AI-102 Plan and manage an Azure AI solution Practice Question
You are managing an Azure AI services resource that is used by several departments. The security team requires that you monitor the resource for unusual access patterns and receive alerts when the number of failed authentication attempts exceeds a threshold. You need to configure the appropriate Azure Monitor components. Which two actions should you take? (Choose two.)
⚠ Common exam trap
The trap here is assuming that enabling a private endpoint or Azure Defender automatically provides threshold-based alerts on failed authentication attempts, when they serve different security purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an alert rule in Azure Monitor that triggers when the count of failed authentication events in the Log Analytics workspace exceeds a threshold.
To monitor failed authentication attempts, you must first enable diagnostic settings to collect logs into a Log Analytics workspace. Then, you can create an alert rule that queries those logs and triggers when the count of failed authentication events exceeds a threshold. The other options either address network security, provide general threat detection, or use an unrelated metric, so they do not meet the specific monitoring and alerting requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Azure Defender for AI services to detect anomalies and generate security alerts.
Why it's wrong here
Azure Defender for AI services (part of Microsoft Defender for Cloud) provides threat protection and can generate alerts for suspicious activity, but it is not designed to alert on a specific threshold of failed authentication attempts. It focuses on advanced threats and anomalies. The requirement is for a custom threshold-based alert, which is better achieved with Azure Monitor alert rules on log data. Therefore, this action does not meet the specific need.
- ✗
Create a metric alert on the TotalCalls metric for the Azure AI services resource.
Why it's wrong here
The TotalCalls metric tracks the total number of API calls, not failed authentication attempts. It does not differentiate between successful and failed calls, so it cannot be used to alert on authentication failures. While it can indicate overall usage, it does not provide the granularity needed to detect security issues related to failed logins. This metric is not suitable for the requirement.
- ✗
Configure a private endpoint for the Azure AI services resource to restrict access to a virtual network.
Why it's wrong here
A private endpoint improves network security by restricting access to a virtual network, but it does not provide monitoring or alerting on failed authentication attempts. It addresses network isolation, not the detection of unusual access patterns. While it is a good security practice, it does not help meet the requirement to monitor and alert on authentication failures, so it is not one of the two actions needed.
- ✓
Create an alert rule in Azure Monitor that triggers when the count of failed authentication events in the Log Analytics workspace exceeds a threshold.
Why this is correct
After logs are in Log Analytics, you can create an alert rule that evaluates a log query periodically. The alert rule can count failed authentication events and trigger when the count exceeds your defined threshold. This directly fulfills the requirement to receive alerts on excessive failed authentication attempts. It is the action that turns the collected data into actionable notifications.
- ✓
Enable diagnostic settings on the Azure AI services resource to send logs to a Log Analytics workspace.
Why this is correct
Diagnostic settings must be enabled to collect the logs that record authentication attempts and other operations. Sending these logs to a Log Analytics workspace allows you to query them using Kusto Query Language (KQL) and create alerts based on conditions. Without diagnostic settings, the logs are not retained or available for analysis, so this is a necessary first step to monitor access patterns and failed authentications.
Go deeper
Related to this question
About these practice questions
One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.