AI-103 sample questions with answers

10 free practice questions for the Microsoft Certified: Azure AI App and Agent Developer Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Plan and manage an Azure AI solution

A refunds agent in Foundry Agent Service calls a payment tool. Policy states that any refund above 500 US dollars must be authorised by a human before money moves, and that the authorisation must be auditable. The agent otherwise runs unattended. How should you enforce the policy?

  1. A.

    Lower the model temperature so that the agent behaves deterministically when it handles refunds

  2. B.

    Add refund-related terms to a guardrail blocklist so that large refund requests are blocked

  3. C.

    Have the payment tool refuse refunds above 500 USD unless a logged human approval is attached

  4. D.

    Add a sentence to the agent instructions telling it to confirm large refunds with the user first

Show answer

Answer: C

The threshold must be enforced where the money moves: the payment tool itself refuses large refunds unless a recorded human approval accompanies the call.

  • A. Lower temperature makes wording more predictable but does not restrict which tools the agent may call.
  • B. A text blocklist cannot evaluate a numeric argument on a tool call and would block ordinary refund conversations.
  • C. The tool enforces the 500-dollar constraint in code and needs a logged human approval, so the rule can't be bypassed and every decision is auditable.
  • D. Instructions are advisory and can be argued away, and asking the customer is not an authorisation by the business.
Question 2Plan and manage an Azure AI solution

A team edits agent instructions and model versions by hand in the Foundry portal and then repeats the edits in production. Two releases have already regressed answer quality. You must make promotion repeatable and stop regressions from reaching production. What should you do?

  1. A.

    Export the production agent definition to a file after each change so that it can be restored quickly

  2. B.

    Use one shared Foundry project for development and production, and separate the environments by naming convention

  3. C.

    Deploy each environment from source control with infrastructure as code, and gate releases on an evaluation run

  4. D.

    Give only the lead developer write access to the production project and require a change ticket for portal edits

Show answer

Answer: C

Versioned definitions deployed by a pipeline make promotion repeatable, and an automated evaluation gate blocks quality regressions before production.

  • A. Post-hoc export is a rollback aid; it detects nothing and prevents no regression.
  • B. A single shared project removes environment isolation, so experiments can affect production traffic.
  • C. Source-controlled definitions plus pipeline deployment fix repeatability, and an evaluation gate blocks quality regressions.
  • D. Access control reduces accidental edits but the promotion stays manual and quality stays unmeasured.
Question 3Plan and manage an Azure AI solution

A German insurer must prove that every inference request for its claims assistant is processed only inside the Azure geography that contains the Foundry resource (Germany). Processing elsewhere in the EU is not acceptable. Traffic is moderate and bursty. Which deployment option satisfies the filing?

  1. A.

    A Global Standard deployment, because the Entra ID tenant is in Germany

  2. B.

    A Standard deployment on a resource in a German region

  3. C.

    A Data Zone Standard deployment in the EU data zone

  4. D.

    A Global Batch deployment with a German storage account for files

Show answer

Answer: B

A Standard deployment on a resource in a German region keeps processing inside that Azure geography; data zone and global types route more widely.

  • A. Global routing can process requests in any region, and Entra ID tenancy does not constrain processing location.
  • B. Standard keeps processing inside the Azure geography of the resource, so requests never leave Germany.
  • C. The EU data zone can process requests anywhere in the EU Data Boundary, which the filing forbids.
  • D. Batch is asynchronous and its global scope breaks the Germany-only processing guarantee.
Question 4Plan and manage an Azure AI solution

Before a public launch, you must produce evidence of how a grounded assistant behaves when it is attacked: when a user tries to elicit harmful content, and when a retrieved document contains hidden instructions. The evidence must be reproducible for the release record. Which two actions should you perform? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    Run the fluency and coherence evaluators over the standard question set

  2. B.

    Run the indirect attack evaluator over a dataset whose retrieved context contains injected instructions

  3. C.

    Set every guardrail harm category to its strictest threshold before the launch

  4. D.

    Run an AI Red Teaming Agent scan and score the responses with the risk and safety evaluators

  5. E.

    Measure average response latency under load with a performance test

  6. F.

    Ask the support team to try to break the assistant for one day and summarise what they found

Show answer

Answer: B, D

An AI Red Teaming Agent scan scores automated attacks with the risk and safety evaluators, and the indirect attack evaluator covers instructions hidden in retrieved content; both produce reproducible scored results.

  • A. Fluency and coherence measure writing quality on benign inputs, not resistance to attack.
  • B. The indirect attack evaluator is the specific measure for instructions injected through retrieved context.
  • C. Tightening thresholds changes behaviour without generating any evidence, and may block legitimate content.
  • D. Automated red teaming with the risk and safety evaluators produces a reproducible attack success rate for direct attacks.
  • E. Latency is a performance attribute and says nothing about behaviour under attack.
  • F. An informal bug bash yields anecdotes rather than a reproducible, comparable metric for the release record.
Question 5Plan and manage an Azure AI solution

Fabrikam is grounding an assistant in 90,000 maintenance procedures. Technicians describe symptoms in their own words, but they also paste exact part codes such as FX-4471-B that must match literally. Recall must stay high for both query styles, and the top five passages sent to the model must be ordered by true relevance. Which retrieval configuration should you use?

  1. A.

    Keyword retrieval only, with a synonym map for common symptom words

  2. B.

    Hybrid vector and keyword retrieval, reranked by the semantic ranker

  3. C.

    Vector-only retrieval with a larger number of nearest neighbours

  4. D.

    Fine-tune the chat model on all 90,000 procedures and query it directly

Show answer

Answer: B

Hybrid retrieval covers paraphrases and literal codes at once, and the semantic ranker reorders the fused list so the best five passages reach the model.

  • A. Keyword-only matching fails on paraphrased symptoms, and a synonym map cannot enumerate free-form language.
  • B. Hybrid retrieval handles both paraphrases and exact codes, and semantic ranking fixes the ordering of the fused list.
  • C. Vector search represents rare alphanumeric codes poorly, so exact part codes stay missed however many neighbours are returned.
  • D. Fine-tuning adapts style and format, not a factual corpus, and it cannot cite the procedure that produced an answer.
Question 6Plan and manage an Azure AI solution

Woodgrove Bank is building an account-servicing agent in Foundry Agent Service. A customer conversation may pause for days and then continue, and the client application must not resend the whole transcript on every turn. Product answers must come only from 400 approved policy PDFs. Which two capabilities should you use? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    Connect the agent to a knowledge source that retrieves passages from an index built over the 400 policy PDFs

  2. B.

    Store the transcript in the application database and prepend it to every request

  3. C.

    Raise the temperature and the maximum response length so the model recalls more detail

  4. D.

    Keep the turns in a service-side agent conversation and send only each new message with its conversation ID

  5. E.

    Add the code interpreter tool so the agent can read the PDFs at run time

  6. F.

    Fine-tune the base model on the text of the 400 policy PDFs

Show answer

Answer: A, D

A Foundry Agent Service conversation keeps the turns on the service side, and a knowledge source such as the Azure AI Search tool or a Foundry IQ knowledge base over the PDFs supplies grounded, citable answers.

  • A. A retrieval-based knowledge source grounds answers in the approved PDFs and returns citations that can be audited.
  • B. Resending the full transcript is exactly what the requirement rules out, and it grows the prompt without bound.
  • C. Temperature and response length control generation behaviour and add no knowledge or memory.
  • D. A service-side conversation stores the prior turns, so the client sends only the new message and the conversation ID.
  • E. The code interpreter executes code in a sandbox; it is not a semantic retrieval mechanism over a document corpus.
  • F. Fine-tuning encodes style, not a changing factual corpus, and produces no citation for an answer.
Question 7Plan and manage an Azure AI solution

Munson's Pickles plans a new multi-agent process in which a triage agent, a pricing agent and a compliance agent hand work to each other with branching and a human approval step. The solution must go into production in early 2027. Which approach should you use to orchestrate the agents?

  1. A.

    Build the orchestration with Microsoft Agent Framework and deploy it as a hosted agent

  2. B.

    Build the process in a Foundry workflow, which is in preview and retiring on December 1, 2026

  3. C.

    Give one prompt agent all three roles in a single long system message

  4. D.

    Chain three model deployments from the client with ad hoc HTTP calls

Show answer

Answer: A

Foundry is retiring workflows on December 1, 2026, and Learn directs new orchestration to Microsoft Agent Framework, which a hosted agent runs in production.

  • A. Learn directs new workflow development to Microsoft Agent Framework, and hosted agents run that code in production.
  • B. Foundry workflows are preview and retire on December 1, 2026, before the planned go-live.
  • C. One prompt cannot provide explicit branching, hand-offs and an enforced approval step between roles.
  • D. Client-side chaining leaves orchestration, state and approvals to custom code with no agent runtime.
Question 8Plan and manage an Azure AI solution

Bellows College needs two custom metrics that the built-in evaluators don't cover: whether every answer stays under 120 words, and whether the tone suits first-year students. Custom evaluators are in preview. Which two evaluator types should you create? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    A prompt-based evaluator for the word limit

  2. B.

    The document retrieval evaluator for both

  3. C.

    A prompt-based evaluator for the tone

  4. D.

    The built-in fluency evaluator for the tone

  5. E.

    A code-based evaluator for the word limit

Show answer

Answer: C, E

Deterministic rules such as a word limit fit a code-based evaluator; subjective judgments such as tone fit a prompt-based (LLM judge) evaluator.

  • A. An LLM judge adds cost and variance to a check that code handles exactly.
  • B. It measures search ranking against relevance labels.
  • C. A judge prompt suits subjective judgments such as tone.
  • D. Fluency measures linguistic quality, not suitability for an audience.
  • E. A Python grade() function suits deterministic rule checks such as length limits.
Question 9Plan and manage an Azure AI solution

Wide World Importers added Hate controls at the Tool call and Tool response points (preview) of its agent's guardrail. Calls to the OpenAPI tool are scanned, but content sent to and from the code interpreter isn't. What explains this?

  1. A.

    Tool controls apply only to model deployments

  2. B.

    The guardrail must also be assigned to the tool

  3. C.

    The code interpreter lacks tool moderation support

  4. D.

    The Hate severity threshold must be set to Low for tool calls

Show answer

Answer: C

Tool call and tool response controls require moderation support from the tool; Learn lists Azure AI Search, Azure Functions, OpenAPI, SharePoint, Fabric, Bing and Browser Automation, and controls don't take effect for other tools.

  • A. Tool call and tool response apply to agents only, not to models.
  • B. Guardrails are assigned to models and agents, not to individual tools.
  • C. Tool intervention points need moderation support from the tool, and the code interpreter isn't listed.
  • D. The threshold changes sensitivity; it can't make an unsupported tool scannable.
Question 10Plan and manage an Azure AI solution

Traces from Woodgrove Bank's agents include customer prompts and tool results with personal data. Operations engineers must keep access to latency and error telemetry, while only a small privacy team may read message content. Sensitive content already lands in the AppGenAIContent table. What should you do?

  1. A.

    Protect AppGenAIContent and grant the privacy team Privileged Monitoring Data Reader

  2. B.

    Give every engineer Log Analytics Contributor on the workspace so they can read all tables

  3. C.

    Store the prompts in span attributes with a custom name

  4. D.

    Remove Application Insights so that no traces are stored

Show answer

Answer: A

Foundry routes sensitive trace content to the AppGenAIContent table; setting it to Protected makes it deny-by-default, and Privileged Monitoring Data Reader grants read access to the authorized team (preview feature).

  • A. A protected table is deny-by-default, and only that role (or equivalent) can read it.
  • B. This broadens access instead of restricting the content.
  • C. Renaming attributes doesn't restrict who can read them.
  • D. This removes the telemetry operations engineers still need.

Keep going with 502 more AI-103 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

AI-103 sample questions with answers (10 free) · CertifyCloudx