AI-102 Plan and manage an Azure AI solution Practice Question
You are deploying an Azure AI solution that uses Azure OpenAI Service and Azure AI Language. The solution must ensure that each service has its own managed identity and that access to keys is restricted. You need to configure authentication for the services. What should you do?
⚠ Common exam trap
Many candidates confuse managed identities with service principals or assuming that storing keys in Key Vault alone satisfies the requirement for per-service identities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable managed identities for each Azure AI service and grant them access to Azure Key Vault.
Managed identities provide an identity for the service in Microsoft Entra ID, allowing it to authenticate to resources like Key Vault without storing credentials. Granting each service's managed identity access to Key Vault ensures secure retrieval of secrets and aligns with the principle of least privilege. Other options either rely on shared secrets or do not provide per-service identities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the services to use API keys stored in Azure App Configuration and enable Microsoft Entra ID authentication for the application.
Why it's wrong here
Storing API keys in App Configuration still exposes keys and does not provide managed identities for the services. Enabling Microsoft Entra ID authentication for the application does not satisfy the requirement for each service to have its own managed identity. This approach adds complexity without meeting the core need.
- ✗
Use Microsoft Entra ID service principals with client secrets for each service and store the secrets in Azure Key Vault.
Why it's wrong here
Service principals with client secrets are a valid authentication method, but they are not managed identities. Managed identities are automatically managed by Azure and eliminate the need for secret rotation. The scenario explicitly requires managed identities, so this option does not meet the requirement.
- ✗
Store the service keys in Azure Key Vault and configure the application to retrieve them at runtime using the Azure SDK.
Why it's wrong here
While storing keys in Key Vault is better than hardcoding, it still requires the application to have credentials to access Key Vault, and the services themselves do not use managed identities. The requirement is for each service to have its own managed identity, which this option does not provide.
- ✓
Enable managed identities for each Azure AI service and grant them access to Azure Key Vault.
Why this is correct
Each Azure AI service can have a system-assigned or user-assigned managed identity. By enabling managed identities and granting them access to Key Vault, you avoid storing credentials in code and can securely retrieve secrets. This aligns with least privilege and Azure best practices for authentication.
Go deeper
Related to this question
About these practice questions
One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.