Courseiva

AI-102 Plan and manage an Azure AI solution Practice Question

You are planning a new Azure AI solution that will use Azure AI Language, Azure AI Vision, and Azure OpenAI. The security team requires that all service credentials be managed centrally, rotated automatically, and never stored in source code or application configuration files. You need to configure the application to retrieve the endpoint and key for each service at runtime. What should you use?

⚠ Common exam trap

The trap here is assuming any configuration service that can store strings is an acceptable secret store, when only Azure Key Vault provides the managed rotation and access control required for credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the keys in Azure Key Vault and retrieve them at runtime by using the Azure Key Vault SDK with a managed identity.

Central secret management with automatic rotation and credential-free access is provided by Azure Key Vault combined with managed identities. Retrieving secrets at runtime through the Key Vault SDK means no key material is ever written into source code or configuration files. The other options either store secrets in non-secret stores or rely on credentials that themselves must be protected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the keys in an Azure Storage account table and retrieve them by using a shared access signature.

    Why it's wrong here

    Azure Table storage is not a secret store and provides no automatic rotation or fine-grained secret access auditing. A shared access signature is itself a credential that must be protected, creating a circular secret-management problem. This approach also exposes keys through a data-plane API that is not designed for credential retrieval.

  • ✗

    Store the keys in environment variables on each Azure App Service instance and read them by using the configuration API.

    Why it's wrong here

    Environment variables are visible in the App Service configuration blade, deployment slots, and process dumps, and they are not rotated automatically. They also require manual updates per instance and do not provide central secret management or auditing, so they do not meet the requirement to avoid storing credentials in application configuration.

  • ✗

    Store the keys in an Azure App Configuration store and load them on application startup by using the App Configuration provider.

    Why it's wrong here

    Azure App Configuration is designed for feature flags and non-secret configuration settings. Although it can reference Key Vault secrets, storing the raw keys directly in App Configuration does not provide the centralized secret lifecycle, access auditing, or automatic rotation required by the security team, so it fails the stated requirements.

  • ✓

    Store the keys in Azure Key Vault and retrieve them at runtime by using the Azure Key Vault SDK with a managed identity.

    Why this is correct

    Azure Key Vault stores secrets centrally and supports automatic rotation through versioning. A managed identity assigned to the application authenticates to Key Vault without embedded credentials, and the Azure Key Vault SDK retrieves the current secret version at runtime. This satisfies central management, rotation, and no secrets in code or configuration files for all three Azure AI services.

About these practice questions

This AI-102 question is part of Courseiva's 761-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.