Courseiva

AI-102 Plan and manage an Azure AI solution Practice Question

You are designing an Azure AI solution that uses an Azure OpenAI resource. The solution must allow developers to call the model from a web app without embedding API keys in client-side code. You need to ensure that the web app can authenticate to the Azure OpenAI resource. What should you implement?

⚠ Common exam trap

The trap here is assuming that storing the API key in Key Vault is sufficient for client-side security, when in fact the key can still be exposed if the client retrieves it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable managed identity on the web app and assign the Cognitive Services OpenAI User role to the identity on the Azure OpenAI resource.

Using a managed identity with the appropriate Azure RBAC role allows the web app to authenticate to Azure OpenAI without any secrets. The Cognitive Services OpenAI User role provides the necessary permissions to invoke the model. This approach is secure, scalable, and aligns with Azure best practices for keyless authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the web app to use the Azure OpenAI API key and rotate it every 24 hours using Azure Automation.

    Why it's wrong here

    Rotating the key frequently reduces risk but does not eliminate the need to store and manage the key. The key would still be present in the app configuration or code, and rotation introduces operational overhead. This is not a keyless solution and does not meet the requirement to avoid embedding API keys in client-side code.

  • ✗

    Store the Azure OpenAI key in Azure Key Vault and have the web app retrieve it at runtime.

    Why it's wrong here

    This approach still exposes the key to the client if the web app is a single-page application, and it requires managing Key Vault access separately. It does not eliminate the need to handle secrets in the app, and it is not the recommended keyless authentication method for Azure OpenAI. It also adds complexity without providing the same security benefits as managed identities.

  • ✗

    Generate a shared access signature (SAS) token for the Azure OpenAI resource and pass it in the request header.

    Why it's wrong here

    Azure OpenAI does not support SAS tokens for authentication. SAS tokens are used for Azure Storage, not for Cognitive Services or Azure OpenAI. Using a SAS token would fail because the service expects either an API key or an Microsoft Entra ID token. This option is a common misconception when mixing authentication mechanisms across Azure services.

  • ✓

    Enable managed identity on the web app and assign the Cognitive Services OpenAI User role to the identity on the Azure OpenAI resource.

    Why this is correct

    Managed identity allows the web app to authenticate to Azure OpenAI without storing credentials. Assigning the Cognitive Services OpenAI User role grants the necessary permissions to call the model. This is the recommended approach for keyless authentication and integrates with Azure RBAC, eliminating secret management in code or configuration.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AI-102 question is part of Courseiva's 761-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.