AI-200 sample questions with answers

10 free practice questions for the Exam AI-200: Developing AI Cloud Solutions on Azure exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Develop containerized solutions on Azure

Wingtip Toys stores the source and Dockerfile for its recommendation API in a private GitHub repository. Every commit to the main branch must build a new image and push it to Azure Container Registry, tagged with the run ID. Which command should you use to set this up?

  1. A.

    az acr import with the GitHub repository as --source

  2. B.

    az acr webhook create with the push action on the repository

  3. C.

    az acr task create with the repo #main as --context and a GitHub PAT

  4. D.

    az acr build with the repository URL as the build context

Show answer

Answer: C

az acr task create with a GitHub context such as https://github.com/org/repo.git#main, a Dockerfile and a PAT sets up commit-triggered builds.

  • A. Import copies existing images from registries; it can't read a Git repository.
  • B. A registry webhook reacts to registry pushes, not to commits in GitHub.
  • C. A task with a Git context and personal access token creates the webhook that triggers builds on commit.
  • D. az acr build runs one quick build on demand and creates no commit trigger.
Question 2Develop containerized solutions on Azure

Alpine Ski House enabled continuous deployment for its App Service custom container so that each docker push to Azure Container Registry redeploys the app. Pushes succeed, but the app never updates, and the registry's webhook shows 401 unauthorized responses. What should you do?

  1. A.

    Recreate the webhook with the delete action instead of push

  2. B.

    Enable Basic Auth Publishing Credentials on the web app

  3. C.

    Grant the web app's managed identity AcrPush on the registry

  4. D.

    Add WEBSITES_PORT to the app settings

Show answer

Answer: B

App Service continuous deployment adds a registry webhook that authenticates with publishing credentials; with basic auth disabled, the webhook gets 401.

  • A. Deployment must follow pushes; the delete action fires on the wrong event.
  • B. The CI/CD webhook needs basic auth publishing credentials, or it receives 401 errors.
  • C. The failing call is the registry's webhook into App Service, not a push.
  • D. The port setting affects request routing, not webhook authentication.
Question 3Develop containerized solutions on Azure

A Python container on App Service for Linux reads its configuration through a library that maps environment variables to nested keys, and it expects a value for Retrieval:IndexName. An app setting named Retrieval:IndexName was added in the portal, but the app still can't find the value. How should you name the app setting?

  1. A.

    Retrieval__IndexName

  2. B.

    Retrieval.IndexName

  3. C.

    APPSETTING_Retrieval:IndexName

  4. D.

    CUSTOMCONNSTRRetrievalIndexName

Show answer

Answer: A

In App Service for Linux and custom containers, nested keys must use a double underscore in place of the colon, for example Retrieval__IndexName.

  • A. Linux containers need the colon in nested key names replaced with a double underscore.
  • B. Periods are replaced with single underscores on Linux, so this doesn't produce the nested key.
  • C. The APPSETTING_ prefix applies to certain frameworks; it doesn't fix the colon.
  • D. That prefix belongs to custom connection strings, not app settings.
Question 4Develop containerized solutions on Azure

Wide World Importers created a Premium Azure Container Registry with a private endpoint and firewall rules. Since then, every az acr import from the company's development registry into this registry fails, although the same import succeeded before the network changes. You need imports to work without reopening public access. What should you do?

  1. A.

    Enable the admin user on the development registry

  2. B.

    Add the pipeline agent's public IP address to the registry firewall

  3. C.

    Add a geo-replica of the development registry in the same region

  4. D.

    Enable the trusted services bypass on the registry

Show answer

Answer: D

Import to or from a network-restricted registry works only when the registry allows trusted services to bypass its network rules.

  • A. Credentials aren't the problem; the request is blocked by the target registry's network rules.
  • B. Import is performed by the service, not by the client, so the client's IP isn't what is blocked.
  • C. Import from an Azure registry always uses the source registry's global endpoint and home region.
  • D. Import into a network-restricted registry requires the trusted services bypass to be enabled.
Question 5Develop containerized solutions on Azure

Contoso Retail keeps its inference images in an Azure Container Registry named contosoacr. The registry was recently switched to the RBAC Registry + ABAC Repository Permissions mode. Developers still hold the AcrPush role, and az acr login succeeds, but every docker push to the ranker repository is now denied. What should you do?

  1. A.

    Enable the admin user and share its password with the developers

  2. B.

    Assign the Contributor role on the registry to each developer

  3. C.

    Reassign AcrPush to each developer at the resource group or subscription scope

  4. D.

    Assign Container Registry Repository Writer, scoped to the ranker repository

Show answer

Answer: D

An ABAC-enabled registry ignores AcrPush, so developers need the Container Registry Repository Writer role, optionally conditioned to the ranker repository.

  • A. The admin account is a shared, full-permission credential; it bypasses per-user identity rather than fixing the role model.
  • B. In ABAC-enabled mode, Owner, Contributor and Reader grant only control plane permissions, not image push.
  • C. Legacy AcrPull, AcrPush and AcrDelete assignments are not honored in an ABAC-enabled registry, whatever their scope.
  • D. In an ABAC-enabled registry the Repository Writer role grants push, and an ABAC condition can limit it to the ranker repository.
Question 6Develop containerized solutions on Azure

Trey Research runs a critical inference API on an AKS cluster whose node pools span three availability zones. The API must keep serving if one zone fails. Which two changes to the API's Deployment manifest follow AKS reliability best practices for this goal? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    Set a nodeSelector that pins every replica to zone 1

  2. B.

    Add a DaemonSet for the API alongside the Deployment

  3. C.

    Run at least two replicas, preferably three

  4. D.

    Add topologySpreadConstraints on topology.kubernetes.io/zone

  5. E.

    Set terminationGracePeriodSeconds to 0

Show answer

Answer: C, D

Run at least two replicas and use topology spread constraints on the zone label so the replicas land in different zones.

  • A. Pinning to one zone makes that zone a single point of failure.
  • B. A DaemonSet runs per node regardless of zones and duplicates the workload.
  • C. Multiple replicas are needed so that another zone still hosts a pod.
  • D. Spread constraints distribute the replicas across the zones.
  • E. This removes graceful shutdown and does nothing for zone resilience.
Question 7Develop containerized solutions on Azure

Before deciding whether to change the service tier of an Azure Container Registry, Alpine Ski House needs a snapshot of how much storage and how many webhooks the registry uses compared with the limits of its current tier. Which Azure CLI command should you run?

  1. A.

    az acr check-health

  2. B.

    az acr show --query sku

  3. C.

    az acr repository list

  4. D.

    az acr show-usage --name alpineacr

Show answer

Answer: D

az acr show-usage returns the registry's current usage of storage, webhooks and other resources alongside the limits of its tier.

  • A. check-health diagnoses environment and connectivity problems, not tier usage.
  • B. This returns only the tier name, not consumption against limits.
  • C. This lists repository names without any usage or limit information.
  • D. show-usage reports current consumption of storage and other resources against the tier's limits.
Question 8Develop containerized solutions on Azure

Adatum ships 300 edge gateways that must pull one model-serving image from the vision/runtime repository in its Azure Container Registry. The gateways have no Microsoft Entra identities, and each must have its own credential that can be revoked without affecting the others. What should you create for each gateway?

  1. A.

    A shared service principal with the AcrPull role

  2. B.

    The admin user with one of its two passwords

  3. C.

    A token whose scope map grants content/write on vision/runtime

  4. D.

    A token whose scope map grants content/read on vision/runtime

Show answer

Answer: D

A token per gateway with a scope map that grants content/read on vision/runtime gives revocable, pull-only access without Entra identities.

  • A. One shared principal can't be revoked per gateway and grants pull on every repository.
  • B. The admin account is registry-wide with full permissions, and only two passwords exist.
  • C. content/write is a push permission; pulling an artifact needs content/read.
  • D. Tokens are non-Entra credentials that can be scoped to one repository and disabled individually.
Question 9Develop containerized solutions on Azure

Wide World Importers has two container apps, chat-frontend and retriever, in the same Container Apps environment. The retriever app has internal ingress on port 8080. What is the simplest address that chat-frontend can use to call retriever?

  1. A.
  2. B.

    The address http://retriever

  3. C.

    The public IP address of the environment

  4. D.

    A private endpoint in front of retriever

Show answer

Answer: B

Within one environment, an app can reach another by its short app name, such as http://retriever, and the traffic never leaves the environment.

  • A. localhost reaches containers in the same replica, not another app.
  • B. Apps in the same environment can call each other by app name for internal calls.
  • C. retriever has internal ingress and isn't published on a public address.
  • D. Apps in one environment already share its network; no endpoint is needed.
Question 10Develop containerized solutions on Azure

Lamna Healthcare deploys a containerized web app with a Bicep template, and its app settings contain Key Vault references that must resolve the first time the app starts. A system-assigned identity can't be granted vault access before the app exists. You need the references to resolve at creation time. What should you do?

  1. A.

    Add WEBSITESKIPCONTENTSHARE_VALIDATION with the value 1

  2. B.

    Store the secret values directly in app settings and replace them later

  3. C.

    Set acrUserManagedIdentityID to the user-assigned identity's client ID

  4. D.

    Use a pre-authorized user-assigned identity set as keyVaultReferenceIdentity

Show answer

Answer: D

Grant a user-assigned identity vault access in advance, assign it to the app, and set keyVaultReferenceIdentity to its resource ID.

  • A. That setting skips Azure Files content share checks; it doesn't authorize the vault.
  • B. Plain values in the template defeat the purpose of Key Vault references.
  • C. That property selects the identity for registry pulls, not for Key Vault references.
  • D. A user-assigned identity can be granted access in advance and selected for Key Vault references.

Keep going with 502 more AI-200 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

AI-200 sample questions with answers (10 free) · CertifyCloudx