AI-102 Plan and manage an Azure AI solution Practice Question
You are developing an Azure AI solution that uses Azure Cognitive Search. The solution must index documents from an Azure Blob Storage container. You need to ensure that the indexer can access the Blob Storage container securely without storing credentials in the indexer definition. What should you do?
⚠ Common exam trap
The trap here is assuming that Azure Key Vault can be directly integrated with Cognitive Search indexers to retrieve secrets at runtime.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable a managed identity for the Azure Cognitive Search service and grant it access to the Blob Storage container.
A managed identity for Azure Cognitive Search is the correct approach because it allows the indexer to authenticate to Blob Storage without storing any credentials in the indexer definition. You assign the managed identity the appropriate role on the storage account. This is a secure, Azure-native method. The other options either store credentials (SAS token or account key) or use the wrong key for authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a shared access signature (SAS) token for the Blob Storage container and include it in the indexer's data source connection string.
Why it's wrong here
A SAS token is a credential that grants access to the storage container. Including it in the connection string means the credential is stored in the indexer definition. This violates the requirement to not store credentials. SAS tokens also expire, requiring rotation. While SAS can be used, it does not provide the same security as a managed identity because the token itself is a secret that must be protected.
- ✗
Store the Blob Storage account key in Azure Key Vault and reference it in the indexer definition using a Key Vault secret URI.
Why it's wrong here
Azure Cognitive Search indexers do not support direct integration with Azure Key Vault for retrieving secrets at runtime. While you can store keys in Key Vault, the indexer cannot dynamically fetch them. You would need to manually retrieve the key and include it in the data source connection string, which still stores a credential in the indexer definition. This does not meet the requirement of not storing credentials.
- ✓
Enable a managed identity for the Azure Cognitive Search service and grant it access to the Blob Storage container.
Why this is correct
Using a managed identity for Azure Cognitive Search allows the indexer to authenticate to Blob Storage without storing credentials. You grant the managed identity the necessary role, such as Storage Blob Data Reader, on the storage account. This is a secure and recommended approach. The indexer can then use the managed identity to access the container. This eliminates the need for connection strings with keys.
- ✗
Configure the indexer to use the Azure Cognitive Search service's API key to authenticate to Blob Storage.
Why it's wrong here
The Azure Cognitive Search service's API key is used to authenticate to the search service itself, not to external data sources like Blob Storage. It cannot be used to access Blob Storage. Each service has its own authentication mechanism. Using the search service key for Blob Storage would fail authentication. This option misunderstands the purpose of the API key.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.