Microsoft AI-103 Responsible AI Controls And Agent Governance Practice Test
This practice topic covers Responsible AI Controls and Agent Governance for Microsoft AI-103. Questions are original and aligned to the current Microsoft skills outline. For broader exam preparation, review the Microsoft AI-103 Exam Dumps page.
Question 1
A workload has a specific constraint: for different risk entry points. The implementation must choose correctly between input and output moderation. Which option best satisfies the constraint?
Correct Answer: A
Correct Answer
Answer A is correct because this choice directly implements the required decision for input versus output moderation for different risk entry points. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer B is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement input versus output moderation for different risk entry points; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement input versus output moderation for different risk entry points; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement input versus output moderation for different risk entry points; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement input versus output moderation for different risk entry points; the decisive requirement in the stem therefore remains unresolved.
Question 2
In a production AI solution, the workload operates under a stated false-positive tolerance. Which action should the engineer take to handle category threshold choice correctly?
Correct Answer: E
Correct Answer
Answer E is correct because this choice directly implements the required decision for category threshold choice under a stated false-positive tolerance. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement category threshold choice under a stated false-positive tolerance; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement category threshold choice under a stated false-positive tolerance; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement category threshold choice under a stated false-positive tolerance; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement category threshold choice under a stated false-positive tolerance; the decisive requirement in the stem therefore remains unresolved.
Question 3
A workload has a specific constraint: where policy specifies review. The implementation must choose correctly between blocking and annotating. Which option best satisfies the constraint?
Correct Answer: D
Correct Answer
Answer D is correct because this choice directly implements the required decision for blocking versus annotating where policy specifies review. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement blocking versus annotating where policy specifies review; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement blocking versus annotating where policy specifies review; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement blocking versus annotating where policy specifies review; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement blocking versus annotating where policy specifies review; the decisive requirement in the stem therefore remains unresolved.
Question 4
A runtime design must distinguish prompt attack detection from harmful-content classification. Which implementation uses the correct capability for the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because this choice directly implements the required decision for prompt attack detection versus harmful-content classification. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement prompt attack detection versus harmful-content classification; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement prompt attack detection versus harmful-content classification; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement prompt attack detection versus harmful-content classification; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement prompt attack detection versus harmful-content classification; the decisive requirement in the stem therefore remains unresolved.
Question 5
In a production AI solution, the control must act before a state-changing tool action. Which action should the engineer take to handle guardrail placement correctly?
Correct Answer: B
Correct Answer
Answer B is correct because this choice directly implements the required decision for guardrail placement before a state-changing tool action. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement guardrail placement before a state-changing tool action; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement guardrail placement before a state-changing tool action; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement guardrail placement before a state-changing tool action; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement guardrail placement before a state-changing tool action; the decisive requirement in the stem therefore remains unresolved.
Question 6
In a production AI solution, the following condition occurs: an acceptable prompt produces unsafe output. Which action should the engineer take to handle risk-specific control correctly?
Correct Answer: A
Correct Answer
Answer A is correct because this choice directly implements the required decision for risk-specific control when an acceptable prompt produces unsafe output. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer B is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement risk-specific control when an acceptable prompt produces unsafe output; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement risk-specific control when an acceptable prompt produces unsafe output; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement risk-specific control when an acceptable prompt produces unsafe output; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement risk-specific control when an acceptable prompt produces unsafe output; the decisive requirement in the stem therefore remains unresolved.
Question 7
In a production AI solution, the following condition occurs: the safety service is unavailable. Which action should the engineer take to handle failure behavior correctly?
Correct Answer: E
Correct Answer
Answer E is correct because this choice directly implements the required decision for failure behavior when the safety service is unavailable. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement failure behavior when the safety service is unavailable; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement failure behavior when the safety service is unavailable; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement failure behavior when the safety service is unavailable; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would block every request in the category even though the policy requires differentiated handling. That can address a neighboring concern, but it does not implement failure behavior when the safety service is unavailable; the decisive requirement in the stem therefore remains unresolved.
Question 8
In a production AI solution, the required outcome is the specified harm dimension. Which action should the engineer take to handle safety evaluator selection correctly?
Correct Answer: D
Correct Answer
Answer D is correct because this choice directly implements the required decision for safety evaluator selection for the specified harm dimension. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement safety evaluator selection for the specified harm dimension; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would block every request in the category even though the policy requires differentiated handling. That can address a neighboring concern, but it does not implement safety evaluator selection for the specified harm dimension; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement safety evaluator selection for the specified harm dimension; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement safety evaluator selection for the specified harm dimension; the decisive requirement in the stem therefore remains unresolved.
Question 9
A runtime design must distinguish groundedness evidence from fluency scores. Which implementation uses the correct capability for the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because this choice directly implements the required decision for groundedness evidence versus fluency scores. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement groundedness evidence versus fluency scores; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would apply the policy only in the client UI while leaving the service endpoint unrestricted. That can address a neighboring concern, but it does not implement groundedness evidence versus fluency scores; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would block every request in the category even though the policy requires differentiated handling. That can address a neighboring concern, but it does not implement groundedness evidence versus fluency scores; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement groundedness evidence versus fluency scores; the decisive requirement in the stem therefore remains unresolved.
Question 10
In a production AI solution, the required outcome is a known attack surface. Which action should the engineer take to handle adversarial evaluation set correctly?
Correct Answer: B
Correct Answer
Answer B is correct because this choice directly implements the required decision for adversarial evaluation set for a known attack surface. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would apply the policy only in the client UI while leaving the service endpoint unrestricted. That can address a neighboring concern, but it does not implement adversarial evaluation set for a known attack surface; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement adversarial evaluation set for a known attack surface; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement adversarial evaluation set for a known attack surface; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would block every request in the category even though the policy requires differentiated handling. That can address a neighboring concern, but it does not implement adversarial evaluation set for a known attack surface; the decisive requirement in the stem therefore remains unresolved.
Question 11
In a production AI solution, the following condition occurs: automated safety labels conflict. Which action should the engineer take to handle human adjudication correctly?
Correct Answer: A
Correct Answer
Answer A is correct because this choice directly implements the required decision for human adjudication when automated safety labels conflict. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer B is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement human adjudication when automated safety labels conflict; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement human adjudication when automated safety labels conflict; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement human adjudication when automated safety labels conflict; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement human adjudication when automated safety labels conflict; the decisive requirement in the stem therefore remains unresolved.
Question 12
An agentic application must handle explanation tooling that links a decision to available evidence. Which control or implementation should the developer use?
Correct Answer: E
Correct Answer
Answer E is correct because this choice directly implements the required decision for explanation tooling that links a decision to available evidence. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would block every request in the category even though the policy requires differentiated handling. That can address a neighboring concern, but it does not implement explanation tooling that links a decision to available evidence; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement explanation tooling that links a decision to available evidence; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement explanation tooling that links a decision to available evidence; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement explanation tooling that links a decision to available evidence; the decisive requirement in the stem therefore remains unresolved.
Question 13
In a production AI solution, the following condition occurs: domain terms trigger false positives. Which action should the engineer take to handle evaluator calibration correctly?
Correct Answer: D
Correct Answer
Answer D is correct because this choice directly implements the required decision for evaluator calibration when domain terms trigger false positives. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would apply the policy only in the client UI while leaving the service endpoint unrestricted. That can address a neighboring concern, but it does not implement evaluator calibration when domain terms trigger false positives; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement evaluator calibration when domain terms trigger false positives; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement evaluator calibration when domain terms trigger false positives; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement evaluator calibration when domain terms trigger false positives; the decisive requirement in the stem therefore remains unresolved.
Question 14
An agentic application must handle trace correlation needed to reconstruct an agent action. Which control or implementation should the developer use?
Correct Answer: C
Correct Answer
Answer C is correct because this choice directly implements the required decision for trace correlation needed to reconstruct an agent action. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement trace correlation needed to reconstruct an agent action; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement trace correlation needed to reconstruct an agent action; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would block every request in the category even though the policy requires differentiated handling. That can address a neighboring concern, but it does not implement trace correlation needed to reconstruct an agent action; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement trace correlation needed to reconstruct an agent action; the decisive requirement in the stem therefore remains unresolved.
Question 15
An agentic application must handle provenance fields needed to identify the retrieved source version. Which control or implementation should the developer use?
Correct Answer: B
Correct Answer
Answer B is correct because this choice directly implements the required decision for provenance fields needed to identify the retrieved source version. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement provenance fields needed to identify the retrieved source version; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would block every request in the category even though the policy requires differentiated handling. That can address a neighboring concern, but it does not implement provenance fields needed to identify the retrieved source version; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would apply the policy only in the client UI while leaving the service endpoint unrestricted. That can address a neighboring concern, but it does not implement provenance fields needed to identify the retrieved source version; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement provenance fields needed to identify the retrieved source version; the decisive requirement in the stem therefore remains unresolved.
Question 16
An agentic application must handle approval evidence binding to the exact authorized action. Which control or implementation should the developer use?
Correct Answer: A
Correct Answer
Answer A is correct because this choice directly implements the required decision for approval evidence binding to the exact authorized action. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer B is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement approval evidence binding to the exact authorized action; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement approval evidence binding to the exact authorized action; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement approval evidence binding to the exact authorized action; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would apply the policy only in the client UI while leaving the service endpoint unrestricted. That can address a neighboring concern, but it does not implement approval evidence binding to the exact authorized action; the decisive requirement in the stem therefore remains unresolved.
Question 17
An agentic application must handle sensitive-data minimization in retained audit logs. Which control or implementation should the developer use?
Correct Answer: E
Correct Answer
Answer E is correct because this choice directly implements the required decision for sensitive-data minimization in retained audit logs. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement sensitive-data minimization in retained audit logs; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement sensitive-data minimization in retained audit logs; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement sensitive-data minimization in retained audit logs; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement sensitive-data minimization in retained audit logs; the decisive requirement in the stem therefore remains unresolved.
Question 18
In a production AI solution, the workload operates under an explicit fictional policy. Which action should the engineer take to handle audit retention correctly?
Correct Answer: D
Correct Answer
Answer D is correct because this choice directly implements the required decision for audit retention under an explicit fictional policy. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement audit retention under an explicit fictional policy; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement audit retention under an explicit fictional policy; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would apply the policy only in the client UI while leaving the service endpoint unrestricted. That can address a neighboring concern, but it does not implement audit retention under an explicit fictional policy; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement audit retention under an explicit fictional policy; the decisive requirement in the stem therefore remains unresolved.
Question 19
In a production AI solution, the required outcome is prompts and tool permissions. Which action should the engineer take to handle tamper-evident change history correctly?
Correct Answer: C
Correct Answer
Answer C is correct because this choice directly implements the required decision for tamper-evident change history for prompts and tool permissions. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement tamper-evident change history for prompts and tool permissions; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement tamper-evident change history for prompts and tool permissions; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement tamper-evident change history for prompts and tool permissions; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement tamper-evident change history for prompts and tool permissions; the decisive requirement in the stem therefore remains unresolved.
Question 20
A runtime design must distinguish oversight mode for reversible from consequential actions. Which implementation uses the correct capability for the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because this choice directly implements the required decision for oversight mode for reversible versus consequential actions. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement oversight mode for reversible versus consequential actions; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement oversight mode for reversible versus consequential actions; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement oversight mode for reversible versus consequential actions; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement oversight mode for reversible versus consequential actions; the decisive requirement in the stem therefore remains unresolved.
Question 21
In a production AI solution, the required outcome is a narrowly defined agent role. Which action should the engineer take to handle tool allowlist correctly?
Correct Answer: A
Correct Answer
Answer A is correct because this choice directly implements the required decision for tool allowlist for a narrowly defined agent role. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer B is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement tool allowlist for a narrowly defined agent role; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement tool allowlist for a narrowly defined agent role; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would block every request in the category even though the policy requires differentiated handling. That can address a neighboring concern, but it does not implement tool allowlist for a narrowly defined agent role; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement tool allowlist for a narrowly defined agent role; the decisive requirement in the stem therefore remains unresolved.
Question 22
An agentic application must handle execution budget that limits runaway autonomous behavior. Which control or implementation should the developer use?
Correct Answer: E
Correct Answer
Answer E is correct because this choice directly implements the required decision for execution budget that limits runaway autonomous behavior. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement execution budget that limits runaway autonomous behavior; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement execution budget that limits runaway autonomous behavior; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would let retrieved or image-embedded instructions override the system policy. That can address a neighboring concern, but it does not implement execution budget that limits runaway autonomous behavior; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement execution budget that limits runaway autonomous behavior; the decisive requirement in the stem therefore remains unresolved.
Question 23
In a production AI solution, the following condition occurs: requested work exceeds agent authority. Which action should the engineer take to handle escalation boundary correctly?
Correct Answer: D
Correct Answer
Answer D is correct because this choice directly implements the required decision for escalation boundary when requested work exceeds agent authority. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement escalation boundary when requested work exceeds agent authority; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement escalation boundary when requested work exceeds agent authority; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement escalation boundary when requested work exceeds agent authority; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement escalation boundary when requested work exceeds agent authority; the decisive requirement in the stem therefore remains unresolved.
Question 24
In a production AI solution, the following condition occurs: user authorization is narrower than agent access. Which action should the engineer take to handle delegated tool access correctly?
Correct Answer: C
Correct Answer
Answer C is correct because this choice directly implements the required decision for delegated tool access when user authorization is narrower than agent access. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement delegated tool access when user authorization is narrower than agent access; the decisive requirement in the stem therefore remains unresolved.
Answer B is incorrect because this choice would record the action only after execution and omit a pre-action approval for irreversible changes. That can address a neighboring concern, but it does not implement delegated tool access when user authorization is narrower than agent access; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would trust a fluent response as proof that the output is grounded and safe. That can address a neighboring concern, but it does not implement delegated tool access when user authorization is narrower than agent access; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement delegated tool access when user authorization is narrower than agent access; the decisive requirement in the stem therefore remains unresolved.
Question 25
In a production AI solution, the condition appears after an observed policy violation. Which action should the engineer take to handle revocation of tool privileges correctly?
Correct Answer: B
Correct Answer
Answer B is correct because this choice directly implements the required decision for revocation of tool privileges after an observed policy violation. It addresses the scenario at the correct stage of the Azure AI solution.
Incorrect Answers
Answer A is incorrect because this choice would apply the policy only in the client UI while leaving the service endpoint unrestricted. That can address a neighboring concern, but it does not implement revocation of tool privileges after an observed policy violation; the decisive requirement in the stem therefore remains unresolved.
Answer C is incorrect because this choice would suppress safety telemetry so the aggregate pass rate improves. That can address a neighboring concern, but it does not implement revocation of tool privileges after an observed policy violation; the decisive requirement in the stem therefore remains unresolved.
Answer D is incorrect because this choice would give the agent broad standing permissions so authorization failures cannot occur. That can address a neighboring concern, but it does not implement revocation of tool privileges after an observed policy violation; the decisive requirement in the stem therefore remains unresolved.
Answer E is incorrect because this choice would rely on prompt instructions alone and omit an independent enforcement control. That can address a neighboring concern, but it does not implement revocation of tool privileges after an observed policy violation; the decisive requirement in the stem therefore remains unresolved.
Popular posts
Recent Posts
