Courseiva

AI-900 Practice Question: Describe Artificial Intelligence workloads and considerations

A healthcare organization is developing an AI system to recommend treatment plans for patients based on their medical history. According to Microsoft's responsible AI principles, which principle is most directly concerned with ensuring that the system protects patients' health data from unauthorized access or misuse?

⚠ Common exam trap

A common mix-up: candidates confuse 'Reliability and safety' with data protection, but reliability ensures the system works correctly, not that data is kept private from unauthorized parties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Privacy and security

The Privacy and security principle is most directly concerned with protecting patients' health data from unauthorized access or misuse. In this scenario, the AI system must comply with regulations like HIPAA and GDPR, ensuring data encryption, access controls, and audit logs are in place to safeguard sensitive medical information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Privacy and security

    Why this is correct

    Privacy and security is the correct principle because it directly addresses how AI systems handle sensitive healthcare data. It requires implementing safeguards like encryption, access controls, and data minimization to prevent unauthorized access, theft, or misuse of patient records. Meeting standards such as HIPAA or GDPR depends on these measures, which align perfectly with protecting patient data in a clinical setting.

  • Transparency

    Why it's wrong here

    Transparency is about making the AI system's behavior, capabilities, and limitations understandable to stakeholders, such as through explainability techniques or clear documentation. It aims to build trust by revealing how predictions are made, not by safeguarding data. Since transparency does not involve enforcing encryption, authentication, or data retention policies, it is not the principle that protects patient information from unauthorized exposure.

    When this WOULD be correct

    A question asking which principle requires that patients understand how the AI system uses their medical history to recommend treatments, or that the system's decision-making process is open to audit.

  • Fairness

    Why it's wrong here

    Fairness ensures the AI system does not produce biased outcomes or discriminate against individuals or groups based on protected attributes like race, gender, or socioeconomic status. Fairness techniques focus on mitigating algorithmic bias and achieving equitable treatment, which is crucial for healthcare equity. However, fairness has nothing to do with securing data against breaches or privacy invasions, making it irrelevant to the protection of patient data in this scenario.

    When this WOULD be correct

    A question asking which principle ensures that an AI system does not discriminate against certain patient groups or provides equitable treatment recommendations across demographics would have fairness as the correct answer.

  • Reliability and safety

    Why it's wrong here

    Reliability and safety focuses on an AI system's ability to perform its intended function consistently and without causing physical or operational harm. This includes robustness against errors, drifts in performance, and fail-safe mechanisms for clinical decision support. While important, it does not govern who can access stored data or how that data is protected, so it does not address the specific concern of unauthorized access to sensitive information.

    When this WOULD be correct

    A question asking: 'Which principle ensures that an AI system for medical diagnosis consistently produces accurate results and does not cause patient harm due to errors?' would make reliability and safety the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AI-900 exam frequently reuses these exact scenarios with slightly different constraints.

Privacy and securityCorrect answer

Why this is correct

Privacy and security is the correct principle because it directly addresses how AI systems handle sensitive healthcare data. It requires implementing safeguards like encryption, access controls, and data minimization to prevent unauthorized access, theft, or misuse of patient records. Meeting standards such as HIPAA or GDPR depends on these measures, which align perfectly with protecting patient data in a clinical setting.

TransparencyWrong answer — click to see why

Why this is wrong here

Transparency is about ensuring AI systems are understandable and explainable, not about protecting data from unauthorized access or misuse.

★ When this WOULD be the correct answer

A question asking which principle requires that patients understand how the AI system uses their medical history to recommend treatments, or that the system's decision-making process is open to audit.

Why candidates choose this

Candidates may confuse transparency with security, thinking that being open about data practices implies protection, or they may overgeneralize transparency to include data handling.

FairnessWrong answer — click to see why

Why this is wrong here

The question specifically asks about protecting patients' health data from unauthorized access or misuse, which directly falls under the privacy and security principle, not fairness.

★ When this WOULD be the correct answer

A question asking which principle ensures that an AI system does not discriminate against certain patient groups or provides equitable treatment recommendations across demographics would have fairness as the correct answer.

Why candidates choose this

Candidates may confuse fairness with data protection, thinking that preventing misuse of data is about treating all patients fairly, but fairness focuses on bias and equity, not data security.

Reliability and safetyWrong answer — click to see why

Why this is wrong here

The question specifically asks about protecting health data from unauthorized access or misuse, which falls under privacy and security, not reliability and safety. Reliability and safety focus on system performance and avoiding harm from incorrect outputs, not data protection.

★ When this WOULD be the correct answer

A question asking: 'Which principle ensures that an AI system for medical diagnosis consistently produces accurate results and does not cause patient harm due to errors?' would make reliability and safety the correct answer.

Why candidates choose this

Candidates may confuse 'safety' with data protection, thinking that safeguarding data is part of ensuring system safety, but safety in AI refers to operational robustness and harm prevention from outputs, not data confidentiality.

Analysis generated from the official AI-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 985 original AI-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-900 exam.