AI-300 sample questions with answers

10 free practice questions for the Microsoft Certified: Machine Learning Operations Engineer Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Design and implement an MLOps infrastructure

Data scientists at Bellows College submit command jobs from the CLI v2. They don't want to create, size, or delete compute clusters, and each job should get compute only while it runs. How should they write the compute setting in their job YAML files?

  1. A.

    Set compute to azureml:serverless-cluster

  2. B.

    Set compute to azureml:local

  3. C.

    Omit the compute property from the job

  4. D.

    Set compute to the name of a compute instance

Show answer

Answer: C

Omitting compute from a command job sends it to serverless compute, which Azure Machine Learning creates, scales and removes for each job.

  • A. No compute of that name exists unless someone creates a cluster; serverless needs no compute name in a command job.
  • B. Local runs execute on the submitting machine and give no managed, scalable compute.
  • C. When no compute target is specified for command, sweep or AutoML jobs, the job runs on serverless compute.
  • D. A compute instance is a personal development VM that someone must create and manage.
Question 2Design and implement an MLOps infrastructure

At Contoso Pharmaceuticals, project leads must add and remove members of their team's workspace access without being Owner on the workspace, and the platform team wants to avoid one role assignment per user. Which two actions should you take? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    Assign each team member the AzureML Data Scientist role

  2. B.

    Assign each project lead the Owner role on the workspace

  3. C.

    Give each lead a custom role with Microsoft.Authorization/*/write

  4. D.

    Make each project lead an owner of the security group

  5. E.

    Assign a workspace role to a Microsoft Entra security group

Show answer

Answer: D, E

Assign the workspace role to a Microsoft Entra security group and make the project lead a group owner, so membership changes need no workspace permissions.

  • A. Individual assignments are what the platform team wants to avoid.
  • B. Owner on the workspace is exactly what the leads must not have.
  • C. Role assignment write permission is equivalent to managing access on the workspace, which leads must not hold.
  • D. A group owner can add or remove members without needing any role on the workspace.
  • E. Group-based assignment grants access to every member and avoids per-user assignments and role assignment limits.
Question 3Design and implement an MLOps infrastructure

Graphic Design Institute wants one Bicep deployment that creates a new resource group named rg-ml-gdi and deploys a workspace with its associated resources into it. The deployment runs from the Azure CLI. Which two actions should you take? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    Deploy with az deployment tenant create

  2. B.

    Use targetScope 'subscription' and a module scoped to the new group

  3. C.

    Deploy with az deployment group create -g rg-ml-gdi

  4. D.

    Deploy with az deployment sub create and a --location value

  5. E.

    Call az group create from inside the Bicep file

Show answer

Answer: B, D

Creating the resource group requires a subscription-scope deployment (targetScope = 'subscription', az deployment sub create --location), with the workspace deployed through a module scoped to the new resource group.

  • A. Tenant scope is for tenant-level resources and needs tenant-level permissions the scenario doesn't call for.
  • B. A subscription-scope file can create the resource group and deploy the workspace through a module whose scope is that resource group.
  • C. A resource group deployment needs the resource group to exist before the command runs.
  • D. Subscription deployments use az deployment sub create, which requires a location for the deployment data.
  • E. Bicep is declarative; it can't run CLI commands, and the resource group is declared as a resource instead.
Question 4Design and implement an MLOps infrastructure

Munson's Pickles has a network-isolated workspace whose default storage account has public network access disabled. Sharing a model from this workspace to the company's registry fails. Security requires that storage stay closed to general internet traffic. What should you do?

  1. A.

    Allow the registry as a resource instance in the storage networking

  2. B.

    Enable public network access from all networks on the storage account

  3. C.

    Create the model in the registry from the workspace job output

  4. D.

    Grant the registry's managed identity Storage Blob Data Reader

Show answer

Answer: A

Data exfiltration protection blocks sharing from a storage account with public access disabled; enabling selected networks and adding the registry as a resource instance allows the share without opening the account broadly.

  • A. Learn's fix is selected networks plus a resource instance rule for Microsoft.MachineLearningServices/registries naming the registry.
  • B. Opening the account to all networks breaks the security requirement.
  • C. The job output still lives in the closed storage account, so the registry can't read it either.
  • D. The failure is a network restriction imposed for exfiltration protection, not a missing data role.
Question 5Design and implement an MLOps infrastructure

An engineer at Trey Research runs az ml data create --path ./claims/claims.csv --name claims-table --version 1 --type mltable. The command fails validation, although the folder ./claims contains claims.csv and a valid MLTable file that reads it. What should the engineer change?

  1. A.

    Point --path at the ./claims folder instead

  2. B.

    Add --datastore workspaceblobstore to the command

  3. C.

    Change --type to uri_file and keep the path

  4. D.

    Rename the MLTable file to MLTable.yaml

Show answer

Answer: A

An mltable data asset is registered from the folder that contains the MLTable file, so --path must point at ./claims, not at the CSV file.

  • A. For an mltable data asset, the path must be a folder that contains a valid MLTable file.
  • B. The datastore isn't the problem; the path points at a file instead of the folder with the MLTable file.
  • C. That registers a plain file, not the table the team needs for its tabular jobs.
  • D. Azure Machine Learning expects a file named exactly MLTable; adding an extension breaks it.
Question 6Design and implement an MLOps infrastructure

A machine learning engineer at Fabrikam Residences must run experiments in a workspace and create, resize, and delete the compute clusters those experiments use. The engineer must not be able to change workspace settings or role assignments. Which role assignment should you make on the workspace?

  1. A.

    AzureML Compute Operator only

  2. B.

    AzureML Data Scientist and Contributor on the workspace

  3. C.

    AzureML Data Scientist and AzureML Compute Operator

  4. D.

    AzureML Data Scientist only

Show answer

Answer: C

Combining AzureML Data Scientist with AzureML Compute Operator gives experimentation plus compute management, without workspace or role assignment changes.

  • A. Compute Operator manages compute but doesn't grant the experimentation actions such as submitting jobs.
  • B. Contributor can modify the workspace itself, which exceeds the requirement.
  • C. Data Scientist covers experimentation, Compute Operator adds compute lifecycle, and neither can change workspace settings.
  • D. Data Scientist covers experimentation but excludes creating and deleting compute.
Question 7Design and implement an MLOps infrastructure

Engineers at Trey Research are registering a command component that scores sales leads. Their team standard requires component names to follow the Azure Machine Learning naming rules. Which component name is valid?

  1. A.

    score-sales-leads

  2. B.

    1scoresales_leads

  3. C.

    scoresalesleads

  4. D.

    ScoreSalesLeads

Show answer

Answer: C

A component name must start with a lowercase letter and contain only lowercase letters, numbers and underscores, so scoresalesleads is the only valid name.

  • A. Hyphens aren't allowed; only lowercase letters, numbers and underscores are.
  • B. A component name must start with a lowercase letter, not a digit.
  • C. The name starts with a lowercase letter and uses only lowercase letters and underscores.
  • D. Component names must use lowercase letters; uppercase isn't allowed.
Question 8Design and implement an MLOps infrastructure

Graphic Design Institute is deciding which datasets to publish as data assets in its organization-wide registry. Which two datasets are good candidates? Each correct answer presents a complete solution.

Choose 2.

  1. A.

    A folder already in a datastore that must stay where it is

  2. B.

    Patient records that only two approved workspaces may read

  3. C.

    A 400 TB image archive that is too costly to copy

  4. D.

    A small reference dataset needed by workspaces in three regions

  5. E.

    A preprocessed public benchmark dataset for all teams to experiment with

Show answer

Answer: D, E

Registry data assets fit broadly shareable data and cross-region sharing; they don't fit sensitive data with fine-grained access, data that is too large to copy, or data that must stay in place.

  • A. Registry data assets currently support only local paths, and the data is copied into the registry.
  • B. Registry data can't be limited to a small subset of users or workspaces while the registry is broadly accessible.
  • C. Creating a data asset in a registry copies the data into registry storage, which rules out data that is too large or costly to copy.
  • D. Sharing data assets across workspaces in different regions is a documented registry scenario.
  • E. Registries suit data without sensitive access controls that can be broadly used in the organization.
Question 9Design and implement an MLOps infrastructure

Coho Winery wants its GitHub Actions workflows to authenticate to Azure without an app registration and without any stored secret. The workflows only submit jobs to one Azure Machine Learning workspace. Which two actions should you perform? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    Enable the admin user on the workspace container registry

  2. B.

    Assign the identity Contributor on the subscription

  3. C.

    Assign the identity AzureML Data Scientist on the workspace

  4. D.

    Create a client secret for the managed identity and store it in GitHub

  5. E.

    Add a federated credential for the repository to a user-assigned managed identity

Show answer

Answer: C, E

A federated credential on a user-assigned managed identity removes both the app registration and the secret, and AzureML Data Scientist on the workspace grants just enough to submit jobs.

  • A. The registry admin user is unrelated to signing in from GitHub and is a stored credential.
  • B. Contributor at subscription scope far exceeds what submitting jobs to one workspace needs.
  • C. Submitting jobs is covered by AzureML Data Scientist, scoped to the one workspace for least privilege.
  • D. Managed identities don't have client secrets, and storing a secret is forbidden.
  • E. A user-assigned managed identity can trust GitHub-issued tokens through a federated credential, with no app registration and no secret.
Question 10Design and implement an MLOps infrastructure

A workflow at Liberty's Delightful Sinful Bakery was copied from a 2022 template and installs the Azure Machine Learning CLI v1 before training. The team is moving the workflow to CLI v2 commands such as az ml job create. Which setup step should the workflow run after signing in to Azure?

  1. A.

    Run az ml workspace create before each job

  2. B.

    Run az extension add --name ml

  3. C.

    Install the Azure Machine Learning CLI v1 extension

  4. D.

    Run pip install azureml-core

Show answer

Answer: B

The Azure Machine Learning CLI v2 is the ml extension to the Azure CLI, installed with az extension add -n ml; CLI v1 support has ended.

  • A. Creating a workspace isn't a setup step, and the workspace already exists.
  • B. The ml extension is the Azure Machine Learning CLI v2, which provides az ml job create and the other v2 commands.
  • C. CLI v1 support ended on September 30, 2025, so new automation must not depend on it.
  • D. azureml-core is the Python SDK v1, whose support ended on June 30, 2026, and it doesn't add CLI commands.

Keep going with 502 more AI-300 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

AI-300 sample questions with answers (10 free) · CertifyCloudx