AI-102 Plan and manage an Azure AI solution Practice Question
Your organization needs to monitor Azure AI services for unusual activity patterns that might indicate a security threat. Which Microsoft security solution should you use?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Sentinel with Microsoft Defender XDR, assuming that 'security monitoring' always falls under Defender, but Sentinel is the SIEM solution required for ingesting and analyzing logs from Azure AI services, while Defender XDR focuses on endpoint and identity protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution. It is specifically designed to ingest logs from Azure AI services, apply analytics to detect unusual activity patterns, and generate alerts for potential security threats, making it the correct choice for monitoring AI services for security anomalies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune manages device enrolment, configuration profiles and compliance policies for endpoints; it does not analyse Azure AI service telemetry for anomalous or malicious activity. It is tempting because Intune enforces security baselines, but endpoint management addresses device posture, not runtime threat detection in cloud AI workloads.
- ✗
Microsoft Defender XDR
Why it's wrong here
Microsoft Defender XDR correlates signals across endpoints, identities, email and cloud apps, but Azure AI service threat monitoring sits with Microsoft Defender for Cloud's AI workload protection. Defender XDR is tempting because it is a security detection suite, yet it lacks the AI-service telemetry coverage this scenario requires.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview governs data discovery, classification, lineage and compliance posture, not threat detection across AI workloads. It is tempting because Purview surfaces sensitive-data exposure in AI services, but unusual-activity monitoring against security threats requires Microsoft Defender for Cloud's AI threat protection rather than a data-governance platform.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a cloud-native SIEM and SOAR platform that ingests logs from Azure AI services and applies analytics rules and machine learning to detect anomalous activity patterns, satisfying the requirement to monitor for unusual behaviour indicating a security threat.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AI-102 question from scratch — 761 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.