Courseiva

AI-102 Implement generative AI solutions Practice Question

You are implementing a Retrieval Augmented Generation pattern with Azure AI Search and Azure OpenAI. Users complain that answers occasionally cite documents the user is not authorized to see, because the index contains all departments' content. You need to restrict retrieval so that each user only receives chunks from documents their identity permits. What should you do?

⚠ Common exam trap

The trap here is treating relevance ranking or prompt instructions as if they provided access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a security filter on a document access field in Azure AI Search, and pass the user's group or object IDs as an OData filter in the query.

Security trimming for RAG must occur at retrieval. Storing each document's allowed principals in a filterable field and passing the caller's group or object IDs as an OData filter ensures the search response never contains unauthorized chunks. Relevance ranking, prompt instructions, and manual index selection do not enforce authorization and can leak restricted content before the model or user sees it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a separate index per department and have users manually select which index to search.

    Why it's wrong here

    Manual index selection relies on users choosing correctly, which is error-prone and does not prevent a user from querying an index they should not access. It also fragments content and complicates cross-department queries. Without an authorization check tied to identity, a user could still select a restricted index. The requirement is automatic, identity-based enforcement, which a per-user filter on a shared index provides more reliably.

  • ✗

    Add a system message instructing the model to ignore any content the user is not allowed to see.

    Why it's wrong here

    A system message cannot know which documents the user is authorized to access, and the model has no trustworthy signal for authorization decisions. Even if instructed, the model may still surface restricted content, and the content has already left the index, so the leak has occurred. Authorization must be enforced before retrieval, not delegated to prompt instructions. This is a classic case of using prompt engineering where a hard security control is required.

  • ✗

    Apply a semantic ranker to the query and rely on relevance scoring to push unauthorized content lower in the results.

    Why it's wrong here

    Semantic ranking reorders results by relevance to the query, not by authorization. An unauthorized but highly relevant document can rank first and still be returned. Relevance is not a security boundary, and any leakage of restricted content to the model or user remains possible. This approach does not satisfy the requirement to prevent unauthorized retrieval and should never be used as an access control mechanism.

  • ✓

    Add a security filter on a document access field in Azure AI Search, and pass the user's group or object IDs as an OData filter in the query.

    Why this is correct

    Azure AI Search supports filtering on fields such as a collection of allowed group IDs. By storing each document's permitted principals and passing the caller's group or object IDs from the token into an OData filter, the query returns only chunks the identity is authorized to read. This enforces security at retrieval time, which is the correct layer for RAG, before content ever reaches the model or the user.

About these practice questions

One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.