Microsoft Practice Questions, Discussions & Exam Topics by our Authors
You need to make the written press releases of your company available in a range of languages.
Whic...
To make the written press releases of your company available in a range of languages, the most suitable service would be A) Translator.
Explanation:
- Translator:
- Reason for Selection: The Translator service in Azure is specifically designed for translating text from one language to another. It supports many languages and can automatically translate the written content of your press releases into the desired target languages. This is exactly what is needed when you want to make content available in multiple languages.
- Scenarios: Ideal for situations where you need to translate large volumes of text, such as articles, press releases, or website content, into various languages to reach a broader audience globally.
Rejected Options:
- B) Text Analytics:
- Reason for Rejection: Text Analytics is a service that provides natural language processing capabilities, such as sentiment analysis, key phrase extraction, and entity recognition. While it is useful for understanding the content of text, it does not provide translation capabilities. It’s not designed to convert text from one language to another.
- Scenarios: Used...
Author: Sofia · Last updated Jul 13, 2026
SNAPSHOT
-
You have an Azure subscription that contains the resources shown in the following table.
You plan to use service endpoints and service endpoint policies.
Which resources can be accessed by using a service endpoint, and which resources support service endpoint ...
Author: Akash · Last updated Jul 15, 2026
SNAPSHOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Ea...
Let’s carefully analyze each part of your question about Text Analytics in the context of AI-900 (Microsoft Azure AI Fundamentals):
1. Identify the language of text – ✅ Yes, Text Analytics can detect the language of a given text.
2. Detect handwritten signatures – ❌ No, Text Analytics does not process image...
Author: Olivia Johnson · Last updated Jul 13, 2026
SNAPSHOT
-
You have an Azure App Service web app named App1 as shown in the following exhibit.
Subnet 2 contains a virtual machine named VM1.
Use the drop-down menus to select the answer choice that completes each statement...
Author: Siddharth · Last updated Jul 15, 2026
DRAG DROP -
Match the types of natural languages processing workloads to the appropriate scenarios.
To answer, drag the appropriate workload type from the column on the left to its scenario on the right. Each workload type may be used on...
Correct Answer: A) Entity recognition, Sentiment analysis, Translation
Explanation
Let’s match each requirement in the question with the correct AI capability:
1. Extracts persons, locations, and organizations from the text
👉 This is Entity Recognition
It identifies named entities such as people, places, companies, dates, etc.
Example: From the sentence “Microsoft was founded by Bill Gates in the USA”, it extracts:
Organization: Microsoft
Person: Bill Gates
Location: USA
2. Evaluates text along a positive–negative scale
👉 This is Sentiment Analysis
It determines whether text expresses posit...
Author: Ava · Last updated Jul 13, 2026
SNAPSHOT
-
You have an Azure subscription that contains the resources shown in the following table.
You create a shared access token as shown in the following exhibit.
Which resources can you access by using the shared access token and Key1?...
Author: Vikram · Last updated Jul 15, 2026
SNAPSHOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Ea...
Let’s carefully analyze each statement.
1. Monitoring online service reviews for profanities – This involves analyzing text to detect offensive language. That is Natural Language Processing (NLP). ✅
2. Identifying brand logos in an image – This involve...
Author: SilverBear · Last updated Jul 13, 2026
You have an Azure subscription that contains an Azure SQL server named SQL1. SQL1 contains an Azure SQL database named DB1.
You need to use Microsoft Defender for Cloud t...
To complete a vulnerability assessment for the Azure SQL Database (DB1) using Microsoft Defender for Cloud, we need to set up the necessary components. Let’s break down the requirements and evaluate each option.
Key Factors in the Decision:
1. Microsoft Defender for SQL:
- Microsoft Defender for SQL provides security recommendations and vulnerability assessments for Azure SQL databases, including both SQL Server and Azure SQL databases.
- For vulnerability assessments, you need to enable Microsoft Defender for SQL on the relevant Azure SQL Server or database.
- Once Microsoft Defender for SQL is enabled, it offers a vulnerability assessment that scans the database and generates security recommendations, including identifying vulnerabilities like SQL injection, improper configurations, and outdated settings.
2. Vulnerability Assessment:
- The first step in configuring a vulnerability assessment for an Azure SQL Database is to enable Microsoft Defender for SQL. This activates the vulnerability assessment features and allows you to use the scanning capabilities provided by Microsoft Defender for Cloud.
Analysis of Each Option:
- A) From Advanced Threat Protection types, select SQL injection vulnerability:
- While SQL injection vulnerability is a critical aspect of security, this option is part of the advanced threat protection settings, which focuses on monitoring and detecting malicious activities and suspicious behavior.
- This option does not initiate a vulnerability assessment. It is more about ongoing threat detection rather than starting a vulnerability assessment. Therefore, this option does not directly address the need to perform a vulnerability scan.
...
Author: ShadowWolf101 · Last updated Jul 15, 2026
You are developing a natural language processing solution in Azure. The solution will analyze customer reviews and determine how positive or negative each review is.
T...
The most suitable natural language processing (NLP) workload for analyzing customer reviews to determine how positive or negative each review is would be B) Sentiment Analysis.
Explanation:
- Sentiment Analysis:
- Reason for Selection: Sentiment analysis is a specific NLP task focused on determining the sentiment or emotional tone expressed in a piece of text. In this case, you want to determine whether customer reviews are positive, negative, or neutral. Sentiment analysis is exactly designed for this task, as it can analyze text and classify it based on the expressed emotions or attitudes of the writer.
- Scenarios: Used for understanding customer feedback, product reviews, social media posts, and any other text data where the goal is to assess sentiment or opinion.
Rejected Options:
- A) Language Detection:
- Reason for Rejection: Language detection is an NLP task that identifies the language in which a text is written. While this is useful when working with multilingual content, it doesn't assess the sentiment or emotional tone of the text. It focuses purely on identifying languages, not the opinions expressed in the text.
- Scenarios: Ideal for application...
Author: Benjamin · Last updated Jul 13, 2026
SNAPSHOT
-
You have an Azure subscription that contains the resources shown in the following table.
SQL1 has the following configurations:
* Auditing: Enabled
* Audit log destination: storage1, Workspace1
DB1 has the following configurations:
* Auditing: Enabled
* Audit log destination: storage2
DB2 has auditing disabled.
Where a...
Author: Ava · Last updated Jul 15, 2026
You use natural language processing to process text from a Microsoft news story.
You receive the output shown in the following exhibit.
...
To determine which type of natural language processing (NLP) was performed, we need to understand the type of output that was received from processing the text of a Microsoft news story. Given the typical outputs of different NLP tasks, we can assess each option based on what the output would represent.
Explanation:
- A) Entity Recognition:
- Reason for Selection: Entity recognition (also called Named Entity Recognition or NER) focuses on identifying entities such as names of people, organizations, dates, locations, and other specific information in text. If the output contains recognized entities like company names, people's names, locations, or dates, then this task would be entity recognition.
- Scenarios: Used in news articles or documents to extract structured information such as people, places, organizations, and dates. Ideal for creating databases or indexing specific data from text.
- B) Key Phrase Extraction:
- Reason for Rejection: Key phrase extraction involves identifying the most important or relevant phrases in a text, such as topics or concepts that are central to the content. If the output shows extracted key phrases or significant concepts (e.g., "economic growth," "climate change"), this would be key phrase extraction.
- Scenarios: Useful in summarizing article...
Author: Leah Davis · Last updated Jul 13, 2026
SIMULATION
-
You need to prevent HTTP connections to the rg1lod28681041n1 Azure Storage account.
To c...
To prevent HTTP connections to the `rg1lod28681041n1` Azure Storage account, you need to configure the access to only allow HTTPS traffic. This can be achieved by using the "Secure transfer required" option in the Azure Storage account settings.
Steps to configure this:
1. Sign in to the Azure portal.
2. Navigate to the `rg1lod28681041n1` Azure Storage account.
3. Go to the "Settings" section and click on "Configuration."
4. Find the "Secure transfer required" setting.
Options available:
1. Secure transfer required (Enable HTTPS only):
- Reasoning: This setting ensures that all requests to the storage account are made using HTTPS. Any HTTP request will be rejected, thus ensuring secure communication. This is the most direct and effective method to prevent HTTP connections to your storage account.
- Use case: This should be used when you need to enforce strict security and prevent the usage of HTTP for communication with your storage account, ensuring data is always encrypted in transit.
2. Network rules (IP-based restrictions):
- Reasoning: You can configure IP restrictions to only allow traffic from specific IP addresses. While this controls access, it does not directly prevent HTTP connections. This is more useful for limiting access to trusted sources but doesn’t specifically enforce HTTPS.
- Use case: Use this option when you need to restrict access ba...
Author: Noah · Last updated Jul 15, 2026
DRAG DROP -
You plan to apply Text Analytics API features to a technical support ticketing system.
Match the Text Analytics API features to the appropriate natural language processing scenarios.
To answer, drag the appropriate feature from the column on the left to its scenario on the right. Ea...
The correct answer is C) Sentiment analysis, Key phrase extraction, Entity recognition ✅
Explanation:
1. Understand how upset a customer… → Sentiment analysis
Detects emotion or tone (negative, positive, neutral) in the text.
2. Summarize important information… → Key phrase extraction
Extracts main topics or phrases to summarize the content.
...
Author: Olivia Johnson · Last updated Jul 13, 2026
SIMULATION
-
You need to ensure that the rg1lod28681041n1 Azure Storage account is encrypted by using a key stored in the KeyVault28681041 Azure ...
To ensure that the `rg1lod28681041n1` Azure Storage account is encrypted using a key stored in the `KeyVault28681041` Azure Key Vault, you need to configure the storage account to use customer-managed keys (CMK) for encryption. This means that instead of using the default Microsoft-managed keys for encryption, you specify a key stored in the Key Vault.
Steps to configure this:
1. Sign in to the Azure portal.
2. Navigate to the `rg1lod28681041n1` Azure Storage account.
3. Go to the "Encryption" section under the "Settings" tab.
4. Select "Customer-managed keys" for encryption.
5. Specify the Key Vault and key you want to use (in this case, `KeyVault28681041`).
Options available:
1. Microsoft-managed keys (Default):
- Reasoning: By default, Azure Storage accounts are encrypted using Microsoft-managed keys. This option allows Microsoft to manage the lifecycle of the keys and encryption for you. While this provides automatic encryption without user intervention, it doesn’t give you control over key management or storage in an Azure Key Vault.
- Rejected because: You want to use a key stored in the `KeyVault28681041` Azure Key Vault, and this option doesn’t allow you to use a key from a Key Vault. This option is suitable when you don't require control over key management and are okay with Microsoft handling the encryption keys.
2. Customer-managed keys (KeyVault-managed):
- Reasoning: This is the key option to select when you want to use a key stored in an Azure Key Vault to encrypt the storage account. By selecting this option, you gain control over the encryption keys, including key rotation and access management, which enhances security and compliance. You can configure the storage account to use a key stored in the `K...
Author: Ethan · Last updated Jul 15, 2026
You are authoring a Language Understanding (LUIS) application to support a music festival.
You want users to be able to ask questions about scheduled shows, such as: `Which act is playing on the main stage?`
Th...
The question "Which act is playing on the main stage?" is an example of B) an utterance.
Explanation:
- B) An Utterance:
- Reason for Selection: In Language Understanding (LUIS), an utterance refers to a user's input or query that the system needs to interpret. It is a specific example of how a user might express their intent. In this case, the user's question, "Which act is playing on the main stage?", is an utterance that represents how a user is asking about the music festival schedule.
- Scenarios: Utterances are the actual phrases or questions users ask the system. For instance, a user might ask "What time does the festival start?" or "Who is performing today?" These utterances are mapped to intents in LUIS for interpretation.
Rejected Options:
- A) An Intent:
- Reason for Rejection: An intent represents the goal or purpose behind the user’s query. In this case, the intent could be something like "GetShowSchedule" or "GetMainStageAct," but the actual input "Which act is playing on the main stage?" is an utterance, not the intent itself. The intent is what the LUIS model identifies as the user’s purpose.
- Scenarios: Used to define what the user wants to achieve, such as "book ...
Author: Manish · Last updated Jul 13, 2026
SNAPSHOT
-
You have an Azure subscription that contains the virtual machines shown in the following table.
You have an Azure Cosmos DB account named cosmos1 configured as shown in the following exhibit.
For each of the following statements,...
Author: Aditya · Last updated Jul 15, 2026
You build a QnA Maker bot by using a frequently asked questions (FAQ) page.
You need to add professional greetings and other response...
To make your QnA Maker bot more user-friendly by adding professional greetings and other responses, the most appropriate action is D) Add chit-chat.
Explanation:
- D) Add Chit-Chat:
- Reason for Selection: In QnA Maker, chit-chat refers to adding non-FAQ-based, conversational responses such as greetings, pleasantries, or friendly remarks. This can be used to create a more engaging, user-friendly experience for the bot by allowing it to respond with a variety of casual and welcoming phrases (e.g., "Hello! How can I assist you today?" or "Thanks for reaching out!").
- Scenarios: Ideal for making a bot feel more conversational and approachable, especially for use cases where building rapport with users is important, such as customer service or virtual assistants.
Rejected Options:
- A) Increase the confidence threshold of responses:
- Reason for Rejection: Increasing the confidence threshold would make the bot more selective about when it gives responses based on its confidence in the answer. This doesn't help in adding greetings or other friendly interactions. Instead, it just fine-tunes how certain or confident the bot needs to be before providing an answer to FAQs.
- Scenarios: Useful for improving response accuracy in ...
Author: Sophia · Last updated Jul 13, 2026
You are troubleshooting a security issue for an Azure Storage account.
You enable Azure Storage Analytics logs and archive it to a storage ac...
To retrieve diagnostics logs from Azure Storage Analytics that have been archived to a storage account, you need to use a tool that can access and query these logs stored in your storage account.
Analysis of Options:
1. A) Azure Cosmos DB explorer:
- Reasoning: Azure Cosmos DB Explorer is used to manage and query data stored in Azure Cosmos DB, not for retrieving diagnostics logs from Azure Storage. It is a specialized tool for NoSQL database operations.
- Rejected because: This option is specific to Cosmos DB and is not relevant for querying or retrieving diagnostics logs from Azure Storage accounts.
2. B) Azure Monitor:
- Reasoning: Azure Monitor can collect and analyze metrics and logs from various Azure resources, including Azure Storage accounts. However, Azure Storage Analytics logs (such as request logs) are typically stored in a storage account, and while Azure Monitor can pull metrics, it is not designed to directly retrieve logs from an archived storage account where analytics logs are stored.
- Rejected because: While Azure Monitor can monitor and analyze performance metrics and diagnostic logs, it is better suited for real-time monitoring and alerting rather than retrieving archived logs directly from a storage account.
3. C...
Author: Emma · Last updated Jul 15, 2026
You need to develop a chatbot for a website. The chatbot must answer users' questions based on the information in the following documents:
* A product troubleshooting guide in a Microsoft Word document
* A frequently...
To develop a chatbot for a website that answers users' questions based on a product troubleshooting guide and a FAQ list, the most suitable service to process the documents would be D) QnA Maker.
Explanation:
- D) QnA Maker:
- Reason for Selection: QnA Maker is designed to process and extract information from documents, FAQs, and knowledge bases. It is particularly useful when you have static information, such as product troubleshooting guides or FAQ lists, and you want to create a chatbot that can retrieve relevant answers from these documents. QnA Maker allows you to upload documents (such as Word files and web pages) and automatically generates a knowledge base that the bot can query to answer user questions.
- Scenarios: Perfect for scenarios where you need to build a chatbot that provides answers to frequently asked questions or specific product-related queries based on structured data from documents.
Rejected Options:
- A) Azure Bot Service:
- Reason for Rejection: Azure Bot Service is a platform for developing and deploying chatbots. While it is essential for creating and hosting the chatbot itself, it does not process documents directly. It needs to be integrated with other services (like QnA Maker or Language Understanding) to process and understand the content of documents.
- Scenarios: Used for...
Author: NightmareDragon2025 · Last updated Jul 13, 2026
You are building a Language Understanding model for an e-commerce business.
You need to ensure that the model detects when utterances are o...
To ensure that the model detects when utterances are outside the intended scope of the model, the most appropriate action would be B) Add utterances to the None intent.
Explanation:
- B) Add Utterances to the None Intent:
- Reason for Selection: The None intent in Language Understanding (LUIS) is specifically designed to capture any user input that doesn't match the defined intents in your model. By adding examples of out-of-scope utterances (those that don't fall under the main intents), the model can be trained to recognize these types of inputs and appropriately classify them as "None," indicating they are outside the scope of the model. This helps the bot to handle irrelevant or unrelated queries effectively.
- Scenarios: Ideal for ensuring that the bot doesn’t get confused by out-of-scope queries and can provide an appropriate response when users ask questions outside the business domain (e.g., non-product-related questions in an e-commerce store).
Rejected Options:
- A) Test the model by using new utterances:
- Reason for Rejection: While testing the model with new utterances is crucial for evaluating performance, it doesn't specifically address the issue of detecting out-of-scope utterances. Testing ensures that the model works well for known use cases but doesn't help in defining a mechanism for handling completely unrelated inputs. You can test, but without explicitly training the model to recog...
Author: FrozenWolf2022 · Last updated Jul 13, 2026
You have an Azure subscription that contains an Azure Blob storage account named blob1.
You need to configure attribute-based access control (ABAC)...
To configure Attribute-Based Access Control (ABAC) for Azure Blob Storage, you need to define conditions based on attributes like blob index tags, container names, and file extensions. ABAC is a way to apply granular access control policies that are based on metadata attributes and conditions that match certain resource characteristics.
Explanation of Options:
1. A) blob index tags only:
- Reasoning: Blob index tags are metadata assigned to a blob in Azure Storage. ABAC can indeed use blob index tags as part of access control conditions. However, ABAC in Azure Blob Storage is not limited to just index tags. It can also use other attributes like file extensions and container names.
- Rejected because: While blob index tags can be used, this option doesn't leverage the full potential of ABAC, as it only considers index tags and ignores other attributes like container names or file extensions.
2. B) blob index tags and container names only:
- Reasoning: This option includes both blob index tags and container names as attributes. ABAC allows you to use the container name to apply policies based on the specific container within which the blob resides. However, this still omits the file extension as a potential access condition.
- Rejected because: Although this option includes two useful attributes, it excludes file extensions, which are another valid attribute that can be considered when defining ABAC rules for blobs.
3. C) file extensions and container names only:
- Reasoning: This option...
Author: Amira · Last updated Jul 15, 2026
You have an Azure subscription that contains a storage account and an Azure web app named App1.
App1 connects to an Azure Cosmos DB database named Cosmos1 that uses a private endpoint named Endpoint1. Endpoint1 has the default ...
In this scenario, you need to validate the name resolution for an Azure Cosmos DB database named Cosmos1 that uses a private endpoint named Endpoint1. The private endpoint allows Azure resources to access Cosmos DB securely through a private IP address within a Virtual Network (VNet).
Key Factors to Consider:
- Private Endpoints in Azure: Private endpoints for Azure services use DNS to resolve the private IP address associated with the service. Each service typically has its own DNS suffix that is used for name resolution.
- Azure Cosmos DB: Cosmos DB typically uses the endpoint format `.privatelink.documents.azure.com` for its private endpoints.
Breakdown of Each Option:
A) endpoint1.privatelink.documents.azure.com
- Correct Choice: Cosmos DB uses `privatelink.documents.azure.com` as the domain suffix for its private endpoints. So, this DNS zone is the correct one for Cosmos1. The `documents` portion of the domain is a key indicator that this is for Cosmos DB.
B) endpoint1.privatel...
Author: CrimsonViperX · Last updated Jul 15, 2026
Which two scenarios are examples of a natural language processing workload? Each correct answer presents a complete soluti...
Let's go through each option and analyze whether it is related to a natural language processing (NLP) workload:
A) Monitoring the temperature of machinery to turn on a fan when the temperature reaches a specific threshold
- This is not an NLP workload. This is more related to sensor data and automation, where the system monitors the temperature and triggers an action (turning on the fan) based on that data. NLP is not involved in this scenario.
B) A smart device in the home that responds to questions such as, "What will the weather be like today?"
- This scenario is a classic example of NLP. The smart device needs to understand and process the natural language question ("What will the weather be like today?") and then respond in a natural language format. NLP is crucial here to interpret and generate the response.
C) A website that uses a knowledge base to interactively respond to users' questions
- This is another example of NLP. The website is...
Author: Oscar · Last updated Jul 13, 2026
You have an AI solution that provides users with the ability to control smart devices by using verbal commands.
Which two types of natural language processing (NLP) workloads does the solution use? Each corre...
The correct AI-900 answers are:
✅ C. speech-to-text
✅ D. language modeling
---
Why these are correct (AI-900 exam explanation):
An AI solution that lets users control smart devices using verbal commands must do two things:
1. Convert spoken words into text
→ Speech-to-text (C)
Example: Converting “Turn on the lights” from voice to text.
2. Understand the meaning and intent of the command
→ Language modeling (D)
Example: Understanding that th...
Author: Aria · Last updated Jul 13, 2026
SNAPSHOT
-
You have an Azure subscription that contains the virtual networks shown in the following table.
The subscription contains the virtual machines shown in the following table.
You have a storage account named contoso2024 that contains the following resources:
* A container named Container1 that contains a file named File1
* A file share named Share1 that contains a file named File2
You create a private endpoint for conto...
Author: GlowingTiger · Last updated Jul 15, 2026
SNAPSHOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Ea...
The correct answer is:
C) Yes, No, Yes
Explanation
1. The Language service can identify in which language text is written → Yes
Azure AI Language service supports language detection.
2. The Language service can detect handwritten signatures in a document → No
Handwritten signa...
Author: Joseph · Last updated Jul 13, 2026
You have an Azure subscription that contains an Azure Kubernetes Service (AKS) cluster named AKS1.
You have an Azure container registry that stores container images that were deployed by using Azure DevOps Microsoft-hosted agents.
You need to ensure that administrators can access...
In this scenario, the goal is to ensure that administrators can access the Azure Kubernetes Service (AKS) cluster, AKS1, only from specific networks, and the solution should minimize administrative effort.
Key Factors to Consider:
- Security and Access Control: To restrict access to AKS from specific networks, you need a way to limit the source of traffic that can reach the Kubernetes API server. This is essential to control who can administer and interact with the cluster.
- Minimizing Administrative Effort: You should choose a solution that is straightforward to configure, and once set up, does not require frequent changes or heavy maintenance.
Breakdown of Each Option:
A) Authorized IP Address Ranges
- Correct Choice: The "Authorized IP Address Ranges" feature allows you to configure a list of IP addresses or ranges that are allowed to access the Kubernetes API server. This solution is simple to configure and minimizes administrative effort because it doesn’t require complex infrastructure changes. It allows you to restrict access to the AKS management plane (Kubernetes API server) to only specific IP addresses or networks. Once this configuration is set, the API server will only be accessible from the allowed IP ranges, preventing unauthorized access from other sources.
B) An Application Gateway Ingress Controller (AGIC)
- Rejected: An Application Gateway Ingress Controller (AGIC) is used for controlling inbound traffic to services deployed inside the AKS cluster. It acts as an ingress controller and routes external traffic to your Kubernetes services based on configured rules. However, it doesn't address controlling access to the Kubernetes API server itself. It's more about managing traffic to application w...
Author: Rohan · Last updated Jul 15, 2026
DRAG DROP -
You plan to use Azure Cognitive Services to develop a voice controlled personal assistant app.
Match the Azure Cognitive Services to the appropriate tasks.
To answer, drag the appropriate service from the column on the left to its description on the right. Each serv...
The correct answer is:
A) Speech, Language service, Speech ✅
Explanation
Convert a user's speech to text → Speech service (speech-to-text)
Identify a user's intent → Language service (intent recognition / LUIS)
Provide a spoken response to the user → Speech service (text-to-speech)
Why the other options are incorrect:
B) T...
Author: IceDragon2023 · Last updated Jul 13, 2026
You have an Azure subscription that contains an Azure Data Lake Storage account named sa1.
You plan to deploy an app named App1 that will access sa1 and perform operations, including Read, List, Create Directory, and Delete Directory.
You need to ensure that App1 can co...
In this scenario, we need to ensure that App1 can securely access the Azure Data Lake Storage account (`sa1`) via a private endpoint, and the minimum number of private endpoints required for this scenario must be determined.
Key Factors to Consider:
- Private Endpoint: A private endpoint allows a service (in this case, Azure Data Lake Storage) to be accessed via a private IP address within a Virtual Network (VNet). It ensures secure and private communication between the app and the storage account by eliminating exposure to the public internet.
- Data Lake Storage: Azure Data Lake Storage (ADLS) is typically accessed through private endpoints, which can be configured for specific services, such as Blob Storage, which ADLS is built on top of.
- Access Requirements for App1: The application App1 needs to perform specific operations (Read, List, Create Directory, Delete Directory) on the storage account. These operations generally fall under the functionality provided by Azure Blob Storage, which Data Lake Storage uses, and these operations can be managed through a private endpoint for accessing the Blob service.
Breakdown of Each Option:
A) 1 Private Endpoint
- Correct Choice: One private endpoint is sufficient to enable secure access for App1 to the Azure Data Lake Storage account (`sa1`). When setting up a private endpoint for a storage account (such as ADLS), it typically covers access to the Blob service, which includes all operations (Read, List, Create Directory, Delete Directory) on Data Lake Storage...
Author: Olivia · Last updated Jul 15, 2026
You need to make the written press releases of your company available in a range of languages.
Whic...
Let's break down each option and analyze which one is best suited for making written press releases available in a range of languages:
A) Speech
- This service would typically deal with converting text into speech or vice versa, enabling voice interactions. Since the task is focused on translating written content (press releases) into different languages, this is not the correct service. Speech would be more appropriate for voice-based tasks, not for translation.
B) Language
- The Language service is a general term that could encompass a range of language-related tasks, including translation, but it is not specific enough. For the task of translating written press releases into various languages, this option does not directly target the specific need of translation and could be too vague.
C) Translator
- The Translator service is specifically designed for translating text between different languages. Given that the task is to m...
Author: VioletCheetah55 · Last updated Jul 13, 2026
You have an Azure subscription that uses Microsoft Defender for Cloud. The subscription contains an instance of Azure Database for PostgreSQL.
You need to ensure that an email alert is triggered when a suspected brute force attack on th...
In this scenario, the goal is to trigger an email alert when a suspected brute force attack on an Azure Database for PostgreSQL is detected, while minimizing administrative effort.
Key Factors to Consider:
- Brute Force Attack Detection: A brute force attack typically involves multiple failed login attempts in a short period of time, which could be detected through monitoring failed login events or suspicious activity patterns.
- Email Alerts: The requirement is to receive an email alert, which means you need a solution that provides this functionality with minimal configuration.
- Minimizing Administrative Effort: The solution should be easy to set up and maintain without requiring extensive configuration or ongoing manual monitoring.
Breakdown of Each Option:
A) The Azure Monitor Activity Log
- Rejected: The Azure Monitor Activity Log is a good tool for tracking changes in resources and activities in the Azure environment, but it is not specifically designed to detect brute force attacks. While you can log certain activities related to authentication failures, it doesn't provide the level of detection needed for brute force attacks on Azure Database for PostgreSQL, nor does it have built-in functionality for triggering email alerts based on such attacks.
B) An Azure Monitor Alert Rule
- Rejected: Azure Monitor Alert Rules are used to trigger notifications based on metrics or log data. While you can create custom alert rules for various metrics, it requires significant setup and configuration to track and define what constitutes a brute force attack, as well as to set up the necessary log sources. Although Azure Monitor can send alerts, setting it up specifically for brute force detection on PostgreSQL requires more effort t...
Author: Olivia Johnson · Last updated Jul 15, 2026
You have insurance claim reports that are stored as text.
You need to extract key terms from the reports to generate s...
To extract key terms from text-based insurance claim reports and generate summaries, the best AI workload option is B) Natural Language Processing (NLP). Here's why:
Explanation of Selected Option:
1. Natural Language Processing (NLP) focuses on understanding, interpreting, and manipulating human language in text form. Key term extraction, text summarization, and document processing are core capabilities of NLP, which makes it ideal for processing textual insurance claim reports. NLP can identify relevant keywords, phrases, and entities (e.g., claims, dates, amounts) and organize them into summaries.
Why Other Options Are Rejected:
- A) Anomaly Detection: This is used to identify abnormal patterns or outliers in data. Anomaly detection is suitable for identifying fraud or detecting unusual claims but does not help in extracting key terms or summarizing text from reports. It's more focused on identifying data inconsistencies rather than processing and understanding textual content.
- C) Computer Vision: This workload is primarily used for analyzing images or videos, detecting objects, and recognizing visual patterns. While it can be useful for extracting text from scanned documents (via Opt...
Author: Joseph · Last updated Jul 13, 2026
You need to configure WebApp1 to meet the data and application requirements.
Which two actions should you perform? Each correct answer presents part o...
To meet the data and application requirements for WebApp1, you need to take actions that secure the application and ensure compatibility with the required protocols.
Analyzing the options:
A) Upload a public certificate.
- Uploading a public certificate is usually done for SSL/TLS purposes or to enable mutual authentication, but it's not strictly necessary to meet data and application requirements in every case. This is often used in scenarios where client certificates are required, but without further context, it does not seem like the top choice here.
B) Turn on the HTTPS Only protocol setting.
- Turning on HTTPS Only forces the application to only accept secure HTTPS connections. This would ensure that all communication is encrypted, which is a critical security measure. This is a good option to secure the communication between the client and WebApp1.
C) Set the Minimum TLS Version protocol setting to 1.2.
- Setting the minimum TLS version to 1.2 ensures that WebApp1 uses a more secure version of the TLS protocol for communication, preventing vulnerabilities associated with earlier versions. TLS 1.2 is currently considered a best practice for secure communication. This is another important security measure to safeguard the application.
D) Change the pricing tier of the App Service plan.
- Changing the pricing tier could affect resources like scaling, performance, and other features, but it may not directly ...
Author: Emma · Last updated Jul 15, 2026
You need to build an app that will read recipe instructions aloud to support users who have reduced vi...
To build an app that reads recipe instructions aloud to users with reduced vision, the best AI service option is C) Speech. Here's why:
Explanation of Selected Option:
- Speech services are specifically designed to convert text to spoken language, a process known as text-to-speech (TTS). This is exactly what you need for the app, as it will take the recipe instructions (text) and read them aloud to the user. The Speech service also allows for various features such as voice customization, language selection, and different speech styles, making it the ideal option for creating an accessible experience.
Why Other Options Are Rejected:
- A) Language Service: Language services are primarily focused on language understanding and processing tasks like language detection, entity recognition, and text analysis. While these can be helpful in understanding and processing the recipe text, they don't provide functionality for reading it aloud. It is not suited for the task of converting text to speech.
- B) Translator: Translator services are used for translating text from one language to ...
Author: Chloe · Last updated Jul 13, 2026
SNAPSHOT -
You need to create Role1 to meet the platform protection requirements.
How should you complete the role definition of Role1? To answer, select the appropriate options in...
Author: Sara · Last updated Jul 15, 2026
You have a webchat bot that provides responses from a QnA Maker knowledge base.
You need to ensure that the bot uses user feedback to improve t...
To ensure that the webchat bot uses user feedback to improve the relevance of its responses over time, the best AI service option is D) Active Learning. Here's why:
Explanation of Selected Option:
- Active Learning is a machine learning technique where the model learns iteratively from new data, especially from labeled data or feedback. In this case, active learning allows the bot to learn from user feedback, improving its ability to generate more relevant responses over time. By identifying areas where the bot's responses could be improved, the system can prioritize which data should be used to retrain the model and adapt its responses accordingly.
Why Other Options Are Rejected:
- A) Key Phrase Extraction: This service is used to identify important phrases or keywords in text. While key phrase extraction can help identify important terms in user queries or responses, it doesn't improve the bot's overall ability to provide better responses over time based on user feedback. Key phrase extraction is useful for content extraction, not for refining response relevance.
- B) Sentiment Analysis: Sentiment analysis is used to determine the emotional tone of text, such as whether a message is positive, negative, or neutral. While sentiment analysis could be useful for un...
Author: Ava · Last updated Jul 13, 2026
DRAG DROP -
You need to configure SQLDB1 to meet the data and application requirements.
Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the li...
Author: Daniel · Last updated Jul 15, 2026
You are developing a conversational AI solution that will communicate with users through multiple channels including email, Micr...
To develop a conversational AI solution that communicates with users across multiple channels such as email, Microsoft Teams, and webchat, the best service option is B) Azure Bot Service. Here's why:
Explanation of Selected Option:
- Azure Bot Service is specifically designed for building, deploying, and managing conversational AI solutions (chatbots) across multiple channels, including webchat, Microsoft Teams, email, and others. This service allows you to easily connect your bot to a variety of communication platforms and manage interactions seamlessly across these channels. It also offers integration with cognitive services like language understanding (LUIS) and language generation to enhance the bot's conversational abilities.
Why Other Options Are Rejected:
- A) Text Analytics: This service is focused on analyzing and extracting information from text, such as sentiment analysis, key phrase extraction, and language detection. While useful for understanding text data, it is not designed for managing multi-channel communication or building a bot framework for cross-channel interactions.
- C) Translator: The Translator service is used for translating text ...
Author: Nia · Last updated Jul 13, 2026
You need to ensure that User2 can implement PIM.
What should you do first?
To ensure that User2 can implement Privileged Identity Management (PIM), the first step is to assign them the necessary role. Let's break down the options:
Analyzing the options:
A) Assign User2 the Global administrator role.
- Privileged Identity Management (PIM) is a feature that is used to manage and secure privileged roles in Azure AD, such as the Global Administrator role. To implement PIM, User2 must have a role that allows them to manage or configure PIM. Assigning them the Global Administrator role is the most direct action since only users with this role can configure PIM settings.
B) Configure authentication methods for contoso.com.
- Configuring authentication methods is related to security measures like password policies, sign-in methods, etc. While important for security, this action doesn't directly enable User2 to configure PIM. Authentication methods would help with user verification but are not essential for the initial setup of PIM.
C) Configure the identity secure score for contoso.com.
- The Identity Secure Score is a feature of Azure AD that helps assess the security posture of an organization. While it's useful for securing the environment, it ...
Author: Zara · Last updated Jul 15, 2026
SNAPSHOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
A bot that responds to queries by internal users is an example of a conversational Al workload?.
An application that displays images relating to an entered search term is an...
The correct answer is:
C) Yes, No, No ✅
Explanation
1. A bot that responds to queries by internal users → Yes
This is a conversational AI workload because it involves natural language interaction with users.
2. An application that displays images re...
Author: Olivia · Last updated Jul 13, 2026
DRAG DROP -
You need to perform the planned changes for OU2 and User1.
Which tools should you use? To answer, drag the appropriate tools to the correct resources. Each tool may be used once, more than once, or not at all. You may need to drag the split ba...
Author: Leah Davis · Last updated Jul 15, 2026
You need to provide content for a business chatbot that will help answer simple user queries.
What are three ways to create question and answer text by using QnA Maker? Each correct answe...
For AI-900, QnA Maker (now part of Azure AI Language) lets you create question–answer content in three valid ways.
---
✅ Correct answers
A. Generate the questions and answers from an existing webpage.
✔ You can point QnA Maker to a URL and it automatically extracts Q&A pairs.
C. Manually enter the questions and answers.
✔ You can directly type custom questions and answers in the portal.
E. Import chit-chat content from a predefined data source.
✔ QnA Maker provides prebuilt chit-chat datasets (Small talk, Professional, Friendly, etc.).
---
❌ Incorrect ...
Author: VioletCheetah55 · Last updated Jul 13, 2026
You need to meet the technical requirements for the finance department users.
Which CAPolicy1 setti...
To meet the technical requirements for the office department users, you need to configure the Conditional Access policy effectively. Let's break down the options and determine the appropriate setting for your scenario.
A) Cloud apps or actions
- Description: This setting controls which cloud apps or actions the Conditional Access policy applies to.
- When to Use: You would select this option if you need to apply the policy to specific apps or certain actions, such as requiring multi-factor authentication (MFA) when accessing a particular cloud app.
- Rejection Reason: If your goal is to modify behavior based on factors like user location, device, or specific conditions of access rather than the apps or actions being used, this is not the right choice.
B) Conditions
- Description: This setting lets you specify conditions under which the policy is applied, such as the user's location, device platform, sign-in risk level, etc.
- When to Use: This is useful when you want to restrict access based on conditions such as user location (e.g., requiring MFA for users signing in from outside the corporate network) or device compliance (e.g., only allowing access from compliant devices).
- Rejection Reason: If the requirements focus solely on access control rather than conditions like user status or device health, this may not be the most effective setting.
C) Grant
- Description: This setting specifies the controls that are applied to users when they meet the conditions defined in the policy. Common controls include requiring multi-factor authentication (MFA), requiring compliant or hybrid Azure AD joined devices, or enforcing terms of u...
Author: Nia · Last updated Jul 15, 2026
You have a frequently asked questions (FAQ) PDF file.
You need to create a conversational support system b...
To create a conversational support system based on a FAQ PDF file, the best service to use would be:
A) QnA Maker
- Reasoning: QnA Maker is designed specifically to create question and answer bots, making it the ideal choice for turning a FAQ document (such as a PDF) into a structured knowledge base. It allows you to upload the FAQ file, extract the questions and answers, and create a chatbot that can respond to users with relevant answers.
- Scenario: This option is perfect when you have a structured FAQ document and you want to convert it into a chatbot for easy user interaction, enabling users to get answers by asking questions similar to those in the FAQ.
Why other options are rejected:
B) Text Analytics
- Reasoning: Text Analytics is used for tasks like sentiment analysis, entity recognition, and key phrase extraction. It is not designed for creating a conversational support system or extracting structured Q&A content from documents.
- Scenario: This service is useful for analyzing text for insights, but it doesn't help in directly ...
Author: Evelyn · Last updated Jul 13, 2026
SNAPSHOT -
You need to delegate the creation of RG2 and the management of permissions for RG1.
Which users can perform each task? To answer, select the appropriate options in ...
Author: Ravi Patel · Last updated Jul 15, 2026
You need to reduce the load on telephone operators by implementing a chatbot to answer simple questions with predefined answers.
Which two AI service should you use to achieve the goal? Each correct ...
To reduce the load on telephone operators by implementing a chatbot to answer simple questions with predefined answers, the most suitable AI services are:
B) QnA Maker
- Reasoning: QnA Maker is specifically designed to create a knowledge base from predefined questions and answers. It allows you to upload FAQ documents or manually create a Q&A set, which the chatbot can then use to respond to user queries. This makes it an ideal tool for answering simple, predefined questions.
- Scenario: Use QnA Maker to create a conversational system that answers frequently asked questions, allowing the chatbot to handle common queries that would otherwise go to telephone operators.
C) Azure Bot Service
- Reasoning: Azure Bot Service is a comprehensive platform for building and deploying chatbots. It integrates with other services like QnA Maker and allows you to create a chatbot interface that can interact with users. By using Azure Bot Service, you can deploy the QnA Maker-based chatbot, reducing the load on operators.
- Scenario: Azure Bot Service acts ...
Author: Ahmed · Last updated Jul 13, 2026
You plan to configure Azure Disk Encryption for VM4.
Which key vault can you use to store the encry...
To determine which Key Vault to use for storing the Azure Disk Encryption key for VM4, we need to consider various factors, including the access control, location, and configuration of the Key Vaults.
Key Considerations:
1. Access Control: Ensure that the Key Vault has appropriate access control set up to allow the necessary permissions for the Azure VM or the Azure Disk Encryption process to access the encryption keys.
2. Location: The Key Vault should ideally be in the same region as the VM to optimize performance and meet any possible regulatory requirements.
3. Key Vault Configuration: The Key Vault must support disk encryption, and the key it holds must be of the correct type (e.g., a Customer Managed Key for encryption). The vault should be configured to support the use of encryption keys for Azure Disk Encryption (ADE).
4. Security Considerations: Ensure that the Key Vault is configured securely, with policies like key rotation, auditing, and access restrictions.
Option Breakdown:
A) KeyVault1
- Considerations: This could be a valid choice if it is located in the same region as the VM (VM4) and has the appropriate access controls configured.
- Rejection Reason: If this Key Vault doesn’t have the correct permissions set up or is in a different region, it may not be suitable.
B) KeyVault2
- Considerations: If this Key Vault is specifically desi...
Author: Samuel · Last updated Jul 15, 2026
Which two scenarios are examples of a conversational AI workload? Each correct answer presents a complete solution....
The two scenarios that are examples of a conversational AI workload are:
A) A smart device in the home that responds to questions such as "What will the weather be like today?"
- Reasoning: This scenario involves natural language processing (NLP) where the smart device understands user input (spoken or typed) and responds with an appropriate answer (e.g., weather forecast). It is an example of conversational AI because it involves understanding and generating human-like responses in a conversational format.
- Scenario: This is a clear use case for conversational AI, as the smart device acts as a conversational agent, engaging in dialogue with the user.
B) A website that uses a knowledge base to interactively respond to users' questions
- Reasoning: This scenario is also an example of conversational AI because it involves a bot or automated system that can engage in conversations with users by providing answers based on a predefined knowledge base (like a chatbot). The user asks questions, and the AI system responds interactively.
- Scenario: This scenario involves a chatbot power...
Author: William · Last updated Jul 13, 2026
You need to encrypt storage1 to meet the technical requirements.
Which key vaults can you use?
To determine which Key Vault(s) can be used to encrypt storage1 while meeting the technical requirements, we must evaluate each option based on the factors related to key management, encryption policies, and storage compatibility.
Key Considerations for Azure Storage Encryption:
1. Key Vault Access Control: The Key Vault must have the proper permissions for the user or service to access the encryption keys for storage1.
2. Encryption Key Type: The Key Vault should store encryption keys that are suitable for Azure Storage encryption, which includes supporting Customer Managed Keys (CMK). The key should be a software key or HSM-backed key configured to be used for storage encryption.
3. Region Compatibility: The Key Vault should ideally be located in the same region as storage1 to minimize latency and ensure compliance with regional regulatory requirements.
4. Key Vault Configuration: The Key Vault must be properly configured to allow Azure Storage to use its keys for encryption (e.g., access policies must be set up for the right permissions).
Option Breakdown:
A) KeyVault2 and KeyVault3 only
- Considerations: If KeyVault2 and KeyVault3 meet the criteria for region, key type, and access permissions, this option may be valid. If KeyVault1 does not meet these requirements (for instance, incorrect permissions, region mismatch, or key configuration issues), then this option would make sense.
- Rejection Reason: If KeyVault1 is correctly configured for encryption and meets the requirements, rejecting it might be unnecessary.
B) KeyVault1 only
- Considerations: KeyVault1 could be the sole sele...
Author: Alexander · Last updated Jul 15, 2026
You have the process shown in the following exhibit.
Which type of AI solution is shown in the di...