AI-102 Plan and manage an Azure AI solution Practice Question
You are deploying an Azure AI solution that uses Azure OpenAI Service. The solution must ensure that all API calls are logged for auditing and that the logs are retained for 90 days. You need to configure diagnostic settings. What should you do?
⚠ Common exam trap
A common mix-up: candidates confuse security alerting with audit logging; Defender for AI does not capture every API call.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable diagnostic settings on the Azure OpenAI resource and send logs to a Log Analytics workspace with a 90-day retention policy.
To log Azure OpenAI API calls for auditing, you must enable diagnostic settings on the Azure OpenAI resource. These logs can be sent to a Log Analytics workspace, where you can configure a 90-day retention period. Other options do not provide resource-level API logging. Application Insights is for application telemetry, Azure Policy enforces configurations, and Defender for AI is for security alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable diagnostic settings on the Azure OpenAI resource and send logs to a Log Analytics workspace with a 90-day retention policy.
Why this is correct
Azure OpenAI supports diagnostic settings that can stream logs to Log Analytics, Storage, or Event Hubs. Sending logs to a Log Analytics workspace allows you to set a retention policy of 90 days, meeting the auditing requirement. This is the native and recommended approach for logging API calls.
- ✗
Enable Azure Defender for AI and configure it to export logs to a SIEM with 90-day retention.
Why it's wrong here
Microsoft Defender for AI provides threat protection and security alerts, not detailed API call logging for auditing. It is not a substitute for diagnostic settings. While it can integrate with a SIEM, it does not capture every API call, so it would not meet the requirement for comprehensive audit logs.
- ✗
Configure Azure Monitor Application Insights to capture all API calls and set the retention to 90 days.
Why it's wrong here
Application Insights is designed for application performance monitoring, not for auditing Azure resource-level API calls. While you can instrument your application to send telemetry, it does not automatically capture Azure OpenAI API calls at the resource level. Diagnostic settings are the correct mechanism for resource logs.
- ✗
Use Azure Policy to enforce that all API calls are logged to an Azure Storage account with a 90-day lifecycle policy.
Why it's wrong here
Azure Policy can audit and enforce configurations, but it does not generate logs for API calls. You still need diagnostic settings to emit logs. A storage account lifecycle policy can manage retention, but without diagnostic settings, no logs are produced. Policy alone cannot fulfill the logging requirement.
Go deeper
Related to this question
About these practice questions
One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.