Courseiva

AI-102 Plan and manage an Azure AI solution Practice Question

Which THREE practices should be followed to secure an Azure AI solution that uses Azure OpenAI Service and Azure AI Search?

⚠ Common exam trap

Test-takers frequently think storing keys in Key Vault is sufficient for security, but the question tests whether you understand that managed identities eliminate the need to handle keys altogether, and that public endpoints (even in a DMZ) are not secure for AI services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use managed identities to authenticate between Azure OpenAI and Azure AI Search.

Option B is correct because managed identities let Azure OpenAI and Azure AI Search authenticate to each other through Microsoft Entra ID without embedding secrets or connection strings in code, eliminating credential leakage and rotation overhead. Option D is correct because requiring HTTPS with TLS 1.2 or higher protects data in transit between client applications and the AI services, preventing interception or downgrade attacks on prompts, responses, and search queries. Option E is correct because enabling firewall rules and private endpoints on the AI service endpoints removes public internet exposure and restricts traffic to approved virtual networks, which is a core network-isolation control for Azure AI workloads. Option A is not appropriate because using API keys directly in application code exposes secrets in source control, logs, and memory even if the keys are originally stored in Azure Key Vault. Option C is not appropriate because placing AI services in a DMZ subnet with public IP addresses increases the attack surface rather than securing the solution; private endpoints and restricted access are preferred.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store API keys in Azure Key Vault but use them directly in application code.

    Why it's wrong here

    Embedding keys directly in application code exposes them in source control and logs; managed identity or Key Vault references should supply credentials at runtime. It tempts because Key Vault storage alone sounds secure, but direct code usage defeats the vault's protection.

  • ✓

    Use managed identities to authenticate between Azure OpenAI and Azure AI Search.

    Why this is correct

    Managed identities let Azure OpenAI authenticate to Azure AI Search without embedding keys or secrets in configuration, eliminating credential exposure and rotation overhead. This satisfies the requirement to secure service-to-service access within the AI solution.

  • ✗

    Place all AI services in a DMZ subnet with public IP addresses.

    Why it's wrong here

    Public IP addresses in a DMZ expose Azure OpenAI and Azure AI Search endpoints to the internet, contradicting private endpoint and network isolation requirements. It tempts as a classic perimeter pattern, yet these services should sit in private subnets reached via private endpoints.

  • ✓

    Require that all client applications use HTTPS with TLS 1.2 or higher.

    Why this is correct

    TLS 1.2 or higher encrypts data in transit between clients and the AI endpoints, preventing interception or downgrade attacks on prompts and responses. This satisfies the requirement to secure communication channels across the Azure OpenAI and Azure AI Search solution.

  • ✓

    Enable firewall and private endpoints for all AI service endpoints.

    Why this is correct

    Private endpoints and firewall rules remove public internet exposure, restricting traffic to approved networks or virtual networks. This satisfies the requirement to secure the AI service endpoints themselves, blocking unauthorised access attempts at the network layer.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.