AI-900 Practice Question: Describe Artificial Intelligence workloads and considerations
A healthcare organization is developing an AI system to recommend treatment plans for patients based on their medical history. According to Microsoft's responsible AI principles, which principle is most directly concerned with ensuring that the system protects patients' health data from unauthorized access or misuse?
⚠ Common exam trap
A common mix-up: candidates confuse 'Reliability and safety' with data protection, but reliability ensures the system works correctly, not that data is kept private from unauthorized parties.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privacy and security
The Privacy and security principle is most directly concerned with protecting patients' health data from unauthorized access or misuse. In this scenario, the AI system must comply with regulations like HIPAA and GDPR, ensuring data encryption, access controls, and audit logs are in place to safeguard sensitive medical information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privacy and security
Why this is correct
Privacy and security is the correct principle because it directly addresses how AI systems handle sensitive healthcare data. It requires implementing safeguards like encryption, access controls, and data minimization to prevent unauthorized access, theft, or misuse of patient records. Meeting standards such as HIPAA or GDPR depends on these measures, which align perfectly with protecting patient data in a clinical setting.
- ✗
Transparency
Why it's wrong here
Transparency is about making the AI system's behavior, capabilities, and limitations understandable to stakeholders, such as through explainability techniques or clear documentation. It aims to build trust by revealing how predictions are made, not by safeguarding data. Since transparency does not involve enforcing encryption, authentication, or data retention policies, it is not the principle that protects patient information from unauthorized exposure.
When this WOULD be correct
A question asking which principle requires that patients understand how the AI system uses their medical history to recommend treatments, or that the system's decision-making process is open to audit.
- ✗
Fairness
Why it's wrong here
Fairness ensures the AI system does not produce biased outcomes or discriminate against individuals or groups based on protected attributes like race, gender, or socioeconomic status. Fairness techniques focus on mitigating algorithmic bias and achieving equitable treatment, which is crucial for healthcare equity. However, fairness has nothing to do with securing data against breaches or privacy invasions, making it irrelevant to the protection of patient data in this scenario.
When this WOULD be correct
A question asking which principle ensures that an AI system does not discriminate against certain patient groups or provides equitable treatment recommendations across demographics would have fairness as the correct answer.
- ✗
Reliability and safety
Why it's wrong here
Reliability and safety focuses on an AI system's ability to perform its intended function consistently and without causing physical or operational harm. This includes robustness against errors, drifts in performance, and fail-safe mechanisms for clinical decision support. While important, it does not govern who can access stored data or how that data is protected, so it does not address the specific concern of unauthorized access to sensitive information.
When this WOULD be correct
A question asking: 'Which principle ensures that an AI system for medical diagnosis consistently produces accurate results and does not cause patient harm due to errors?' would make reliability and safety the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AI-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Privacy and securityCorrect answer▾
Why this is correct
Privacy and security is the correct principle because it directly addresses how AI systems handle sensitive healthcare data. It requires implementing safeguards like encryption, access controls, and data minimization to prevent unauthorized access, theft, or misuse of patient records. Meeting standards such as HIPAA or GDPR depends on these measures, which align perfectly with protecting patient data in a clinical setting.
✗TransparencyWrong answer — click to see why▾
Why this is wrong here
Transparency is about ensuring AI systems are understandable and explainable, not about protecting data from unauthorized access or misuse.
★ When this WOULD be the correct answer
A question asking which principle requires that patients understand how the AI system uses their medical history to recommend treatments, or that the system's decision-making process is open to audit.
Why candidates choose this
Candidates may confuse transparency with security, thinking that being open about data practices implies protection, or they may overgeneralize transparency to include data handling.
✗FairnessWrong answer — click to see why▾
Why this is wrong here
The question specifically asks about protecting patients' health data from unauthorized access or misuse, which directly falls under the privacy and security principle, not fairness.
★ When this WOULD be the correct answer
A question asking which principle ensures that an AI system does not discriminate against certain patient groups or provides equitable treatment recommendations across demographics would have fairness as the correct answer.
Why candidates choose this
Candidates may confuse fairness with data protection, thinking that preventing misuse of data is about treating all patients fairly, but fairness focuses on bias and equity, not data security.
✗Reliability and safetyWrong answer — click to see why▾
Why this is wrong here
The question specifically asks about protecting health data from unauthorized access or misuse, which falls under privacy and security, not reliability and safety. Reliability and safety focus on system performance and avoiding harm from incorrect outputs, not data protection.
★ When this WOULD be the correct answer
A question asking: 'Which principle ensures that an AI system for medical diagnosis consistently produces accurate results and does not cause patient harm due to errors?' would make reliability and safety the correct answer.
Why candidates choose this
Candidates may confuse 'safety' with data protection, thinking that safeguarding data is part of ensuring system safety, but safety in AI refers to operational robustness and harm prevention from outputs, not data confidentiality.
Analysis generated from the official AI-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Responsible AI Principles
Key term
Responsible AI
A framework of ethical principles and practices that ensure artificial intelligence systems are developed and deployed in a transparent, fair, accountable, and safe manner.
Key term
Privacy and security
Privacy and security refer to the practices and technologies used to protect sensitive data from unauthorized access while ensuring individuals' rights over their personal information are respected.
About these practice questions
One of 985 original AI-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-900 exam.