AI-102 Plan and manage an Azure AI solution Practice Question
You are deploying an Azure AI solution that uses Azure AI Search. The solution must be able to access the search service from an Azure virtual network without traversing the public internet. You need to configure the search service to meet this requirement. What should you do?
⚠ Common exam trap
The trap here is assuming that service endpoints or IP firewalls provide private connectivity, when they actually still use public IP addresses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a private endpoint for the search service and configure the virtual network to use it.
To access Azure AI Search privately from a virtual network, you must use a private endpoint, which assigns a private IP address from your subnet to the search service. This ensures all traffic remains within the Azure backbone. Other options either use public internet or do not provide a private IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the search service to use an IP firewall and add the virtual network's public IP address.
Why it's wrong here
An IP firewall restricts access based on public IP addresses, but traffic still traverses the public internet. It does not provide private connectivity from the virtual network. Additionally, virtual network public IP addresses are not static and may change. Thus, this does not meet the requirement for private access.
- ✓
Create a private endpoint for the search service and configure the virtual network to use it.
Why this is correct
A private endpoint creates a network interface in your virtual network, allowing private connectivity to Azure AI Search. This enables access from within the virtual network without going over the public internet. You must also configure the search service to deny public access and allow the private endpoint. This satisfies the requirement for private network access.
- ✗
Deploy the search service with a public endpoint and use Azure Front Door to route traffic privately.
Why it's wrong here
Azure Front Door is a global load balancer and CDN that operates over the public internet. It does not provide private connectivity from a virtual network to the search service. Traffic would still traverse the public internet. Therefore, this does not meet the requirement for private access without public internet.
- ✗
Enable a service endpoint for Azure AI Search on the virtual network subnet.
Why it's wrong here
Service endpoints allow secure access to Azure services over the Azure backbone network, but they still use public IP addresses and are not fully private. They do not provide a private IP address for the search service. For true private connectivity, a private endpoint is required. Service endpoints are a legacy feature and less secure.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.