Microsoft AB-100 Responsible AI Governance and Assurance Practice Test

 

Topic 16 covers Responsible AI, Governance and Assurance for Microsoft AB-100, using the current skills measured as of July 22, 2026 and primary Microsoft documentation. For broader exam preparation, review the AB-100 Exam Dumps page. These are original practice questions, and every option includes a scenario-specific explanation.

Question 1

A governance board is reviewing responsible ai, governance and assurance. The unresolved requirement concerns an agent with several business owners. The current design does not yet establish how accountability should be handled. Which approach best fits the requirement?

  1. Link a model change to reviewer and approval evidence.
  2. Require an explanation appropriate to a high-impact decision.
  3. Correlate a business incident with the deployed configuration.
  4. Assign accountability for an agent with several business owners.
  5. Trace data movement across every dependent service.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—assign accountability for an agent with several business owners—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘link a model change to reviewer and approval evidence’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘require an explanation appropriate to a high-impact decision’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘correlate a business incident with the deployed configuration’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘trace data movement across every dependent service’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 2

The operating model needs an explicit rule for an approval gate proportional to action risk. Which design decision should be recorded?

  1. Record grounding-source changes with reproducible versions.
  2. Define an approval gate proportional to action risk.
  3. Design human oversight with genuine intervention authority.
  4. Set retention from a stated investigation or organizational requirement.
  5. Validate the configured processing region against stated policy.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—define an approval gate proportional to action risk—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘record grounding-source changes with reproducible versions’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘design human oversight with genuine intervention authority’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘set retention from a stated investigation or organizational requirement’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘validate the configured processing region against stated policy’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 3

Before a wider rollout of responsible ai, governance and assurance, the governance board reviews the current evidence. The review has identified a specific issue: maintain an inventory of deployed agents and owners. What should the architect recommend?

  1. Assign accountability for an agent with several business owners.
  2. Maintain an inventory of deployed agents and owners.
  3. Disclose the agent role when user expectations require it.
  4. Include telemetry exports in a residency review in the architecture or business-case boundary before comparing alternatives.
  5. Preserve actor identity in deployment audit records.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—maintain an inventory of deployed agents and owners—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘assign accountability for an agent with several business owners’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘disclose the agent role when user expectations require it’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘include telemetry exports in a residency review’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘preserve actor identity in deployment audit records’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 4

The business requirement is clear, but the current design leaves an exception review process with an expiry unsettled. What should the architect recommend?

  1. Set an exception review process with an expiry.
  2. Assess cross-border transfer introduced by a connector.
  3. Record the control owner and evidence source, then validate the design against responsible-AI, residency, audit, and governance requirements.
  4. Evaluate accessibility barriers in an AI experience.
  5. Protect audit evidence against unauthorized alteration.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—set an exception review process with an expiry—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess cross-border transfer introduced by a connector’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘evaluate accessibility barriers in an ai experience’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect audit evidence against unauthorized alteration’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 5

A pilot for responsible ai, governance and assurance reaches a decision point for the regional data-governance group. The current solution leaves incident escalation for cross-team agent failures unresolved, and the gap is now affecting the stated business or technical requirement. Which action should the team take next?

  1. Check recovery-region behavior under a residency restriction.
  2. Document limitations before expanding a model’s use.
  3. Maintain an inventory of deployed agents and owners.
  4. Correlate a business incident with the deployed configuration.
  5. Define incident escalation for cross-team agent failures.

Correct Answer: E

 

Correct Answer

Answer E is correct because This is correct because it applies the reserved architecture decision—define incident escalation for cross-team agent failures—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘check recovery-region behavior under a residency restriction’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘document limitations before expanding a model’s use’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘maintain an inventory of deployed agents and owners’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘correlate a business incident with the deployed configuration’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 6

During a design workshop on responsible ai, governance and assurance, the compliance architecture team identifies a constraint. The review has identified a specific issue: establish a periodic access and purpose review. Which approach best fits the requirement?

  1. Distinguish storage location from transient processing location and do not treat the two conditions as equivalent.
  2. Choose a remedy because observed harm invalidates prior acceptance is the decisive constraint.
  3. Set an exception review process with an expiry.
  4. Establish a periodic access and purpose review.
  5. Set retention from a stated investigation or organizational requirement.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—establish a periodic access and purpose review—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘distinguish storage location from transient processing location’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘choose a remedy when observed harm invalidates prior acceptance’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘set an exception review process with an expiry’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘set retention from a stated investigation or organizational requirement’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 7

Before a wider rollout of responsible ai, governance and assurance, the audit and assurance team reviews the current evidence. Existing evidence is insufficient to make a safe release or architecture decision about disparate outcomes across affected user groups. What is the best design choice?

  1. Assess disparate outcomes across affected user groups.
  2. Link a model change to reviewer and approval evidence.
  3. Trace data movement across every dependent service.
  4. Define incident escalation for cross-team agent failures.
  5. Assign accountability for an agent with several business owners.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—assess disparate outcomes across affected user groups—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘link a model change to reviewer and approval evidence’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘trace data movement across every dependent service’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘define incident escalation for cross-team agent failures’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘assign accountability for an agent with several business owners’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 8

The responsible AI council is preparing an architecture decision record for responsible ai, governance and assurance. The current solution leaves an explanation appropriate to a high-impact decision unresolved, and the gap is now affecting the stated business or technical requirement. Which approach best fits the requirement?

  1. Record grounding-source changes with reproducible versions.
  2. Define an approval gate proportional to action risk.
  3. Require an explanation appropriate to a high-impact decision.
  4. Validate the configured processing region against stated policy.
  5. Record the control owner and evidence source, then validate the design against responsible-AI, residency, audit, and governance requirements.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—require an explanation appropriate to a high-impact decision—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘record grounding-source changes with reproducible versions’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘define an approval gate proportional to action risk’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘validate the configured processing region against stated policy’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

 

Question 9

The responsible AI council is preparing an architecture decision record for responsible ai, governance and assurance. The current solution leaves human oversight with genuine intervention authority unresolved, and the gap is now affecting the stated business or technical requirement. Which action should the team take next?

  1. Preserve actor identity in deployment audit records.
  2. Maintain an inventory of deployed agents and owners.
  3. Design human oversight with genuine intervention authority.
  4. Include telemetry exports in a residency review in the architecture or business-case boundary before comparing alternatives.
  5. Assess disparate outcomes across affected user groups.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—design human oversight with genuine intervention authority—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘preserve actor identity in deployment audit records’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘maintain an inventory of deployed agents and owners’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘include telemetry exports in a residency review’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess disparate outcomes across affected user groups’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 10

The compliance architecture team is preparing an architecture decision record for responsible ai, governance and assurance. The review has identified a specific issue: disclose the agent role when user expectations require it. Which action should the team take next?

  1. Assess cross-border transfer introduced by a connector.
  2. Disclose the agent role when user expectations require it.
  3. Protect audit evidence against unauthorized alteration.
  4. Require an explanation appropriate to a high-impact decision.
  5. Set an exception review process with an expiry.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—disclose the agent role when user expectations require it—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess cross-border transfer introduced by a connector’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect audit evidence against unauthorized alteration’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘require an explanation appropriate to a high-impact decision’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘set an exception review process with an expiry’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 11

A governance board is reviewing responsible ai, governance and assurance. Existing evidence is insufficient to make a safe release or architecture decision about accessibility barriers in an AI experience. Which action should the team take next?

  1. Define incident escalation for cross-team agent failures.
  2. Correlate a business incident with the deployed configuration.
  3. Check recovery-region behavior under a residency restriction.
  4. Evaluate accessibility barriers in an AI experience.
  5. Design human oversight with genuine intervention authority.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—evaluate accessibility barriers in an AI experience—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘define incident escalation for cross-team agent failures’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘correlate a business incident with the deployed configuration’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘check recovery-region behavior under a residency restriction’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘design human oversight with genuine intervention authority’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 12

The audit and assurance team is preparing an architecture decision record for responsible ai, governance and assurance. The review has identified a specific issue: document limitations before expanding a model’s use. What should the architect recommend?

  1. Establish a periodic access and purpose review.
  2. Set retention from a stated investigation or organizational requirement.
  3. Document limitations before expanding a model’s use.
  4. Record the control owner and evidence source, then validate the design against responsible-AI, residency, audit, and governance requirements.
  5. Distinguish storage location from transient processing location and do not treat the two conditions as equivalent.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—document limitations before expanding a model’s use—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘establish a periodic access and purpose review’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘set retention from a stated investigation or organizational requirement’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘distinguish storage location from transient processing location’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 13

A production-readiness review of responsible ai, governance and assurance gives the regional data-governance group new evidence. The team has confirmed that observed harm invalidates prior acceptance. It must now decide how to proceed. What is the best design choice?

  1. Link a model change to reviewer and approval evidence.
  2. Evaluate accessibility barriers in an AI experience.
  3. Assess disparate outcomes across affected user groups.
  4. Choose a remedy when observed harm invalidates prior acceptance.
  5. Assign accountability for an agent with several business owners.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—choose a remedy when observed harm invalidates prior acceptance—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘link a model change to reviewer and approval evidence’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘evaluate accessibility barriers in an ai experience’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess disparate outcomes across affected user groups’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘assign accountability for an agent with several business owners’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 14

Before a wider rollout of responsible ai, governance and assurance, the regional data-governance group reviews the current evidence. The review has identified a specific issue: trace data movement across every dependent service. Which action should the team take next?

  1. Require an explanation appropriate to a high-impact decision.
  2. Document limitations before expanding a model’s use.
  3. Define an approval gate proportional to action risk.
  4. Trace data movement across every dependent service.
  5. Record grounding-source changes with reproducible versions.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—trace data movement across every dependent service—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘require an explanation appropriate to a high-impact decision’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘document limitations before expanding a model’s use’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘define an approval gate proportional to action risk’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘record grounding-source changes with reproducible versions’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 15

The compliance architecture team is preparing an architecture decision record for responsible ai, governance and assurance. Existing evidence is insufficient to make a safe release or architecture decision about the configured processing region against stated policy. What is the best design choice?

  1. Design human oversight with genuine intervention authority.
  2. Preserve actor identity in deployment audit records.
  3. Validate the configured processing region against stated policy.
  4. Choose a remedy because observed harm invalidates prior acceptance is the decisive constraint.
  5. Maintain an inventory of deployed agents and owners.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—validate the configured processing region against stated policy—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘design human oversight with genuine intervention authority’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘preserve actor identity in deployment audit records’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘choose a remedy when observed harm invalidates prior acceptance’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘maintain an inventory of deployed agents and owners’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 16

A pilot for responsible ai, governance and assurance reaches a decision point for the audit and assurance team. The review has identified a specific issue: include telemetry exports in a residency review. What is the best design choice?

  1. Set an exception review process with an expiry.
  2. Protect audit evidence against unauthorized alteration.
  3. Disclose the agent role when user expectations require it.
  4. Record the control owner and evidence source, then validate the design against responsible-AI, residency, audit, and governance requirements.
  5. Include telemetry exports in a residency review.

Correct Answer: E

 

Correct Answer

Answer E is correct because This is correct because it applies the reserved architecture decision—include telemetry exports in a residency review—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘set an exception review process with an expiry’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect audit evidence against unauthorized alteration’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘disclose the agent role when user expectations require it’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

 

Question 17

Before a wider rollout of responsible ai, governance and assurance, the regional data-governance group reviews the current evidence. Existing evidence is insufficient to make a safe release or architecture decision about cross-border transfer introduced by a connector. Which approach best fits the requirement?

  1. Define incident escalation for cross-team agent failures.
  2. Validate the configured processing region against stated policy.
  3. Correlate a business incident with the deployed configuration.
  4. Assess cross-border transfer introduced by a connector.
  5. Evaluate accessibility barriers in an AI experience.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—assess cross-border transfer introduced by a connector—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘define incident escalation for cross-team agent failures’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘validate the configured processing region against stated policy’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘correlate a business incident with the deployed configuration’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘evaluate accessibility barriers in an ai experience’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 18

Before a wider rollout of responsible ai, governance and assurance, the responsible AI council reviews the current evidence. The review has identified a specific issue: check recovery-region behavior under a residency restriction. Which action should the team take next?

  1. Check recovery-region behavior under a residency restriction.
  2. Document limitations before expanding a model’s use.
  3. Establish a periodic access and purpose review.
  4. Include telemetry exports in a residency review in the architecture or business-case boundary before comparing alternatives.
  5. Set retention from a stated investigation or organizational requirement.

Correct Answer: A

 

Correct Answer

Answer A is correct because This is correct because it applies the reserved architecture decision—check recovery-region behavior under a residency restriction—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘document limitations before expanding a model’s use’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘establish a periodic access and purpose review’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘include telemetry exports in a residency review’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘set retention from a stated investigation or organizational requirement’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 19

During a design workshop on responsible ai, governance and assurance, the audit and assurance team identifies a constraint. Stakeholders are conflating storage location from transient processing location, leading to an incorrect conclusion. What should the architect recommend?

  1. Assess disparate outcomes across affected user groups.
  2. Choose a remedy because observed harm invalidates prior acceptance is the decisive constraint.
  3. Distinguish storage location from transient processing location.
  4. Assess cross-border transfer introduced by a connector.
  5. Assign accountability for an agent with several business owners.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—distinguish storage location from transient processing location—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess disparate outcomes across affected user groups’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘choose a remedy when observed harm invalidates prior acceptance’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess cross-border transfer introduced by a connector’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘assign accountability for an agent with several business owners’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 20

A production-readiness review of responsible ai, governance and assurance gives the responsible AI council new evidence. The unresolved requirement concerns reviewer and approval evidence. The current design does not yet establish how a model change should be handled. What is the best design choice?

  1. Define an approval gate proportional to action risk.
  2. Link a model change to reviewer and approval evidence.
  3. Preserve auditable evidence of approvals, changes, data movement, and exceptions rather than relying on informal governance decisions.
  4. Require an explanation appropriate to a high-impact decision.
  5. Record the control owner and evidence source, then validate the design against responsible-AI, residency, audit, and governance requirements.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—link a model change to reviewer and approval evidence—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘define an approval gate proportional to action risk’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This safeguard can be important in a broader production design, but it is a supporting control rather than the primary decision required by this scenario. Selecting it alone would leave the core architecture choice unresolved.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘require an explanation appropriate to a high-impact decision’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

 

Question 21

A pilot for responsible ai, governance and assurance reaches a decision point for the audit and assurance team. The unresolved requirement concerns reproducible versions. The current design does not yet establish how grounding-source changes should be handled. What should the architect recommend?

  1. Maintain an inventory of deployed agents and owners.
  2. Validate the configured processing region against stated policy.
  3. Record grounding-source changes with reproducible versions.
  4. Distinguish storage location from transient processing location and do not treat the two conditions as equivalent.
  5. Design human oversight with genuine intervention authority.

Correct Answer: C

 

Correct Answer

Answer C is correct because This is correct because it applies the reserved architecture decision—record grounding-source changes with reproducible versions—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘maintain an inventory of deployed agents and owners’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘validate the configured processing region against stated policy’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘distinguish storage location from transient processing location’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘design human oversight with genuine intervention authority’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 22

A pilot for responsible ai, governance and assurance reaches a decision point for the compliance architecture team. The current solution leaves actor identity in deployment audit records unresolved, and the gap is now affecting the stated business or technical requirement. What is the best design choice?

  1. Set an exception review process with an expiry.
  2. Include telemetry exports in a residency review in the architecture or business-case boundary before comparing alternatives.
  3. Link a model change to reviewer and approval evidence.
  4. Preserve actor identity in deployment audit records.
  5. Disclose the agent role when user expectations require it.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—preserve actor identity in deployment audit records—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘set an exception review process with an expiry’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘include telemetry exports in a residency review’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘link a model change to reviewer and approval evidence’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘disclose the agent role when user expectations require it’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 23

A production-readiness review of responsible ai, governance and assurance gives the audit and assurance team new evidence. The unresolved requirement concerns unauthorized alteration. The current design does not yet establish how audit evidence should be handled. Which approach best fits the requirement?

  1. Assess cross-border transfer introduced by a connector.
  2. Define incident escalation for cross-team agent failures.
  3. Evaluate accessibility barriers in an AI experience.
  4. Record grounding-source changes with reproducible versions.
  5. Protect audit evidence against unauthorized alteration.

Correct Answer: E

 

Correct Answer

Answer E is correct because This is correct because it applies the reserved architecture decision—protect audit evidence against unauthorized alteration—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess cross-border transfer introduced by a connector’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘define incident escalation for cross-team agent failures’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘evaluate accessibility barriers in an ai experience’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘record grounding-source changes with reproducible versions’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

 

Question 24

A pilot for responsible ai, governance and assurance reaches a decision point for the regional data-governance group. The unresolved requirement concerns the deployed configuration. The current design does not yet establish how a business incident should be handled. What is the best design choice?

  1. Establish a periodic access and purpose review.
  2. Document limitations before expanding a model’s use.
  3. Check recovery-region behavior under a residency restriction.
  4. Correlate a business incident with the deployed configuration.
  5. Record the control owner and evidence source, then validate the design against responsible-AI, residency, audit, and governance requirements.

Correct Answer: D

 

Correct Answer

Answer D is correct because This is correct because it applies the reserved architecture decision—correlate a business incident with the deployed configuration—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘establish a periodic access and purpose review’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer B is incorrect because This is not the best choice because it addresses the adjacent decision ‘document limitations before expanding a model’s use’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘check recovery-region behavior under a residency restriction’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is a useful verification step after the primary architecture decision, but it does not by itself resolve the decision the scenario asks for. The design choice must be made first, and this evidence can then confirm that the chosen approach behaves as intended.

 

Question 25

Before a wider rollout of responsible ai, governance and assurance, the regional data-governance group reviews the current evidence. The current solution leaves retention from a stated investigation or organizational requirement unresolved, and the gap is now affecting the stated business or technical requirement. Which approach best fits the requirement?

  1. Protect audit evidence against unauthorized alteration.
  2. Set retention from a stated investigation or organizational requirement.
  3. Choose a remedy because observed harm invalidates prior acceptance is the decisive constraint.
  4. Distinguish storage location from transient processing location and do not treat the two conditions as equivalent.
  5. Assess disparate outcomes across affected user groups.

Correct Answer: B

 

Correct Answer

Answer B is correct because This is correct because it applies the reserved architecture decision—set retention from a stated investigation or organizational requirement—to the decisive constraint in the scenario. It keeps the action at the appropriate responsible ai, governance and assurance boundary and produces a result that can be verified before wider deployment.

Incorrect Answers

Answer A is incorrect because This is not the best choice because it addresses the adjacent decision ‘protect audit evidence against unauthorized alteration’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer C is incorrect because This is not the best choice because it addresses the adjacent decision ‘choose a remedy when observed harm invalidates prior acceptance’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer D is incorrect because This is not the best choice because it addresses the adjacent decision ‘distinguish storage location from transient processing location’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

Answer E is incorrect because This is not the best choice because it addresses the adjacent decision ‘assess disparate outcomes across affected user groups’ rather than the scenario’s decisive requirement. Although that action can be valid within responsible ai, governance and assurance, selecting it here would leave the stated constraint unresolved or move the design to the wrong stage.

img