be used by multiple applications. The applications must authenticate using Azure Active Directory (Azure AD) tokens. You need to assign the appropriate role to the applications' managed identities so they can call the Azure AI Language service. Which role should you assign?

A.Reader
B.Azure AI Developer
C.Cognitive Services User
D.Cognitive Services Contributor
AnswerC

The Cognitive Services User role grants access to read and write data for Azure AI services, including calling the Azure AI Language APIs. It allows the managed identity to authenticate and perform operations such as text analytics and language understanding. This role provides the necessary permissions without granting full control over the resource, following the principle of least privilege for application access.

Why this answer

For applications to call Azure AI Language using Azure AD authentication, they need a role that grants data-plane access. The Cognitive Services User role provides read and write access to the service's data plane without granting management permissions. This aligns with least privilege and is the correct choice for managed identities that only need to invoke the API.

Exam trap

The trap here is confusing the Contributor role, which manages the resource, with the User role, which allows calling the service API.

132
MCQeasy

You need to monitor costs for an Azure AI solution that uses multiple Azure AI services. Which Azure tool should you use to set budgets and receive alerts?

A.Azure Advisor
B.Azure Monitor
C.Azure Service Health
D.Azure Cost Management
AnswerD

Azure Cost Management aggregates spend across all Azure AI services within a subscription or resource group, letting you define budgets scoped to those resources and configure alerts when thresholds are breached. It is the native tool for cost visibility and proactive notification, matching the monitoring requirement.

Why this answer

Azure Cost Management is the dedicated Azure tool for setting budgets, defining cost thresholds, and configuring alerts when spending exceeds those limits. It provides detailed cost analysis, forecasting, and policy enforcement across all Azure services, including AI services like Cognitive Services and Azure Machine Learning.

Exam trap

The trap here is that candidates confuse Azure Advisor's cost recommendations with actual budget management, or they mistakenly think Azure Monitor's alerting capabilities extend to financial cost thresholds rather than just operational metrics.

How to eliminate wrong answers

Option A is wrong because Azure Advisor provides personalized recommendations for cost optimization, security, and performance, but it does not allow you to set budgets or configure cost alerts. Option B is wrong because Azure Monitor collects and analyzes telemetry data (metrics, logs) for application performance and health, not for financial cost tracking or budget management. Option C is wrong because Azure Service Health provides information about service outages, planned maintenance, and health advisories for Azure services, not cost monitoring or budget alerts.

133
MCQhard

Refer to the exhibit. You are using Azure AI Document Intelligence with a layout model. The pipeline returns an empty tables array even though the document contains tables. The OCR step extracts text correctly. What is the most likely issue?

A.The OCR step is not recognizing table cells.
B.The table extraction step is misconfigured.
C.The output field mapping for tables is missing.
D.The layout extraction step is not correctly identifying table structures.
AnswerD

The layout model performs its own table-structure detection, separate from OCR text extraction. Correct text with an empty tables array means the structure-detection stage is failing to recognise rows, columns and spans, so the table identification step is the faulty component.

Why this answer

The layout model in Azure AI Document Intelligence performs OCR and then uses a layout extraction step to identify structural elements like tables. If the OCR extracts text correctly but the tables array is empty, it indicates that the layout extraction step failed to detect the table boundaries or cell structure, not that OCR missed the text. Option D correctly identifies this as the most likely issue.

Exam trap

The trap here is that candidates assume OCR and table extraction are the same step, but Azure AI Document Intelligence separates text recognition from structural layout analysis, so correct OCR does not guarantee correct table detection.

How to eliminate wrong answers

Option A is wrong because the OCR step extracts text correctly, as stated in the question, so it is recognizing table cells as text; the issue is not with OCR recognition. Option B is wrong because the layout model does not have a separate 'table extraction' configuration that can be misconfigured; table extraction is an inherent part of the layout analysis, and the pipeline is using the standard layout model. Option C is wrong because output field mapping is used for custom extraction models (like prebuilt or custom neural models), not for the layout model, which returns raw structural elements like tables and cells directly in the JSON output without requiring field mapping.

134
MCQhard

Your company uses Azure OpenAI to generate code snippets. Developers need to ensure that the generated code does not contain security vulnerabilities. What should you implement?

A.Set usage quotas to limit the number of code generation requests
B.Fine-tune the model on a dataset of secure code examples
C.Configure Azure OpenAI content filters to block vulnerable code
D.Integrate a static code analysis tool into the CI/CD pipeline to scan generated code
AnswerD

Static analysis scans generated code for known vulnerability patterns such as injection flaws or insecure API use before merge, catching issues that prompt engineering alone cannot guarantee. Integrating it into CI/CD enforces this check consistently on every generated snippet.

Why this answer

Integrating a static code analysis tool (e.g., Microsoft Defender for DevOps, SonarQube, or Checkmarx) into the CI/CD pipeline allows automated scanning of generated code for security vulnerabilities before deployment. This approach directly addresses the requirement to ensure generated code is free of vulnerabilities, as Azure OpenAI content filters are not designed to detect code-level security flaws like SQL injection or buffer overflows.

Exam trap

The trap here is that candidates confuse Azure OpenAI content filters (which handle text-level safety) with code-level security scanning, leading them to incorrectly select Option C, while the correct approach requires a dedicated security analysis tool integrated into the development pipeline.

How to eliminate wrong answers

Option A is wrong because setting usage quotas only limits the number of requests, not the security quality of the generated code; it prevents abuse but does not scan for vulnerabilities. Option B is wrong because fine-tuning on secure code examples improves the model's output quality but does not guarantee that every generated snippet is vulnerability-free, as the model can still produce insecure patterns not present in the training data. Option C is wrong because Azure OpenAI content filters are designed to block harmful or policy-violating content (e.g., hate speech, violence), not to detect code-specific security vulnerabilities like cross-site scripting or insecure cryptographic practices.

135
Multi-Selectmedium

Which THREE of the following are capabilities of Azure AI Content Safety?

Select 3 answers
A.Sexual content detection
B.Hate speech detection
C.Self-harm detection
D.Sentiment analysis
E.Personally identifiable information (PII) detection
AnswersA, B, C

Sexual content detection is a core Azure AI Content Safety capability, satisfying the stem's requirement for content moderation features. The service classifies text and images against severity levels for sexual material, alongside hate, violence and self-harm categories, using its dedicated classification models rather than general-purpose filtering.

Why this answer

Azure AI Content Safety provides built-in AI classifiers that detect harmful content across four categories: sexual, hate, violence, and self-harm, so options A (sexual content detection), B (hate speech detection), and C (self-harm detection) are all correct capabilities of the service. These categories are exposed through the Analyze Text and Analyze Image APIs, which return severity scores (0-7) for each category, enabling applications to filter or moderate harmful content. Option D (sentiment analysis) is not part of Content Safety; sentiment analysis is a feature of Azure AI Language.

Option E (PII detection) is also not part of Content Safety; PII detection is provided by Azure AI Language's Personally Identifiable Information extraction capability.

Exam trap

The trap here is that candidates confuse Azure AI Content Safety with other Azure AI services that handle sentiment analysis or PII detection, leading them to select options that belong to Azure AI Language or Azure AI Search instead of the specific content moderation service.

136
MCQeasy

Your team is developing a chatbot using Azure AI Bot Service. You need to ensure that the bot can handle multiple languages and respond appropriately. Which Azure AI service should you integrate to perform language detection?

A.Azure AI Language
B.Azure AI Speech
C.Azure AI Content Safety
D.Azure AI Translator
AnswerA

Azure AI Language provides the language detection feature, returning the detected language and confidence score for input text. Integrating it lets the bot identify the incoming language and route to appropriate responses, satisfying the multilingual handling requirement.

Why this answer

Azure AI Language provides pre-built language detection capabilities as part of its natural language processing (NLP) features. By integrating this service, the bot can analyze incoming text and identify the language, enabling it to route responses appropriately or trigger language-specific logic.

Exam trap

The trap here is that candidates often confuse Azure AI Translator's built-in language detection (which is a secondary capability) with the dedicated language detection service, leading them to choose Option D instead of the correct Azure AI Language.

How to eliminate wrong answers

Option B is wrong because Azure AI Speech focuses on speech-to-text, text-to-speech, and speaker recognition, not on detecting the language of text input. Option C is wrong because Azure AI Content Safety is designed to detect harmful or inappropriate content (e.g., hate speech, self-harm) in text or images, not to identify the language. Option D is wrong because Azure AI Translator is used to translate text between languages, but it does not perform standalone language detection; while Translator can sometimes infer language during translation, the dedicated language detection feature is part of Azure AI Language.

137
Multi-Selecthard

You are planning to deploy a custom neural voice (CNV) model using Azure AI Speech. You need to ensure that the deployment meets Microsoft's responsible AI requirements. Which two actions should you take? (Choose two.)

Select 2 answers
A.Submit an application to Microsoft for access to custom neural voice and wait for approval.
B.Deploy the model to a public endpoint without any access restrictions.
C.Train the model using data from publicly available audio sources without consent.
D.Obtain explicit consent from the voice talent and store the consent statement.
E.Use a standard voice model instead of a custom neural voice to avoid the approval process.
AnswersA, D

Access to custom neural voice is restricted. You must submit an application to Microsoft that describes your use case and how you will comply with responsible AI guidelines. Microsoft reviews the application and grants access only if approved. This is a mandatory step before you can create and deploy a CNV model. It ensures that the technology is used responsibly.

Why this answer

To deploy a custom neural voice model responsibly, you must obtain explicit consent from the voice talent and submit an application to Microsoft for access. These are mandatory steps in the gated access process. Using standard voices or training without consent does not meet the requirements.

Deploying to a public endpoint without restrictions is also against policy.

Exam trap

The trap here is assuming that custom neural voice can be deployed without Microsoft approval, when in fact it requires a gated access application and consent.

138
MCQhard

Your organization uses Azure AI Document Intelligence to extract data from invoices. The solution must identify custom fields not present in the prebuilt models, such as 'purchase order number' located in varying positions across documents. What should you do?

A.Use the layout model and apply manual post-processing.
B.Use Azure AI Forms Recognizer with prebuilt receipt model.
C.Use the prebuilt invoice model with field merging.
D.Train a custom extraction model using labeled sample invoices.
AnswerD

Custom extraction models learn field labels and their positional context from your own labelled invoices, so they locate fields such as purchase order number wherever they appear. Prebuilt invoice models expose only a fixed schema, which cannot capture organisation-specific fields in varying positions.

Why this answer

Azure AI Document Intelligence (formerly Form Recognizer) allows you to train a custom extraction model using labeled sample invoices. This approach enables the model to learn custom fields like 'purchase order number' that appear in varying positions, which prebuilt models cannot handle. By providing labeled examples, the model generalizes to extract the field accurately from new documents.

Exam trap

The trap here is that candidates may assume the prebuilt invoice model can be extended with custom fields via configuration or merging, but Azure AI Document Intelligence requires explicit custom model training to recognize fields not present in prebuilt schemas.

How to eliminate wrong answers

Option A is wrong because the layout model only extracts text and structure (tables, lines) without semantic field recognition; manual post-processing would be inefficient and error-prone for custom fields. Option B is wrong because the prebuilt receipt model is designed for receipts, not invoices, and cannot extract custom fields like 'purchase order number'. Option C is wrong because the prebuilt invoice model does not support field merging; it only extracts predefined fields and cannot learn new custom fields.

139
Multi-Selecteasy

Which TWO monitoring metrics should you track to ensure the health and performance of an Azure AI Search service used for a customer-facing product catalog?

Select 2 answers
A.Throttled search queries count.
B.Indexer execution history and duration.
C.Storage used in GB.
D.Search latency (average and P99).
E.Number of successful search requests.
AnswersA, D

Throttled search queries count directly exposes capacity exhaustion, revealing when the service rejects requests because replica or partition limits are exceeded. For a customer-facing catalogue, this metric satisfies the availability constraint: throttling silently degrades the user experience, so tracking it triggers timely scaling before shoppers encounter failed searches.

Why this answer

Option A, throttled search queries count, is correct because throttling directly indicates that the service is hitting its query-per-second (QPS) capacity limits, which degrades the customer-facing catalog experience and signals a need to scale replicas or partitions. Option D, search latency (average and P99), is correct because latency is the primary performance indicator for a user-facing search experience; tracking both average and P99 reveals tail-latency problems that average alone would hide. Option B is not among the correct answers because indexer execution history and duration relates to data ingestion pipelines, not the query-time health of a customer-facing catalog.

Option C is not correct because storage used in GB is a capacity metric that does not reflect query performance or service health for end users. Option E is not correct because counting only successful search requests gives no insight into failures, throttling, or latency, and a rising success count can mask underlying performance degradation.

Exam trap

The trap here is that candidates often confuse operational metrics (like indexer duration or storage usage) with customer-facing performance metrics, leading them to select indexer execution history instead of search latency.

140
Multi-Selecthard

Which THREE are required when planning to use Azure OpenAI Service for a generative AI application that must comply with responsible AI principles?

Select 3 answers
A.Restrict the model to a maximum of 1000 tokens.
B.Implement content filters to block harmful outputs.
C.Design with human-in-the-loop for critical decisions.
D.Enable rate limiting to prevent abuse.
E.Establish data governance policies for training data.
AnswersB, C, E

Content filters are mandatory for Azure OpenAI deployments, screening prompts and completions to block harmful categories such as violence, hate, and self-harm. Implementing them is a required responsible AI control for any generative application handling user input and model output.

Why this answer

Option B is correct because Azure OpenAI Service provides configurable content filters (categories such as hate, violence, sexual, and self-harm, with severity thresholds) that are a core responsible AI control for blocking harmful model outputs. Option C is correct because human-in-the-loop review is a responsible AI requirement for high-impact or critical decisions, ensuring a human validates or overrides model output before it affects users. Option E is correct because data governance policies for training data address privacy, consent, provenance, and bias concerns, which are foundational to responsible AI compliance.

Option A is not required: a 1000-token cap is an arbitrary cost/latency constraint, not a responsible AI principle, and token limits are set per model/deployment as needed. Option D is not required: rate limiting is an availability and abuse-mitigation control, not a responsible AI requirement, and it does not by itself ensure fair, safe, or accountable AI behavior.

Exam trap

The trap here is that candidates confuse operational controls (like token limits or rate limiting) with responsible AI requirements, which are specifically about fairness, safety, transparency, and accountability, not performance or security.

141
MCQmedium

You are deploying an Azure AI solution that calls Azure OpenAI and Azure AI Language from an Azure Container Apps environment. The solution must authenticate to both services without using service keys, and the container app must be able to access the services even if the network is restricted to private endpoints. What should you configure?

A.Create a service principal, store its client secret in the container app environment variables, and assign the Contributor role on each Azure AI resource.
B.Use the Azure AI services multi-service account key retrieved from Azure Key Vault and pass it in the Ocp-Apim-Subscription-Key header.
C.Configure the container app to use an Azure Front Door origin with a private link and enable token-based authentication by using a shared access signature.
D.Enable a system-assigned managed identity on the container app and assign the Cognitive Services User role to the identity on each Azure AI resource.
AnswerD

A system-assigned managed identity gives the container app an identity in Microsoft Entra ID without any secret. Assigning the Cognitive Services User role on each Azure AI resource grants the data-plane permissions needed to call Azure OpenAI and Azure AI Language. This works with private endpoints because authentication uses the identity rather than keys.

Why this answer

Identity-based authentication with a managed identity and the Cognitive Services User role allows the container app to call Azure OpenAI and Azure AI Language without any keys. Because the identity is recognized by Microsoft Entra ID, the calls are authorized even when the services are reachable only through private endpoints. The other options either use keys or assign roles that do not grant data-plane access.

Exam trap

The trap here is assigning a management-plane role such as Contributor and expecting it to authorize data-plane inference calls, which require a Cognitive Services data role instead.

142
MCQmedium

Refer to the exhibit. You are configuring an agent in Azure AI Foundry. The agent fails to start because the specified model is not available in the current Azure OpenAI resource. What should you do to resolve the issue?

A.Modify the system_prompt to include the model version
B.Deploy the gpt-4-0613 model in the Azure OpenAI resource
C.Change the connection_type to 'Weak'
D.Change the provider to 'AzureAI'
AnswerB

The agent requires a deployed model matching the specified name in the Azure OpenAI resource. Deploying gpt-4-0613 creates that deployment, making the model available for the agent to reference and allowing it to start successfully.

Why this answer

The agent fails to start because the specified model (likely gpt-4-0613) is not deployed in the Azure OpenAI resource. In Azure AI Foundry, agents require an existing model deployment to invoke; you cannot use a model that hasn't been deployed. Option B correctly resolves this by deploying the required model in the Azure OpenAI resource.

Exam trap

The trap here is that candidates might think modifying the system_prompt or changing a connection setting can fix a missing model deployment, but Azure OpenAI requires explicit model deployment before any resource can use it.

How to eliminate wrong answers

Option A is wrong because the system_prompt defines the agent's behavior and instructions, not the model version or deployment; modifying it cannot make an undeployed model available. Option C is wrong because connection_type is not a valid configuration for Azure OpenAI resources; 'Weak' is not a recognized connection type and does not affect model availability. Option D is wrong because the provider is already Azure (Azure OpenAI) and changing it to 'AzureAI' is not a valid provider option; the issue is the missing model deployment, not the provider.

143
MCQeasy

You are building an Azure AI solution that uses Azure AI Vision to analyze images. The solution must be able to extract text from images and return the text in a structured format. You need to choose the appropriate Azure AI Vision feature. What should you use?

A.Image Analysis
B.Face API
C.Read API
D.Custom Vision
AnswerC

The Read API in Azure AI Vision is specifically designed for optical character recognition (OCR). It extracts printed and handwritten text from images and documents and returns the text in a structured format, including lines and words. This meets the requirement to extract text and return it in a structured format.

Why this answer

The Read API is the OCR component of Azure AI Vision. It extracts text from images and returns it in a structured JSON format with lines and words. This is the correct choice for extracting text from images in a structured format.

Exam trap

The trap here is confusing Image Analysis with OCR capabilities, as Image Analysis can detect text but does not provide the same structured output as the Read API.

144
MCQmedium

You are designing a chatbot using Azure AI Language. The chatbot must understand user intents and also extract entities like dates and locations. Which feature combination should you use?

A.Conversational Language Understanding (CLU) with entities
B.Sentiment analysis and entity linking
C.Custom text classification and key phrase extraction
D.Orchestration Workflow and custom text classification
AnswerA

Conversational Language Understanding provides intent classification alongside integrated entity extraction, satisfying both requirements in one Azure AI Language resource. Custom entities capture dates and locations through labelled training utterances, unlike sentiment analysis or key phrase extraction, which return no intent predictions. CLU therefore meets the stem's dual constraint without combining separate services.

Why this answer

Conversational Language Understanding (CLU) is the correct Azure AI Language feature for building a chatbot that understands user intents and extracts entities like dates and locations. CLU is specifically designed for natural language understanding (NLU) tasks, providing prebuilt and custom entity extraction alongside intent recognition, which directly matches the requirement.

Exam trap

The trap here is that candidates often confuse entity linking (which maps to external knowledge bases) with entity extraction (which pulls values directly from the utterance), leading them to choose Option B despite it lacking intent recognition.

How to eliminate wrong answers

Option B is wrong because sentiment analysis evaluates the emotional tone of text, not user intents, and entity linking maps named entities to a knowledge base (e.g., Wikipedia), not extracting arbitrary entities like dates and locations. Option C is wrong because custom text classification assigns predefined labels to entire documents, not user intents in a conversational context, and key phrase extraction identifies key terms but does not extract structured entities like dates and locations. Option D is wrong because Orchestration Workflow routes requests between different language services (e.g., CLU, QnA Maker) but does not itself perform intent recognition or entity extraction; custom text classification also does not handle entity extraction.

145
MCQhard

You are deploying an Azure AI solution that uses Azure AI Document Intelligence to extract data from invoices. The solution must process documents in near real-time and must be able to handle sudden spikes in volume. You need to design the architecture to meet these requirements while minimizing cost. What should you use?

A.Azure Logic Apps with a recurrence trigger that polls the blob container every minute.
B.Azure Functions with a blob trigger that calls the Document Intelligence API and uses a consumption plan.
C.Azure Kubernetes Service (AKS) with a horizontal pod autoscaler that processes documents from a queue.
D.Azure Batch with a pool of virtual machines that processes documents from a queue.
AnswerB

Azure Functions with a blob trigger can process documents as they are uploaded, providing near real-time processing. The consumption plan automatically scales out during spikes and scales in when idle, minimizing cost. This serverless approach is ideal for unpredictable workloads and reduces infrastructure management.

Why this answer

For near real-time processing with sudden spikes and minimal cost, a serverless approach with Azure Functions on a consumption plan is best. The blob trigger ensures immediate processing when documents are uploaded, and the consumption plan scales automatically and charges only for execution time. Other options introduce latency, require infrastructure management, or do not scale to zero.

Exam trap

The trap here is assuming that Logic Apps are always cheaper, but polling and scaling limits can increase cost and delay.

146
MCQhard

You are deploying an Azure AI solution that uses Azure OpenAI Service. The solution must ensure that all API calls are logged for auditing and that the logs are retained for 90 days. You need to configure diagnostic settings. What should you do?

A.Enable diagnostic settings on the Azure OpenAI resource and send logs to a Log Analytics workspace with a 90-day retention policy.
B.Enable Azure Defender for AI and configure it to export logs to a SIEM with 90-day retention.
C.Configure Azure Monitor Application Insights to capture all API calls and set the retention to 90 days.
D.Use Azure Policy to enforce that all API calls are logged to an Azure Storage account with a 90-day lifecycle policy.
AnswerA

Azure OpenAI supports diagnostic settings that can stream logs to Log Analytics, Storage, or Event Hubs. Sending logs to a Log Analytics workspace allows you to set a retention policy of 90 days, meeting the auditing requirement. This is the native and recommended approach for logging API calls.

Why this answer

To log Azure OpenAI API calls for auditing, you must enable diagnostic settings on the Azure OpenAI resource. These logs can be sent to a Log Analytics workspace, where you can configure a 90-day retention period. Other options do not provide resource-level API logging.

Application Insights is for application telemetry, Azure Policy enforces configurations, and Defender for AI is for security alerts.

Exam trap

The trap here is confusing security alerting with audit logging; Defender for AI does not capture every API call.

147
MCQeasy

A developer is tasked with integrating Azure OpenAI Service into an application that generates product descriptions. The developer needs to ensure that the generated content does not contain offensive language. Which Azure AI service should be used in addition to Azure OpenAI?

A.Azure AI Search
B.Azure AI Vision
C.Azure AI Language
D.Azure AI Content Safety
AnswerD

Azure AI Content Safety provides dedicated hate, violence, sexual and self-harm classifiers that screen generated text after Azure OpenAI produces it, satisfying the requirement to block offensive language that the model's own filters may not catch.

Why this answer

Azure AI Content Safety (D) is the correct service because it provides built-in content moderation capabilities that can detect and filter offensive, inappropriate, or harmful language in text and images. By integrating Azure AI Content Safety with Azure OpenAI, the developer can automatically screen generated product descriptions for profanity, hate speech, or other offensive content before they are displayed to users, ensuring compliance with content policies.

Exam trap

The trap here is that candidates may confuse Azure AI Language's text analytics features (like sentiment analysis) with content moderation, but Azure AI Language does not include dedicated offensive language filtering, which is a distinct capability of Azure AI Content Safety.

How to eliminate wrong answers

Option A is wrong because Azure AI Search is a cognitive search service used for indexing and retrieving data, not for content moderation or filtering offensive language. Option B is wrong because Azure AI Vision is designed for image analysis tasks such as object detection, OCR, and facial recognition, and does not include text-based content safety features. Option C is wrong because Azure AI Language provides natural language processing capabilities like sentiment analysis, key phrase extraction, and language understanding, but it does not offer dedicated content moderation or offensive language detection; that functionality is specifically handled by Azure AI Content Safety.

148
MCQeasy

A company is deploying an Azure AI solution that uses Azure Cognitive Services. The solution must comply with data residency requirements that mandate all customer data be stored within a specific geographic region. Which action should the company take when creating the Cognitive Services resource?

A.Apply a resource tag that specifies the region.
B.Configure the endpoint URL to point to a regional endpoint.
C.Set the SKU to a tier that supports regional restrictions.
D.Select the appropriate region during resource creation.
AnswerD

Selecting the appropriate region during resource creation pins the Cognitive Services resource to that geography, ensuring stored customer data remains within the mandated boundary. Data residency is enforced at the resource level, so the region chosen at deployment determines where data is processed and stored. Other settings do not relocate data after provisioning.

Why this answer

Data residency requirements are satisfied by physically storing customer data within a specific geographic boundary. When creating an Azure Cognitive Services resource, selecting the appropriate region (e.g., 'West Europe' or 'East US') during the provisioning process ensures that all data processed and stored by that service instance remains within that Azure datacenter region. This is the fundamental and only guaranteed method to enforce data residency at the resource level.

Exam trap

The trap here is that candidates confuse network-level controls (like endpoint configuration or tagging) with physical data storage guarantees, mistakenly believing that a regional endpoint or a tag can enforce data residency when only the initial region selection during resource creation can do so.

How to eliminate wrong answers

Option A is wrong because resource tags are metadata labels used for organization, cost tracking, or policy enforcement; they do not influence where the underlying service stores data. Option B is wrong because the endpoint URL is automatically generated based on the chosen region and cannot be manually configured to redirect storage; it only determines the network access point, not the physical data location. Option C is wrong because the SKU tier (e.g., S0, F0) determines throughput limits and feature availability, not geographic restrictions; no SKU tier enforces regional data storage.

149
MCQmedium

You have an Azure AI solution that uses Azure AI Language to perform sentiment analysis. The solution is experiencing high latency. Which action should you take to reduce latency?

A.Move the service to a different Azure region.
B.Use the Free tier of the Azure AI Language service.
C.Increase the request timeout value.
D.Scale the service by increasing the number of instances or using a higher pricing tier.
AnswerD

Latency from throttling or insufficient throughput is resolved by scaling out instances or moving to a higher tier, increasing provisioned transactions per second. This directly addresses the capacity constraint causing the high latency in Azure AI Language sentiment analysis.

Why this answer

Scaling the Azure AI Language service by increasing the number of instances or moving to a higher pricing tier (e.g., from Standard S0 to a tier with higher throughput) directly addresses high latency by providing more capacity to handle concurrent requests. High latency often results from hitting the service's rate limits or throughput constraints, and scaling alleviates this bottleneck without changing the underlying architecture.

Exam trap

The trap here is that candidates often confuse network latency (solved by region proximity) with service throughput latency (solved by scaling), leading them to incorrectly choose Option A when the real bottleneck is capacity, not geography.

How to eliminate wrong answers

Option A is wrong because moving the service to a different Azure region primarily reduces network latency due to geographic proximity, but it does not resolve high latency caused by insufficient service capacity or throttling; the core issue is throughput, not distance. Option B is wrong because the Free tier has strict rate limits (e.g., 5,000 transactions per month) and lower throughput, which would likely worsen latency under load rather than reduce it. Option C is wrong because increasing the request timeout value does not reduce latency; it only allows the client to wait longer for a response, masking the symptom without addressing the underlying performance issue.

← PreviousPage 2 of 2 · 149 questions total

Ready to test yourself?

Try a timed practice session using only Plan Manage Azure Ai questions.