Courseiva

AI-900 Practice Question: Describe Artificial Intelligence workloads and considerations

What is 'AI governance' and what tools does Azure provide for it?

⚠ Common exam trap

It's easy for candidates to confuse 'AI governance' with external regulation (Option A) or a specific approval process (Option C), rather than recognizing it as the internal framework of policies and controls that Azure implements through tools like Azure Policy and RBAC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The policies, processes, and controls ensuring AI systems are developed and operated responsibly

AI governance refers to the framework of policies, processes, and controls that guide the responsible development, deployment, and operation of AI systems. Azure provides tools like Azure Policy, Azure Role-Based Access Control (RBAC), and Microsoft Purview to enforce governance rules, audit AI usage, and ensure compliance with ethical standards. Option B correctly captures this definition, as it focuses on the organizational and technical mechanisms for responsible AI, not external restrictions or certifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Government regulation that prohibits certain types of AI systems

    Why it's wrong here

    Government regulation that prohibits certain types of AI systems is external legislation, which is distinct from an organisation's own AI governance. AI governance is the organisation's internal set of policies, processes, and controls for managing AI responsibly, while government regulation represents legal constraints imposed from outside. Furthermore, governance is broader than prohibition: it includes enabling responsible innovation, defining acceptable uses, monitoring bias and drift, and maintaining audit trails, none of which are captured by simply banning certain systems.

  • The policies, processes, and controls ensuring AI systems are developed and operated responsibly

    Why this is correct

    This is the correct definition because AI governance is precisely the framework of policies, processes, and controls that guide responsible AI development and operation across the system's lifecycle. It covers areas such as fairness, reliability, privacy, security, transparency, and accountability, and is operationalised through tools like Azure Machine Learning's Responsible AI dashboard, which provides model explanations, fairness assessment, error analysis, and counterfactuals. Effective governance requires continuous oversight, auditing, and feedback loops, not just a one-time review or external rule.

  • Electing a board of AI experts to approve all AI projects before they go to production

    Why it's wrong here

    Electing a board of AI experts to approve all AI projects before they go to production is too narrow to define AI governance. While an approval board can be one governance mechanism, true AI governance encompasses a broader system of policies, processes, and controls that operate throughout the entire AI lifecycle, including data preparation, model training, evaluation, deployment, and ongoing monitoring. It also includes auditing, fairness checks, transparency requirements, and incident response procedures that cannot be reduced to a single pre-production gate.

  • Restricting AI development to organisations with formal AI certifications

    Why it's wrong here

    Restricting AI development to organisations with formal AI certifications describes an external assurance or accreditation scheme, not the internal governance practice itself. AI governance refers to how an organisation structures its own policies, procedures, and controls to ensure responsible development and operation of AI systems. Certification programs may support compliance or maturity assessment, but they do not capture the ongoing, embedded practices like bias mitigation, explainability, and model monitoring that governance requires within each organisation.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AI-900 question is part of Courseiva's 985-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-900 exam.