Single Choice Moderate

Q

A company has a customer support agent that uses Azure OpenAI and retrieves information from confidential internal policy documents to generate answers.

Only the members of the company's support team are authorized to access this data.

Security testing shows that prompt injection attacks can cause the agent to return confidential content.

You need to ensure the solution design complies with the Microsoft responsible AI principle of privacy and security by enforcing server-side inspection of both user prompts and model responses.

Which design change best complies with the responsible AI principle? More than one answer choice may achieve the goal. Select the BEST answer.

ID: #26615 Practice Assessment for Exam AB-100: Agentic AI Business Solutions Architect 4 views
Question Info
#26615Q ID
ModerateDifficulty
Practice Assessment for Exam AB-100: Agentic AI Business Solutions ArchitectTopic

Choose the Best Option

Click any option to instantly check if you're correct.

  • A Add client-side content moderation to the chat UI. ✔ ✖
  • B Fine-tune the Azure OpenAI model on confidential policy documents. ✔ ✖
  • C Provide user training and warning banners about confidential data. ✔ ✖
  • D Implement a server-side gateway or an orchestration layer that will inspect and filters requests and responses. ✔ ✖
Correct Answer

Explanation

Objective:

3.4 Design responsible AI, security, governance, risk management, and compliance

What This Item Tests:

Review solution for adherence to responsible AI principles

Additional Reading:

Inspect incoming and outgoing data

Mitigate

Introduction to Microsoft's Responsible AI Approach - Introduction

Rationale:

A server-side gateway and an orchestration layer provide enforceable, centralized inspection and filtering of both inbound prompts and outbound responses before content reaches users, which complies with the responsible AI principle of security and privacy. Client-side moderation and user guidance are not reliable enforcement mechanisms, and model fine-tuning does not provide consistent or auditable protection against prompt injection-driven data leakage.

Share This Question

Challenge a friend or share with your study group.

Related MCQ Questions