AI-102 Implement generative AI solutions Practice Question
You are using Azure OpenAI Service to generate code snippets for a development team. You notice that the generated code sometimes contains security vulnerabilities. You need to minimize the risk of generating insecure code while maintaining productivity. What should you do?
⚠ Common exam trap
The trap here is that candidates may overestimate the effectiveness of fine-tuning (Option B) for security, not realizing that system messages are a simpler, more practical first-line defense in Azure OpenAI Service, while fine-tuning is better suited for domain-specific style or knowledge rather than real-time safety constraints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use system messages to instruct the model to prioritize security
System messages in Azure OpenAI Service allow you to set the context and behavior of the model, including instructing it to prioritize security when generating code. This approach directly influences the model's output without requiring retraining or sacrificing flexibility, making it the most effective way to reduce security vulnerabilities while maintaining productivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use system messages to instruct the model to prioritize security
Why this is correct
System messages set persistent behavioural instructions applied to every request, so embedding a security-first directive steers the model away from vulnerable patterns such as unsanitised input handling, satisfying the requirement to reduce insecure output without adding review overhead.
- ✗
Fine-tune the model on a dataset of secure code
Why it's wrong here
Fine-tuning teaches style and format from examples; it does not reliably suppress insecure patterns, and a secure-code dataset cannot cover every vulnerability class. It is tempting because fine-tuning genuinely customises behaviour for domain-specific tasks such as adopting a house coding standard, but the stem needs prompt-level grounding in secure coding guidance.
- ✗
Set the temperature parameter to 0
Why it's wrong here
Temperature 0 makes sampling deterministic, selecting the highest-probability token; it does not remove insecure patterns already present in the model's distribution. It is tempting because low temperature suits reproducible, factual outputs such as structured extraction, but determinism is orthogonal to whether the emitted code is secure.
- ✗
Disable content filtering to allow more flexibility
Why it's wrong here
Disabling content filtering removes the safety layer that screens prompts and completions, so insecure or harmful code becomes likelier, not rarer. It is tempting because filtering can block legitimate code patterns, and disabling it suits scenarios needing unfiltered output under an approved exemption, not vulnerability reduction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.