AI-102 Plan and manage an Azure AI solution Practice Question
You need to enforce that only users from your Microsoft Entra ID tenant can call your Azure AI Language API endpoint. Which security mechanism should you configure?
⚠ Common exam trap
Many exam-takers confuse network-level controls (IP whitelist, Azure Firewall) with identity-level controls, mistakenly thinking that restricting by IP address or network firewall is sufficient to enforce tenant-specific access, when in fact only Entra ID authentication can validate the caller's tenant membership.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID authentication
Microsoft Entra ID authentication (formerly Azure AD) allows you to enforce that only users and applications from your specific Entra ID tenant can call the Azure AI Language API. This is achieved by configuring a managed identity or service principal and assigning it the Cognitive Services User role, which ensures that tokens issued by your tenant are required for access. API keys and IP whitelists do not provide tenant-level identity enforcement, and Azure Firewall is a network-level control that does not authenticate individual users or applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID authentication
Why this is correct
Microsoft Entra ID authentication validates bearer tokens issued by your tenant, so only principals within that tenant can call the endpoint. This enforces the tenant restriction directly, unlike key-based access which any key holder can use.
- ✗
API key authentication
Why it's wrong here
API keys authenticate the calling application, not the user's identity, so any holder of the key—including external parties—can call the endpoint; they cannot verify tenant membership. Keys suit service-to-service access where caller identity is irrelevant. Microsoft Entra ID authentication is required to restrict access to your tenant's users.
- ✗
IP whitelist
Why it's wrong here
An IP whitelist restricts callers by network address, so any user outside the permitted ranges is blocked regardless of tenant membership, and tenant users on other networks are excluded. It suits fixed-egress scenarios such as on-premises gateways, not identity-based access control.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall filters network traffic by IP address, port and protocol at the perimeter, so it cannot validate Entra ID tenant membership or issue tokens for API calls. It is tempting because it genuinely restricts access to known source addresses, and would be the right choice for blocking traffic from specific public IP ranges reaching your virtual network.
Go deeper
Related to this question
About these practice questions
One of 761 original AI-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.