Courseiva

AI-102 Plan and manage an Azure AI solution Practice Question

You are developing an Azure AI solution that uses Azure Cognitive Search. The solution must index documents from an Azure Blob Storage container. You need to ensure that the indexer can access the Blob Storage container securely without storing credentials in the indexer definition. What should you do?

⚠ Common exam trap

The trap here is assuming that Azure Key Vault can be directly integrated with Cognitive Search indexers to retrieve secrets at runtime.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable a managed identity for the Azure Cognitive Search service and grant it access to the Blob Storage container.

A managed identity for Azure Cognitive Search is the correct approach because it allows the indexer to authenticate to Blob Storage without storing any credentials in the indexer definition. You assign the managed identity the appropriate role on the storage account. This is a secure, Azure-native method. The other options either store credentials (SAS token or account key) or use the wrong key for authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a shared access signature (SAS) token for the Blob Storage container and include it in the indexer's data source connection string.

    Why it's wrong here

    A SAS token is a credential that grants access to the storage container. Including it in the connection string means the credential is stored in the indexer definition. This violates the requirement to not store credentials. SAS tokens also expire, requiring rotation. While SAS can be used, it does not provide the same security as a managed identity because the token itself is a secret that must be protected.

  • ✗

    Store the Blob Storage account key in Azure Key Vault and reference it in the indexer definition using a Key Vault secret URI.

    Why it's wrong here

    Azure Cognitive Search indexers do not support direct integration with Azure Key Vault for retrieving secrets at runtime. While you can store keys in Key Vault, the indexer cannot dynamically fetch them. You would need to manually retrieve the key and include it in the data source connection string, which still stores a credential in the indexer definition. This does not meet the requirement of not storing credentials.

  • ✓

    Enable a managed identity for the Azure Cognitive Search service and grant it access to the Blob Storage container.

    Why this is correct

    Using a managed identity for Azure Cognitive Search allows the indexer to authenticate to Blob Storage without storing credentials. You grant the managed identity the necessary role, such as Storage Blob Data Reader, on the storage account. This is a secure and recommended approach. The indexer can then use the managed identity to access the container. This eliminates the need for connection strings with keys.

  • ✗

    Configure the indexer to use the Azure Cognitive Search service's API key to authenticate to Blob Storage.

    Why it's wrong here

    The Azure Cognitive Search service's API key is used to authenticate to the search service itself, not to external data sources like Blob Storage. It cannot be used to access Blob Storage. Each service has its own authentication mechanism. Using the search service key for Blob Storage would fail authentication. This option misunderstands the purpose of the API key.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.