AI-102 Plan and manage an Azure AI solution Practice Question
You are deploying an Azure AI Language resource that will process customer feedback. The resource must be accessible only from a specific Azure virtual network and must allow access from an on-premises network via a site-to-site VPN. You need to configure network security for the resource. What should you do?
⚠ Common exam trap
A common mix-up: candidates confuse service endpoints with private endpoints; service endpoints do not provide private IP connectivity for on-premises clients and do not disable public access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a private endpoint for the Azure AI Language resource and disable public access.
A private endpoint is the correct solution because it assigns a private IP address from your virtual network to the Azure AI Language resource, allowing secure access from both the VNet and on-premises via VPN. Disabling public access ensures the resource is not reachable from the internet. This configuration satisfies the network isolation requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Azure Private Link to create a private endpoint for the Azure AI Language resource and enable public access for on-premises clients.
Why it's wrong here
Creating a private endpoint is correct, but enabling public access contradicts the requirement to restrict access to the virtual network. On-premises clients should use the private endpoint via VPN, not public access. This configuration would leave the resource accessible from the internet, which is not desired.
- ✓
Configure a private endpoint for the Azure AI Language resource and disable public access.
Why this is correct
A private endpoint creates a private IP address for the Azure AI Language resource within your virtual network, enabling secure access from the VNet and on-premises via VPN. Disabling public access ensures no exposure to the internet. This meets the requirement for restricted access and integrates with your existing network infrastructure.
- ✗
Enable public access and configure IP firewall rules to allow only the on-premises public IP address.
Why it's wrong here
Allowing public access with IP restrictions still exposes the resource to the internet, which violates the requirement to restrict access to the virtual network. Additionally, on-premises traffic over VPN would appear as the VPN gateway's public IP, but this approach does not provide private connectivity and is less secure than a private endpoint.
- ✗
Configure a service endpoint for Azure AI Language on the virtual network subnet and enable public access for on-premises clients.
Why it's wrong here
Service endpoints allow secure access from a virtual network subnet to Azure services, but they do not provide private IP connectivity for on-premises clients. On-premises access would still require public access or a private endpoint. Service endpoints also do not disable public access entirely, so the resource remains publicly accessible.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.