Courseiva

AI-102 Implement generative AI solutions Practice Question

You are deploying a generative AI assistant on Azure OpenAI Service that must summarize user-supplied financial reports. Security policy requires that report contents never leave your Azure tenant and that the model must not be fine-tuned. You need to provision the resource so that prompt and completion data are not retained for human review and are not used to train any shared model. What should you configure?

⚠ Common exam trap

The trap here is assuming that disabling diagnostic content logging or adding content filters changes how the service retains prompts, when data-handling behavior is governed by the abuse-monitoring modification process instead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit an Azure OpenAI limited access modification request to disable abuse monitoring for the subscription.

The requirement is about data handling by the service itself, not about access control or content safety. The only mechanism that removes default human review and retention of prompts and completions for an Azure OpenAI resource is an approved limited access modification for abuse monitoring on the subscription. Content filters, diagnostic settings, and RBAC all address different concerns and leave the retention behavior unchanged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the Azure OpenAI resource's 'Content logging' to Disabled in Azure Monitor diagnostic settings.

    Why it's wrong here

    Azure Monitor diagnostic settings control where request and response metadata or content are exported, such as to Log Analytics. Disabling content logging only stops telemetry export; it does not govern the service's own abuse-monitoring retention or training behavior. It therefore does not satisfy the requirement that prompt and completion data not be retained for human review.

  • ✓

    Submit an Azure OpenAI limited access modification request to disable abuse monitoring for the subscription.

    Why this is correct

    Approved limited access modification for abuse monitoring removes the standard human review and retention of prompts and completions for the approved subscription. Because the requirement is that report contents are neither retained for review nor used to train shared models, this is the correct control. Fine-tuning is unaffected, and data stays within the tenant boundary.

  • ✗

    Create the deployment in a separate resource group and assign the Cognitive Services User role only to the application's managed identity.

    Why it's wrong here

    Resource group placement and least-privilege role assignment control who can call the model, not what the service does with the data afterward. RBAC does not change abuse-monitoring retention or training behavior, so the reports could still be reviewed by human moderators. This does not meet the stated data-handling requirement.

  • ✗

    Deploy the model with a content filter policy set to block high-severity categories and enable prompt shields.

    Why it's wrong here

    Content filter policies and Prompt Shields evaluate inputs and outputs for harmful content such as violence or jailbreak attempts. They are safety controls, not data-governance controls, and they do not stop the service from retaining prompts for abuse monitoring or from any training use. This option addresses a different requirement entirely.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.