Courseiva

AI-102 Implement generative AI solutions Practice Question

You are deploying a generative AI solution that uses Azure OpenAI Service with your own data stored in Azure AI Search. Users report that answers are sometimes pulled from documents the user is not permitted to see, because the retrieval step searches the entire index. You need to ensure each user only receives answers grounded in documents they are authorized to access, without creating a separate index per user. What should you do?

⚠ Common exam trap

The trap here is assuming that Azure OpenAI content filtering or a separate model deployment provides document-level authorization, when access control must actually be applied as a filter in the retrieval index.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a security filter field to the Azure AI Search index and pass the user's group or tenant identifier as an OData filter on each query.

Authorization must be enforced where the documents are selected, not where the model generates text. Adding a filterable access-control field to the Azure AI Search index and applying the caller's identity as an OData filter causes the retrieval step to return only permitted chunks, so the model can never ground an answer in a restricted document. This preserves one shared index while honoring per-user permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a security filter field to the Azure AI Search index and pass the user's group or tenant identifier as an OData filter on each query.

    Why this is correct

    Azure AI Search supports filterable fields that can be combined with the search query, so indexing an access-control field (for example, allowed groups) and passing the caller's identity as an OData filter restricts retrieval to documents that user may see. This keeps a single shared index while enforcing per-user authorization at query time, which is exactly the requirement. The model then only receives permitted grounding content, so answers cannot cite restricted documents.

  • ✗

    Enable Azure OpenAI content filtering at High severity for both prompts and completions.

    Why it's wrong here

    Content filtering evaluates whether text is harmful across categories such as hate, violence, and self-harm; it has no awareness of which documents a given user is permitted to read. Because the leakage in this scenario comes from the retrieval layer returning unauthorized chunks, raising the filter severity changes nothing about which documents are retrieved. It would only make the assistant refuse more harmful-sounding content, leaving the authorization gap fully intact.

  • ✗

    Create a separate Azure OpenAI deployment for each department and route users to the deployment matching their department.

    Why it's wrong here

    A model deployment is an inference endpoint; it does not partition the search index or enforce document-level permissions. Even if each department had its own deployment, every deployment could still be wired to the same shared index and retrieve the same unrestricted chunks. This adds cost and operational complexity without introducing any authorization check, so unauthorized documents would continue to appear in answers.

  • ✗

    Increase the chunk size of the indexed documents so that fewer documents are returned per query.

    Why it's wrong here

    Chunk size affects how much surrounding text travels with each retrieved passage and how many passages fit in the prompt, not who is allowed to retrieve them. Larger chunks might even pull more sensitive text into a single unauthorized result. Because no authorization predicate is applied, a user can still receive content from any indexed document, so this change does not satisfy the access-control requirement and may worsen accidental disclosure.

About these practice questions

Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.