Single Choice Moderate

Q

A company has a multi-agent solution built in Microsoft Foundry. The solution grounds responses in internal HR documents and uses agent tools to call internal and external systems.

Security testing shows that prompt injection attacks can expose internal HR content and some external tool calls run without clear permission boundaries.

You need to recommend a solution that enforces agent governance by applying least-privilege access to the grounding data, restricting external tool usage, and preserving auditability.

What should you recommend?

ID: #26669 Practice Assessment for Exam AB-100: Agentic AI Business Solutions Architect 10 views
Question Info
#26669Q ID
ModerateDifficulty
Practice Assessment for Exam AB-100: Agentic AI Business Solutions ArchitectTopic

Choose the Best Option

Click any option to instantly check if you're correct.

  • A Move agent logs from Log Analytics to a dedicated storage account. ✔ ✖
  • B Use a larger foundation model to reduce the prompt injection risk. ✔ ✖
  • C Enable Microsoft Defender for Cloud AI threat protection and forward alerts to Microsoft Sentinel. ✔ ✖
  • D Require managed identities and Azure RBAC for agents and tools and restrict external tool usage to explicitly approved integrations. ✔ ✖
Correct Answer

Explanation

Objective:

3.4 Design responsible AI, security, governance, risk management, and compliance

What This Item Tests:

Design governance for agents

Additional Reading:

Agent security

Governance and security for AI agents across the organization

Establish a single control plane for AI agents across the organization

Standardize authentication

Data governance and compliance

3. Agent knowledge and tools

Manage your Copilot Studio projects, an overview

Rationale:

Using managed identities with Azure RBAC enforces least-privilege access for both grounding data and tool execution, while restricting external tools to explicitly approved integrations establishes clear governance and auditability boundaries. Monitoring controls, log storage changes, or model selection do not enforce permission boundaries or govern agent tool usage.

Share This Question

Challenge a friend or share with your study group.

Related MCQ Questions