AI-102 Implement generative AI solutions Practice Question
You are deploying a generative AI assistant on Azure OpenAI Service that must summarize user-supplied financial reports. Security policy requires that report contents never leave your Azure tenant and that the model must not be fine-tuned. You need to provision the resource so that prompt and completion data are not retained for human review and are not used to train any shared model. What should you configure?
⚠ Common exam trap
The trap here is assuming that disabling diagnostic content logging or adding content filters changes how the service retains prompts, when data-handling behavior is governed by the abuse-monitoring modification process instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit an Azure OpenAI limited access modification request to disable abuse monitoring for the subscription.
The requirement is about data handling by the service itself, not about access control or content safety. The only mechanism that removes default human review and retention of prompts and completions for an Azure OpenAI resource is an approved limited access modification for abuse monitoring on the subscription. Content filters, diagnostic settings, and RBAC all address different concerns and leave the retention behavior unchanged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the Azure OpenAI resource's 'Content logging' to Disabled in Azure Monitor diagnostic settings.
Why it's wrong here
Azure Monitor diagnostic settings control where request and response metadata or content are exported, such as to Log Analytics. Disabling content logging only stops telemetry export; it does not govern the service's own abuse-monitoring retention or training behavior. It therefore does not satisfy the requirement that prompt and completion data not be retained for human review.
- ✓
Submit an Azure OpenAI limited access modification request to disable abuse monitoring for the subscription.
Why this is correct
Approved limited access modification for abuse monitoring removes the standard human review and retention of prompts and completions for the approved subscription. Because the requirement is that report contents are neither retained for review nor used to train shared models, this is the correct control. Fine-tuning is unaffected, and data stays within the tenant boundary.
- ✗
Create the deployment in a separate resource group and assign the Cognitive Services User role only to the application's managed identity.
Why it's wrong here
Resource group placement and least-privilege role assignment control who can call the model, not what the service does with the data afterward. RBAC does not change abuse-monitoring retention or training behavior, so the reports could still be reviewed by human moderators. This does not meet the stated data-handling requirement.
- ✗
Deploy the model with a content filter policy set to block high-severity categories and enable prompt shields.
Why it's wrong here
Content filter policies and Prompt Shields evaluate inputs and outputs for harmful content such as violence or jailbreak attempts. They are safety controls, not data-governance controls, and they do not stop the service from retaining prompts for abuse monitoring or from any training use. This option addresses a different requirement entirely.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.