CertSafari

    Free Microsoft Certified: Azure AI Cloud Developer Associate (AI-200) Sample Questions

    35 free sample questions from our bank of 345+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Develop containerized solutions on Azure

    Subdomain 1.2: Implement container-orchestrated solutions

    1.The recommendation API's custom scale rule targets the `order-events` queue, and the queue has been empty for several minutes after a burst of traffic. Given the default scale behavior, how long does Container Apps wait after the queue empties before scaling the app down to zero replicas?

    1. A.Zero seconds, because Container Apps scales down to zero immediately the instant the queue length reaches zero
    2. B.300 seconds, matching the default cool down period that must elapse before scaling the last replica down to zero
    3. C.30 seconds, matching the default polling interval used to check the queue length rather than the cool down window
    4. D.900 seconds, because Container Apps always waits three times the default cool down period before scaling in fully
    Show answer & explanation

    Correct answer: B — 300 seconds, matching the default cool down period that must elapse before scaling the last replica down to zero

    • A. Container Apps does not scale to zero instantly when the queue empties; it waits out the configured cool down period first, so an immediate drop to zero replicas is not the default behavior.
    • B. The cool down period defaults to 300 seconds and only applies when scaling from the final replica down to zero, so KEDA waits five minutes after the queue empties before removing the last replica.
    • C. The 30-second value is the default polling interval, which controls how often KEDA checks the queue length, not how long it waits before scaling the last replica to zero.
    • D. There is no default behavior that triples the cool down period; the documented default cool down window is simply 300 seconds.

    Subdomain 1.2: Implement container-orchestrated solutions

    2.A pod on the AKS retraining cluster can reach the cluster's internal Kubernetes API but cannot resolve or connect to an external Azure Database for PostgreSQL endpoint. Which first troubleshooting step best isolates whether the problem is DNS resolution versus network connectivity?

    1. A.Run kubectl exec into the pod and use nslookup or a similar tool to test whether the database hostname resolves
    2. B.Delete the pod and let the Deployment controller recreate it, since a fresh pod often clears transient network issues
    3. C.Increase the Deployment's replica count so that at least one replica is more likely to reach the database successfully
    4. D.Restart the AKS control plane components, since kube-apiserver connectivity problems typically cause external DNS failures too
    Show answer & explanation

    Correct answer: A — Run kubectl exec into the pod and use nslookup or a similar tool to test whether the database hostname resolves

    • A. Running nslookup or dig from inside the pod via kubectl exec directly tests whether the hostname resolves, which separates a DNS problem from a downstream network or firewall issue before further diagnosis.
    • B. Recreating the pod might mask a transient issue but doesn't diagnose whether the root cause is DNS resolution or network routing, so it isn't a targeted troubleshooting step.
    • C. Adding replicas increases the chance that one instance happens to work, but it doesn't investigate or explain why the existing pod can't resolve or reach the database.
    • D. The control plane components like kube-apiserver are Azure-managed and unrelated to a workload pod's ability to resolve or reach an external database endpoint.

    Subdomain 1.2: Implement container-orchestrated solutions

    3.Given the following Deployment manifest excerpt intended to run three replicas of the recommendation API pod, which line is missing and prevents `kubectl apply -f` from creating three pods instead of the default single pod? ```yaml apiVersion: apps/v1 kind: Deployment metadata: name: recommendation-api spec: selector: matchLabels: app: recommendation-api template: metadata: labels: app: recommendation-api spec: containers: - name: recommendation-api image: northwindacr.azurecr.io/recommendation-api:v3 ```

    1. A.A replicas: 3 field is missing directly under spec, so the Deployment falls back to its default of one pod
    2. B.The apiVersion field is missing a required v2 suffix, which the Kubernetes scheduler needs to allow multiple pods
    3. C.The image tag v3 must be removed entirely, since tagged images are restricted to a single-replica Deployment
    4. D.The metadata.name field must be duplicated inside spec.template for each of the three intended replicas
    Show answer & explanation

    Correct answer: A — A replicas: 3 field is missing directly under spec, so the Deployment falls back to its default of one pod

    • A. A Deployment's spec.replicas field controls how many pod copies the controller maintains, and when it is omitted the field defaults to a single replica, which explains why only one pod would be created here.
    • B. apps/v1 is the correct and complete apiVersion for a Deployment; there is no v2 suffix requirement, and apiVersion has no bearing on replica count.
    • C. A specific image tag like v3 pins the container image version and has no relationship to how many replicas a Deployment creates.
    • D. The pod template's metadata is a single template reused for every replica the controller creates; it is not duplicated per replica, and duplicating it would be invalid YAML for this field.

    Subdomain 1.2: Implement container-orchestrated solutions

    4.Which of the following correctly describe an Azure Container Apps environment shared by the recommendation-api app and a background worker app? (Select 3.)(Select 3)

    1. A.The environment provides a secure network boundary so apps placed inside it can share the same virtual network
    2. B.The environment centralizes a shared Log Analytics workspace that collects logs from every app deployed inside it
    3. C.Apps within the same environment can reach each other over an internal address without going through public ingress
    4. D.Every app in the environment is forced to share one revision mode, since revision mode is set at the environment level
    5. E.The environment is a Kubernetes cluster that the team must patch and upgrade directly, just like a self-managed AKS node pool
    6. F.The environment must be deleted and recreated whenever a new revision is deployed to any app running inside it
    Show answer & explanation

    Correct answers: A, B, C — The environment provides a secure network boundary so apps placed inside it can share the same virtual network; The environment centralizes a shared Log Analytics workspace that collects logs from every app deployed inside it; Apps within the same environment can reach each other over an internal address without going through public ingress

    • A. A Container Apps environment defines the secure network boundary shared by the apps placed inside it, which is why co-located apps can share the same virtual network.
    • B. The environment centralizes a shared Log Analytics workspace, so logs from every contained app land in one place for querying instead of being scattered per app.
    • C. Apps in the same environment gain internal service discovery and can communicate over internal addresses without traffic leaving through public ingress.
    • D. Revision mode is configured per container app, not per environment, so two apps in the same environment can run in different revision modes independently.
    • E. Container Apps abstracts the underlying Kubernetes infrastructure away entirely; the team never patches or upgrades a cluster the way they would with self-managed AKS.
    • F. Deploying a new revision to one app has no effect on the environment resource itself, which persists unchanged across any number of revision deployments.

    Subdomain 1.1: Implement container application hosting

    5.Meridian Retail's platform team configured an Azure Container Registry task with a base image update trigger for its `web` application image, which is built from a shared `python:3.12-slim` base. Six weeks later, a critical OS patch is released for that base image on Docker Hub, and the team wants the application image rebuilt and repushed automatically, without anyone manually running a build. What additional condition must be true for this to happen automatically?

    1. A.The task must be able to detect that the tracked base image reference was updated, which it does by periodically checking the digest of the base image the application image depends on.
    2. B.Someone must manually trigger the task with `az acr build` each time a base image patch is announced, because base image update triggers only work for images hosted inside the same registry.
    3. C.The registry must be upgraded to the Premium tier, because base image update triggers are a Premium-only feature not available on Standard or Basic registries.
    4. D.The application's Dockerfile must pin the base image to a specific digest rather than a floating tag, because digest-pinned images are the only ones ACR Tasks can track for updates.
    Show answer & explanation

    Correct answer: A — The task must be able to detect that the tracked base image reference was updated, which it does by periodically checking the digest of the base image the application image depends on.

    • A. Once a task is created with a base image update trigger, Azure Container Registry Tasks track the base image dependency and detect digest changes on its own, starting a new build automatically when the tracked base image changes, whether it's in Docker Hub or an Azure registry.
    • B. This is incorrect because base image update triggers explicitly support tracking public base images outside the registry, such as ones hosted on Docker Hub, not only images inside the same registry.
    • C. This is incorrect because base image update triggers are available on Basic, Standard, and Premium registries; Premium is required for geo-replication and content trust, not for this trigger type.
    • D. This is incorrect because tracking a floating tag is exactly what allows the trigger to notice a new patched version was published; pinning to an immutable digest would prevent the dependency from ever appearing updated.

    Subdomain 1.1: Implement container application hosting

    6.An engineer configuring an Azure Container Registry task needs the build context to point at a Dockerfile inside a `services/api` subfolder of the `release` branch of a GitHub repository. Which context string correctly expresses this location?

    1. A.`https://github.com/org/repo.git#release:services/api`
    2. B.`https://github.com/org/repo.git/release/services/api`
    3. C.`https://github.com/org/repo.git?branch=release&path=services/api`
    4. D.`github.com/org/repo:release/services/api`
    Show answer & explanation

    Correct answer: A — `https://github.com/org/repo.git#release:services/api`

    • A. The `#branch:subfolder` syntax after the repository URL is the documented way to combine a specific branch with a subfolder path as a single task context.
    • B. Appending the branch and folder as plain URL path segments isn't recognized by Azure Container Registry Tasks as a way to select a branch and subfolder together.
    • C. Query-string parameters like `?branch=` and `&path=` aren't part of the supported context syntax for Git repository sources in Azure Container Registry Tasks.
    • D. Dropping the `https://` scheme and combining branch and subfolder with a plain slash doesn't match the required `git-url#branch:subfolder` context format.

    Subdomain 1.1: Implement container application hosting

    7.A team is switching an App Service app's secrets from plain app settings to Key Vault references so secrets aren't stored in App Service configuration in plaintext. Which combination of actions correctly implements this? (Choose 3.)(Select 3)

    1. A.Assign the app a managed identity, either system-assigned or user-assigned.
    2. B.Grant that managed identity the Key Vault Secrets User role, or a Get permission access policy, on the vault.
    3. C.Set the app setting's value to a `@Microsoft.KeyVault(SecretUri=...)` or `@Microsoft.KeyVault(VaultName=...;SecretName=...)` string.
    4. D.Store the raw secret value directly in the `web.config` or startup script bundled inside the container image.
    5. E.Enable the registry's admin user account so the vault can authenticate registry pulls on the app's behalf.
    6. F.Set every Key Vault-referencing app setting to be a deployment slot setting so each environment can point at its own vault.
    Show answer & explanation

    Correct answers: A, B, C — Assign the app a managed identity, either system-assigned or user-assigned.; Grant that managed identity the Key Vault Secrets User role, or a Get permission access policy, on the vault.; Set the app setting's value to a `@Microsoft.KeyVault(SecretUri=...)` or `@Microsoft.KeyVault(VaultName=...;SecretName=...)` string.

    • A. A managed identity is required because Key Vault references resolve using that identity to authenticate to the vault at runtime.
    • B. The identity needs explicit read access to secrets, granted through either Azure RBAC or a vault access policy, or the reference will fail to resolve.
    • C. The app setting's value must be the Key Vault reference string itself; App Service resolves that string into the underlying secret value for the running app.
    • D. Baking the raw secret into the image or a config file defeats the purpose of moving it to Key Vault, since the secret is still stored in plaintext, just in a different place.
    • E. The registry's admin account has nothing to do with Key Vault authentication; it governs image pull credentials for the container registry, not secret access.
    • F. Marking these settings as slot settings is a reasonable practice for keeping environments separate, but it is not a required step for the reference itself to resolve, so it isn't part of what correctly implements the reference.

    Subdomain 1.1: Implement container application hosting

    8.A security team wants an App Service Linux web app to pull its container image from Azure Container Registry entirely over private networking, with no image pull traffic crossing the public internet. Which combination of configurations achieves this? (Choose 3.)(Select 3)

    1. A.Integrate the App Service app with a virtual network and enable `vnetImagePullEnabled` so pull traffic is routed through that network.
    2. B.Configure a private endpoint for the Azure Container Registry inside the same or a peered virtual network.
    3. C.Ensure DNS resolution for the registry's login server resolves to the private endpoint's private IP address from the app's network path.
    4. D.Add the App Service app's public outbound IP addresses to the registry's IP access rules allow list.
    5. E.Enable the registry's admin user account so authentication no longer depends on Microsoft Entra ID.
    6. F.Turn on geo-replication so the nearest replica is always used regardless of network path.
    Show answer & explanation

    Correct answers: A, B, C — Integrate the App Service app with a virtual network and enable `vnetImagePullEnabled` so pull traffic is routed through that network.; Configure a private endpoint for the Azure Container Registry inside the same or a peered virtual network.; Ensure DNS resolution for the registry's login server resolves to the private endpoint's private IP address from the app's network path.

    • A. Virtual network integration combined with the image-pull routing setting is what forces the app's own pull requests onto the private network path instead of the public internet.
    • B. A private endpoint gives the registry a private IP address reachable from inside the virtual network, which is the resource pull traffic needs to reach privately.
    • C. Even with a private endpoint configured, pulls will still go over the public path unless DNS resolves the registry's hostname to that private IP for the app.
    • D. Allow-listing public outbound IPs is a public-network access control; it does nothing to keep the traffic itself off the public internet, which is the actual requirement here.
    • E. The admin account authentication method is unrelated to network path; enabling it doesn't change whether traffic is public or private.
    • F. Geo-replication controls which regional replica serves a pull for latency and availability; it doesn't make the traffic path private.

    Domain 2: Develop AI solutions by using Azure data management services

    Subdomain 2.3: Integrate Azure Managed Redis in AI solutions

    9.Meridian Imaging built a RAG chatbot backed by Azure Managed Redis. On a request for radiology-report guidance, the application checks Redis first; on a miss it queries Cosmos DB, then must decide how to keep the cache populated for the next similar request without reworking the read path. Which caching pattern should the team implement?

    1. A.Use cache-aside: query Cosmos DB directly on a cache miss, then write the fetched result into Redis before returning it to the caller.
    2. B.Use write-behind: write every response to Redis first, then have a background worker persist that same value into Cosmos DB later.
    3. C.Use read-through: configure the Cosmos DB change feed to push every write directly into Redis so the app never queries Cosmos DB.
    4. D.Use refresh-ahead: run a scheduled timer that repopulates Redis keys before they expire, independent of whether any request occurs.
    Show answer & explanation

    Correct answer: A — Use cache-aside: query Cosmos DB directly on a cache miss, then write the fetched result into Redis before returning it to the caller.

    • A. Cache-aside keeps the read path in application control: on a miss the app fetches from Cosmos DB and populates Redis itself, which is exactly the behavior described and requires no extra infrastructure to rework the read path.
    • B. Write-behind writes to the cache first and defers the database write, which does not describe a request flow that reads from Cosmos DB on a miss and populates Redis afterward.
    • C. Routing every Cosmos DB write through the change feed into Redis is a separate pipeline that the team would need to build, not the simple on-miss population the scenario calls for.
    • D. Refresh-ahead proactively repopulates keys on a timer regardless of requests, which does not match a design where the app reads Redis first and falls back to Cosmos DB only on a miss.

    Subdomain 2.3: Integrate Azure Managed Redis in AI solutions

    10.NovaHealth Diagnostics stores each indexed clinical note as a nested document containing the embedding plus structured fields such as patient cohort, department, and a list of prior visit IDs. Which Redis data structure and module combination best fits storing and querying this nested document alongside its vector?

    1. A.Store the document with RedisJSON and index it with RediSearch, since JSON supports the nested fields and arrays alongside the vector field.
    2. B.Store the document as a Hash and index it with RediSearch, since hashes natively support nested objects and arrays inside a single field.
    3. C.Store the document with RedisTimeSeries and index it with RediSearch, since time series labels can represent nested cohort and visit data.
    4. D.Store the document as a Hash and index it with RedisBloom, since bloom filters can represent nested arrays of prior visit identifiers.
    Show answer & explanation

    Correct answer: A — Store the document with RedisJSON and index it with RediSearch, since JSON supports the nested fields and arrays alongside the vector field.

    • A. RedisJSON is designed to store nested objects and arrays, and it is meant to be paired with RediSearch for integrated indexing and querying, which fits a document with cohort, department, and a list of visit IDs.
    • B. A Redis Hash is a flat field-value structure and does not natively represent nested objects or arrays, so it is a poor fit for a document containing a list of prior visit IDs.
    • C. RedisTimeSeries labels are simple key-value tags for time-stamped metrics, not a mechanism for representing nested documents with arrays and structured fields.
    • D. RedisBloom provides probabilistic membership filters, not document storage, and a plain Hash still cannot hold nested arrays natively.

    Subdomain 2.3: Integrate Azure Managed Redis in AI solutions

    11.Which combination of provisioning choices must the Meridian Imaging team make when creating a new Azure Managed Redis instance that will host a RediSearch vector index? (Select all that apply.)(Select 3)

    1. A.Enable the RediSearch module at instance creation time, since modules cannot be added to an existing cache afterward.
    2. B.Select the Enterprise clustering policy, since RediSearch requires it and cannot run on other clustering modes.
    3. C.Set the eviction policy to NoEviction, since RediSearch requires that Redis never evict keys under memory pressure.
    4. D.Choose the Flash Optimized tier, since it is the only tier built specifically for large vector datasets.
    5. E.Enable active geo-replication across regions, since RediSearch cannot operate on any single-region cache instance.
    6. F.Disable data persistence, since RediSearch indexes cannot coexist with on-disk backup copies of the data.
    Show answer & explanation

    Correct answers: A, B, C — Enable the RediSearch module at instance creation time, since modules cannot be added to an existing cache afterward.; Select the Enterprise clustering policy, since RediSearch requires it and cannot run on other clustering modes.; Set the eviction policy to NoEviction, since RediSearch requires that Redis never evict keys under memory pressure.

    • A. Azure Managed Redis modules must be selected at creation time and cannot be manually added afterward, so enabling RediSearch during provisioning is required.
    • B. RediSearch requires the Enterprise clustering policy, and this is a documented prerequisite the team must configure at creation.
    • C. RediSearch requires the NoEviction eviction policy so that Redis never silently drops indexed keys under memory pressure.
    • D. Flash Optimized is the one in-memory-tier family that does not support RediSearch at all, making it the wrong choice for this vector search workload.
    • E. RediSearch works on a single-region instance; active geo-replication is an optional resilience feature, not a prerequisite for enabling the module.
    • F. Data persistence is a separate on-disk backup feature supported across tiers and is not incompatible with running a RediSearch index.

    Subdomain 2.2: Develop AI solutions by using Azure Database for PostgreSQL

    12.Meridian Health Analytics stores clinical guideline excerpts as 1536-dimension embeddings in an `embedding vector(1536)` column inside Azure Database for PostgreSQL Flexible Server. The table holds 40 million rows, and the RAG chatbot backing the clinician portal must return top-k matches in well under 100 ms during business hours. Which index type should the team create on the `embedding` column to meet this requirement?

    1. A.IVFFlat index
    2. B.HNSW index
    3. C.B-tree index
    4. D.GIN index
    Show answer & explanation

    Correct answer: B — HNSW index

    • A. IVFFlat trades query speed for faster, lower-memory builds, so it does not deliver the lowest per-query latency at 40 million rows.
    • B. HNSW builds a multilayer graph that gives the fastest approximate nearest-neighbor lookups among pgvector's index types, matching this sub-100 ms target at large scale.
    • C. A B-tree index only supports equality and range comparisons on scalar columns, so it cannot accelerate nearest-neighbor distance searches on a vector column.
    • D. A GIN index accelerates containment and full-text lookups on composite or array types, not distance ordering over vector embeddings.

    Subdomain 2.2: Develop AI solutions by using Azure Database for PostgreSQL

    13.A team is sizing the `lists` parameter for an IVFFlat index on a table expected to hold 500,000 embedding rows. Which value follows pgvector's general sizing guidance for a table under one million rows?

    1. A.Approximately `rows / 1000`, giving roughly 500 lists for this table's expected row count.
    2. B.Approximately `rows / 10`, giving roughly 50,000 lists regardless of how large the table grows.
    3. C.A fixed value of 1, since IVFFlat performs best with a single inverted list at any scale.
    4. D.Approximately the square root of the total number of rows, applied the same way at every table size.
    Show answer & explanation

    Correct answer: A — Approximately `rows / 1000`, giving roughly 500 lists for this table's expected row count.

    • A. pgvector's guidance suggests `rows / 1000` for tables under roughly one million rows, which lands near 500 lists for 500,000 rows and balances list count against list size.
    • B. A `rows / 10` ratio produces far more lists than pgvector recommends at this scale, fragmenting the index and hurting recall without a proportional speed benefit.
    • C. A single list defeats the purpose of the inverted-list structure, effectively making every query scan the entire table.
    • D. The square-root formula is the guidance for tables larger than roughly one million rows, not for a 500,000-row table.

    Subdomain 2.2: Develop AI solutions by using Azure Database for PostgreSQL

    14.Which combination of changes would reduce query latency on Meridian Health's HNSW-backed vector search without discarding relevant candidates entirely? (Select all that apply.)(Select 3)

    1. A.Limit the `vector(n)` column to only as many dimensions as the embedding model actually produces, avoiding unnecessary padding.
    2. B.Scale the compute tier up to add more vCores so concurrent queries have less contention for CPU time.
    3. C.Lower `hnsw.ef_search` far enough that most relevant candidates are excluded from the search entirely.
    4. D.Enable PgBouncer transaction pooling so short-lived query connections avoid full connection setup overhead each time.
    5. E.Store every embedding as `text` instead of `vector` so PostgreSQL treats comparisons as simple string operations.
    6. F.Disable the HNSW index and force a full sequential scan for every similarity query to guarantee exact results.
    Show answer & explanation

    Correct answers: A, B, D — Limit the `vector(n)` column to only as many dimensions as the embedding model actually produces, avoiding unnecessary padding.; Scale the compute tier up to add more vCores so concurrent queries have less contention for CPU time.; Enable PgBouncer transaction pooling so short-lived query connections avoid full connection setup overhead each time.

    • A. Matching the column dimension to the actual embedding size avoids wasted storage and comparison overhead per row, reducing the work each query does.
    • B. More vCores reduce contention when many similarity queries run concurrently, directly lowering per-query wait time under load.
    • C. Lowering `ef_search` too far trades away real matches for speed, which is the failure mode the question asks the team to avoid, not a valid latency fix here.
    • D. Transaction pooling reduces the overhead of establishing a fresh backend connection for every short query, cutting latency contributed by connection setup.
    • E. Storing embeddings as `text` removes pgvector's typed distance operators and indexing entirely, forcing far slower comparisons, not faster ones.
    • F. Disabling the index guarantees exact results but turns every query into a full table scan, which increases latency rather than reducing it.

    Subdomain 2.1: Develop AI solutions by using Azure Cosmos DB for NoSQL

    15.Which statement correctly ranks Azure Cosmos DB's five consistency levels from strongest to weakest?

    1. A.Strong, bounded staleness, session, consistent prefix, eventual.
    2. B.Strong, session, bounded staleness, eventual, consistent prefix.
    3. C.Bounded staleness, strong, consistent prefix, session, eventual.
    4. D.Strong, consistent prefix, session, bounded staleness, eventual.
    Show answer & explanation

    Correct answer: A — Strong, bounded staleness, session, consistent prefix, eventual.

    • A. This matches the documented order from the strongest read guarantee to the weakest across Azure Cosmos DB's five consistency levels.
    • B. This ordering swaps session and bounded staleness and places consistent prefix last, which doesn't match the documented strength ranking.
    • C. This ordering places bounded staleness above strong consistency, which reverses their actual relative strength.
    • D. This ordering places consistent prefix above session, but session is documented as the stronger of the two levels.

    Subdomain 2.1: Develop AI solutions by using Azure Cosmos DB for NoSQL

    16.NorthWind Diagnostics wants to store 1536-dimension OpenAI embeddings alongside each clinical note document, using cosine similarity for retrieval. Which container vector policy definition is correct?

    1. A.`{"path": "/contentVector", "dataType": "vector32", "distanceFunction": "cosine", "dimensions": 1536}`
    2. B.`{"path": "/contentVector", "dataType": "float32", "distanceFunction": "cosine", "dimensions": 1536}`
    3. C.`{"path": "/contentVector", "dataType": "float32", "distanceFunction": "cosine", "dimensions": "1536"}`
    4. D.`{"path": "/contentVector", "dataType": "float32", "similarityMetric": "cosine", "dimensions": 1536}`
    Show answer & explanation

    Correct answer: B — `{"path": "/contentVector", "dataType": "float32", "distanceFunction": "cosine", "dimensions": 1536}`

    • A. `vector32` is not one of the supported vector data types; the supported floating types are `float32` and `float16`, alongside `int8` and `uint8`.
    • B. `float32` is a supported data type, `cosine` is a supported distance function, and `dimensions` is a numeric value matching the 1536-dimension embedding.
    • C. The `dimensions` field must be a numeric value, not a quoted string, or the container vector policy fails validation.
    • D. The container vector policy field is named `distanceFunction`, not `similarityMetric`, so this key wouldn't be recognized as intended.

    Subdomain 2.1: Develop AI solutions by using Azure Cosmos DB for NoSQL

    17.A NorthWind Diagnostics developer wants to react to new and updated clinical notes from a Python service by using the Azure Cosmos DB SDK's change feed processor with a lease container, matching a pattern they've seen used in a .NET sample. What should they do instead, given the Python SDK's current change feed support?

    1. A.Install the .NET change feed processor library alongside the Python SDK so both languages share the same lease container implementation.
    2. B.Configure the account to use the REST API directly, since the change feed processor is unavailable through any Azure Cosmos DB SDK.
    3. C.Use the change feed pull model, which gives direct access to the change feed but requires the application to manage checkpoints manually.
    4. D.Use Azure Functions with a generic HTTP trigger to periodically call the monitored container's read endpoint on a fixed schedule.
    Show answer & explanation

    Correct answer: C — Use the change feed pull model, which gives direct access to the change feed but requires the application to manage checkpoints manually.

    • A. SDK libraries aren't cross-language installable components, so a Python application can't invoke a .NET library's change feed processor implementation.
    • B. The change feed processor specifically is unsupported for Python and Node.js SDKs, but the underlying change feed itself remains fully available through those SDKs' pull model.
    • C. The change feed processor library is only available for .NET and Java, so Python and Node.js applications use the pull model and manage their own continuation tokens and checkpoints.
    • D. A generic scheduled poll doesn't use the change feed's continuation tokens, so it would miss the ordering and completeness guarantees the change feed itself provides.

    Subdomain 2.2: Develop AI solutions by using Azure Database for PostgreSQL

    18.Which statement about `ivfflat.probes` is accurate when querying an IVFFlat index?

    1. A.Increasing `ivfflat.probes` searches more of the inverted lists per query, which improves recall at the cost of additional query time.
    2. B.`ivfflat.probes` controls how many rows are stored inside each inverted list during the index build, not query-time search behavior.
    3. C.Setting `ivfflat.probes` to zero disables the IVFFlat index completely and forces PostgreSQL to automatically use a sequential scan instead.
    4. D.`ivfflat.probes` is a permanent, index-wide setting fixed at build time that cannot be changed per session, per role, or per query.
    Show answer & explanation

    Correct answer: A — Increasing `ivfflat.probes` searches more of the inverted lists per query, which improves recall at the cost of additional query time.

    • A. `ivfflat.probes` is a query-time parameter, and raising it makes the search visit more lists before returning results, trading some latency for better recall.
    • B. List membership is determined at build time by the clustering algorithm and the `lists` parameter, not by the query-time `probes` setting.
    • C. Setting probes to zero is not a documented way to disable the index, and PostgreSQL does not automatically substitute a sequential scan from that setting alone.
    • D. `ivfflat.probes` is a runtime parameter that can be set per session with `SET`, so it is not fixed for the life of the index.

    Subdomain 2.1: Develop AI solutions by using Azure Cosmos DB for NoSQL

    19.Clinicians in the NorthWind Diagnostics portal edit their own patient notes and must always see their own most recent edit immediately after saving, even though the account spans multiple regions. Strict global ordering across all users is not required. Which consistency level meets this need with the lowest latency?

    1. A.Strong consistency, so every read in every region reflects the most recently committed write across the entire account.
    2. B.Bounded staleness consistency, so reads across regions lag writes only up to a configured number of versions or a time window.
    3. C.Session consistency, so each client presents its session token on every read and always sees its own prior writes.
    4. D.Eventual consistency, so reads return whichever version of the item is currently available on any regional replica.
    Show answer & explanation

    Correct answer: C — Session consistency, so each client presents its session token on every read and always sees its own prior writes.

    • A. Strong consistency provides this guarantee but at the cost of cross-region write latency that this per-user scenario doesn't actually need.
    • B. Bounded staleness bounds cross-region lag globally but doesn't specifically guarantee that an individual client always reads back its own most recent write.
    • C. Session consistency guarantees a client that just wrote an item will read that same write back using its session token, at latency comparable to eventual consistency.
    • D. Eventual consistency offers no read-your-writes guarantee, so a clinician could briefly see a stale version of a note they just saved.

    Domain 3: Connect to and consume Azure services

    Subdomain 3.1: Develop event- and message-based AI solutions

    20.A developer on the Litware claims platform needs to inspect messages that Service Bus already moved into the audit-log subscription's dead-letter sub-queue using the Azure.Messaging.ServiceBus .NET library. Which configuration lets the receiver read from that sub-queue instead of the live subscription?

    1. A.Set `ServiceBusReceiverOptions.SubQueue` to `SubQueue.DeadLetter` when creating the receiver for the claims-events topic and audit-log subscription.
    2. B.Call `ServiceBusReceiver.DeadLetterMessageAsync` on every message pulled from the live subscription to redirect it into the sub-queue.
    3. C.Create a second subscription on the claims-events topic and add a SQL filter rule that matches only already dead-lettered messages.
    4. D.Set the `TimeToLive` property on the `ServiceBusReceiverOptions` to zero so expired messages are exposed directly to the receiver.
    Show answer & explanation

    Correct answer: A — Set `ServiceBusReceiverOptions.SubQueue` to `SubQueue.DeadLetter` when creating the receiver for the claims-events topic and audit-log subscription.

    • A. Setting SubQueue to SubQueue.DeadLetter tells the client library to address the audit-log subscription's dead-letter path directly, so the receiver reads from the sub-queue rather than the live subscription.
    • B. DeadLetterMessageAsync is how an application explicitly sends a message it already received into the dead-letter sub-queue; it does not configure a receiver to read from that sub-queue.
    • C. Dead-lettered messages are not visible to ordinary subscription filter rules because filters evaluate messages arriving at the topic, not messages already parked in a sub-queue.
    • D. Time-to-live controls how long a message stays active before expiring; it has no effect on which sub-queue a receiver is scoped to read from.

    Subdomain 3.1: Develop event- and message-based AI solutions

    21.Litware wants undelivered OCR events to be preserved instead of dropped once Event Grid exhausts its retry attempts. What must be configured on the event subscription to achieve this?

    1. A.A dead-letter destination pointing at a container in an Azure Storage account, specified when creating the event subscription.
    2. B.Nothing extra — Event Grid automatically preserves every undelivered event in a hidden system storage location by default.
    3. C.A Service Bus dead-letter sub-queue attached to the event subscription, since Event Grid reuses Service Bus's dead-letter infrastructure directly.
    4. D.A second event subscription with a longer time-to-live that automatically inherits any events the first subscription failed to deliver.
    Show answer & explanation

    Correct answer: A — A dead-letter destination pointing at a container in an Azure Storage account, specified when creating the event subscription.

    • A. Dead-lettering in Event Grid is off unless you point the event subscription at a storage account container to hold undelivered events after retries and time-to-live are exhausted.
    • B. There is no automatic hidden preservation; without an explicitly configured dead-letter destination, events that exhaust retries are dropped rather than saved anywhere.
    • C. Event Grid's dead-letter mechanism writes to Blob storage, not to a Service Bus sub-queue; the two dead-letter systems belong to separate services and are not interchangeable.
    • D. A second subscription does not inherit failed deliveries from the first; each event subscription evaluates and delivers matching events independently.

    Subdomain 3.1: Develop event- and message-based AI solutions

    22.Litware's operations team finds unexpected messages piling up in the document-ocr subscription's dead-letter sub-queue and wants to identify the root causes before fixing anything. Select the two `DeadLetterReason` values below that indicate the message itself was structurally too large or too old, rather than a processing failure by the OCR worker.(Select 2)

    1. A.`HeaderSizeExceeded`, meaning the message's size quota was exceeded.
    2. B.`TTLExpiredException`, meaning the message's time-to-live elapsed before it was consumed.
    3. C.`MaxDeliveryCountExceeded`, meaning delivery attempts ran out without a successful completion.
    4. D.`Session ID is null`, meaning a session-enabled entity received a message without a session identifier.
    5. E.`MaxTransferHopCountExceeded`, meaning an auto-forwarding chain exceeded the allowed number of hops.
    Show answer & explanation

    Correct answers: A, B — `HeaderSizeExceeded`, meaning the message's size quota was exceeded.; `TTLExpiredException`, meaning the message's time-to-live elapsed before it was consumed.

    • A. HeaderSizeExceeded reflects the message exceeding a size quota, which is a structural property of the message itself rather than anything the OCR worker did during processing.
    • B. TTLExpiredException means the message aged out of its allowed lifetime before any consumer processed it, again a property of the message's timing rather than a worker failure.
    • C. MaxDeliveryCountExceeded reflects repeated failed or abandoned processing attempts by consumers, which points at worker behavior rather than the message's size or age.
    • D. A missing session ID is a configuration mismatch between the message and a session-enabled entity, not a size or expiration issue with the message itself.
    • E. Exceeding the forwarding hop count is about the routing chain the message traveled through, not the size or time-to-live of the message content.

    Subdomain 3.2: Develop and implement Azure Functions

    23.A serverless API built with an HTTP-triggered function must accept requests like /orders/{orderId} and use the orderId segment as a lookup key inside the function code. What is the correct way to expose that value to the function?

    1. A.Define a route template with a `{orderId}` placeholder on the HTTP trigger, then bind that placeholder to a function parameter so it is passed in automatically.
    2. B.Parse the raw request URL string manually inside the function body every time, since Azure Functions has no built-in support for named route segments.
    3. C.Store the identifier in a custom HTTP response header on every incoming request, then read that header value back out inside the function handler.
    4. D.Configure the value as an application setting named `orderId` so the runtime injects the current request's path segment into that setting automatically.
    Show answer & explanation

    Correct answer: A — Define a route template with a `{orderId}` placeholder on the HTTP trigger, then bind that placeholder to a function parameter so it is passed in automatically.

    • A. Correct: declaring a route placeholder on the trigger and binding it to a parameter is the documented way to receive named path segments automatically.
    • B. Incorrect: manual URL parsing is unnecessary work, since the HTTP trigger's route template mechanism already extracts named segments for the function.
    • C. Incorrect: a response header is sent back to the caller after processing, so it cannot be used to receive an identifier from an incoming request.
    • D. Incorrect: application settings are static configuration values loaded at startup, not per-request values that change with each incoming path.

    Subdomain 3.2: Develop and implement Azure Functions

    24.Contoso Claims needs a serverless API backend where a single submitted claim event must be independently delivered to three different downstream processors (fraud check, notification, and archival), each consuming at its own pace with the ability to filter which events it receives. Which trigger-binding pairing fits this fan-out requirement best?

    1. A.Publish the event to a Service Bus topic and give each downstream processor its own Service Bus subscription trigger, optionally with a filter rule.
    2. B.Publish the event to a single Storage queue and let each of the three processors compete to dequeue the same queue message independently.
    3. C.Publish the event to three separate Storage queues and write duplicate messages from the API function to each of the queues in turn.
    4. D.Publish the event to a Timer-triggered function that polls a shared table on a fixed schedule and forwards rows to each processor in sequence.
    Show answer & explanation

    Correct answer: A — Publish the event to a Service Bus topic and give each downstream processor its own Service Bus subscription trigger, optionally with a filter rule.

    • A. Correct: a Service Bus topic with per-processor subscriptions and optional filters is purpose-built for delivering one event independently to multiple consumers.
    • B. Incorrect: a Storage queue message is delivered to only one competing consumer, so the other two processors would never see that event.
    • C. Incorrect: manually duplicating messages across three queues works but adds fragile custom logic and offers no built-in per-consumer filtering.
    • D. Incorrect: polling a shared table on a schedule introduces unnecessary latency and coupling compared to an event-driven fan-out mechanism.

    Subdomain 3.2: Develop and implement Azure Functions

    25.A team wants to enable remote build for a function app running on a Linux Elastic Premium plan, using tooling that doesn't already configure it automatically. Which two application settings must be set together to enable this?(Select 2)

    1. A.ENABLE_ORYX_BUILD set to true
    2. B.SCM_DO_BUILD_DURING_DEPLOYMENT set to true
    3. C.WEBSITE_RUN_FROM_PACKAGE set to 1
    4. D.FUNCTIONS_WORKER_RUNTIME set to python
    5. E.AzureWebJobsStorage set to a new connection string
    Show answer & explanation

    Correct answers: A, B — ENABLE_ORYX_BUILD set to true; SCM_DO_BUILD_DURING_DEPLOYMENT set to true

    • A. Correct: this setting is one of the two application settings that together request a remote build on Linux hosting plans.
    • B. Correct: this setting is the companion flag that, together with the Oryx build setting, enables the platform to build the deployment remotely.
    • C. Incorrect: this setting should specifically not be set when requesting a remote build, since it conflicts with the platform's remote build and run-from-package behavior.
    • D. Incorrect: this setting identifies the function app's language worker and is required generally, but it doesn't toggle remote build behavior.
    • E. Incorrect: this setting configures the default storage connection used by the runtime and has no effect on whether a remote build occurs.

    Subdomain 3.2: Develop and implement Azure Functions

    26.A team troubleshooting a failed deployment to a Linux Consumption plan function app finds the following application settings already configured for that app: ``` ENABLE_ORYX_BUILD=true SCM_DO_BUILD_DURING_DEPLOYMENT=true WEBSITE_RUN_FROM_PACKAGE=1 ``` Deployments intermittently fail to pick up rebuilt dependencies. Which line should be removed to fix the conflicting configuration?

    1. A.WEBSITE_RUN_FROM_PACKAGE=1, because this setting must not be set when a remote build is requested through the Oryx build settings.
    2. B.ENABLE_ORYX_BUILD=true, because this setting is only valid on Windows Consumption plans and has no effect on Linux.
    3. C.SCM_DO_BUILD_DURING_DEPLOYMENT=true, because this setting conflicts with any Linux-based hosting plan and must always remain false.
    4. D.None of the lines need to be removed, because all three settings are fully compatible together on the Linux Consumption plan.
    Show answer & explanation

    Correct answer: A — WEBSITE_RUN_FROM_PACKAGE=1, because this setting must not be set when a remote build is requested through the Oryx build settings.

    • A. Correct: documented guidance is explicit that this setting shouldn't be set at the same time a remote build is requested through the Oryx build settings.
    • B. Incorrect: this setting is specifically the one used to request a remote build on Linux plans, not Windows, so the claim reverses its actual purpose.
    • C. Incorrect: this setting is one of the two settings that together enable a valid remote build configuration on Linux, not a conflicting one.
    • D. Incorrect: the combination described is exactly the documented conflict that causes inconsistent deployment behavior, so a line does need to be removed.

    Subdomain 3.1: Develop event- and message-based AI solutions

    27.Litware's fraud-scoring worker sometimes reprocesses the same claims-events message twice because of retries after transient network failures, and downstream scoring must not be applied twice to the same claim. Which Service Bus capability should Litware enable to detect and discard the duplicate?

    1. A.Duplicate detection on the queue or topic, so messages carrying a `MessageId` already seen within the configured detection window are discarded.
    2. B.Sessions on the fraud-scoring subscription, since grouping messages by session automatically removes any duplicate deliveries within a session.
    3. C.Setting a shorter `TimeToLive` on the claims-events topic expires messages faster, so a transient-failure retry can never redeliver the same message.
    4. D.A higher `MaxDeliveryCount` on the subscription, which reduces how often a transient failure forces redelivery of the same message.
    Show answer & explanation

    Correct answer: A — Duplicate detection on the queue or topic, so messages carrying a `MessageId` already seen within the configured detection window are discarded.

    • A. Duplicate detection compares each incoming message's MessageId against ones already accepted within the detection window and discards exact repeats, which is the documented mechanism for exactly-once-style processing.
    • B. Sessions group related messages for ordered processing by a single consumer; they do not compare message identifiers to filter out duplicates caused by retried sends.
    • C. Time-to-live only controls how long a message stays eligible for delivery before expiring; shortening it does not change whether a retried send is recognized as a duplicate.
    • D. Raising the delivery attempt limit changes how many times an unsettled message can be redelivered before dead-lettering; it does nothing to detect or suppress duplicate sends caused by network retries.

    Domain 4: Secure, monitor, and troubleshoot Azure solutions

    Subdomain 4.2: Monitor and troubleshoot Azure solutions

    28.The team is troubleshooting elevated 5xx responses across Meridian's checkout flow using Application Insights logs. Which KQL practices will help them narrow down the root cause?(Select 3)

    1. A.Filter the requests table on resultCode startswith "5" and a recent ago() time window to isolate failing requests first.
    2. B.Join the filtered requests results to the exceptions table on operation_Id to see which exceptions occurred during those same operations.
    3. C.Summarize the dependencies table by target and success to check whether a specific downstream call is failing at the same time.
    4. D.Run a .create table management command inside the same query to persist the failing rows for later comparison.
    5. E.Skip the exceptions table entirely, since requests.resultCode always contains the full exception stack trace already.
    6. F.Query only the customMetrics table, since HTTP result codes are not tracked anywhere else in Application Insights.
    Show answer & explanation

    Correct answers: A, B, C — Filter the requests table on resultCode startswith "5" and a recent ago() time window to isolate failing requests first.; Join the filtered requests results to the exceptions table on operation_Id to see which exceptions occurred during those same operations.; Summarize the dependencies table by target and success to check whether a specific downstream call is failing at the same time.

    • A. Filtering requests on a 5xx result code within a recent time window is the natural first step to isolate exactly the failing requests under investigation.
    • B. Joining on operation_Id links each failing request to any exceptions raised during the same operation, which is the standard correlation technique across these tables.
    • C. Summarizing dependencies by target and success reveals whether a specific downstream service is the source of the failures, which is directly relevant to root-causing 5xx errors.
    • D. A management command like .create table cannot be embedded inside a tabular query and would not help correlate the failing rows within this investigation.
    • E. requests.resultCode is only a numeric status code and does not contain exception stack traces, so skipping the exceptions table would remove important diagnostic detail.
    • F. HTTP result codes are recorded on the requests table itself, so restricting the investigation to customMetrics would miss the very data needed to isolate the failures.

    Subdomain 4.1: Implement secure Azure solutions

    29.The security team wants Meridian Health's engineers to stop hardcoding a third-party API key anywhere in application code, and instead retrieve the current value at runtime by referencing a stable identifier that also lets them fetch a specific prior value if a rollback is needed. What should the application call to retrieve the secret this way?

    1. A.Retrieve the secret by its Key Vault URI, which addresses a specific version or the latest version of the value on demand.
    2. B.Read the API key from a checked-in `.env` file that the deployment pipeline decrypts locally before packaging the container image.
    3. C.Compile the API key into the application binary at build time using a preprocessor macro defined in the CI pipeline.
    4. D.Cache the API key permanently in the container's local disk on first launch so no further vault calls are required.
    Show answer & explanation

    Correct answer: A — Retrieve the secret by its Key Vault URI, which addresses a specific version or the latest version of the value on demand.

    • A. Applications retrieve Key Vault secrets through a URI that can target the current version or a specific historical version, which is exactly the addressable, rollback-friendly retrieval the scenario asks for.
    • B. A checked-in file, even encrypted, reintroduces the credential into source control and version history, which is the hardcoding pattern the security team is trying to eliminate.
    • C. Compiling the key into the binary means every rotation requires a rebuild and redeploy, and the key is now embedded in a distributable artifact rather than centrally managed.
    • D. Caching the value permanently on local disk defeats centralized secret management and means a rotated secret in the vault never reaches the running container.

    Subdomain 4.1: Implement secure Azure solutions

    30.Meridian Health stores a SQL Server password in Key Vault and wants it rotated automatically before it expires, without a person manually generating and re-entering a new password. Which mechanism does Key Vault use to start this automated rotation?

    1. A.Key Vault publishes a `SecretNearExpiry` event to Event Grid roughly 30 days before expiration, which triggers a function that rotates the secret.
    2. B.Key Vault sends a rotation email to the vault owner, who must manually paste the newly chosen password into the Azure portal secret blade.
    3. C.Key Vault automatically regenerates any secret's value in place the moment its expiration date is reached, with no external trigger needed.
    4. D.Azure Monitor alerts fire when a secret's TTL elapses, and an administrator must approve a rotation request in the Azure Advisor dashboard.
    Show answer & explanation

    Correct answer: A — Key Vault publishes a `SecretNearExpiry` event to Event Grid roughly 30 days before expiration, which triggers a function that rotates the secret.

    • A. Thirty days before a secret's expiration date, Key Vault raises a near-expiry event that Event Grid delivers to a subscribed endpoint such as a function, which then generates and stores the new version.
    • B. Key Vault does not send rotation emails, and requiring a person to paste a new password back in defeats the purpose of an automated rotation pipeline.
    • C. Key Vault itself never regenerates secret values; it only stores versions and raises the near-expiry event, leaving the actual value generation and update to an external function or automation.
    • D. Azure Advisor produces recommendations and does not manage secret expiration workflows, and Key Vault rotation does not route through an Advisor approval step.

    Subdomain 4.1: Implement secure Azure solutions

    31.Meridian Health is designing an automated secret rotation pipeline for a SQL Server credential stored in Key Vault. Which combination of components must be provisioned for the documented rotation pattern to work? (Choose 3)(Select 3)

    1. A.A function app with a system-assigned managed identity granted a role to access secrets in the key vault.
    2. B.An Event Grid subscription for the `SecretNearExpiry` event, routed to the function app's endpoint.
    3. C.A storage account used by the function app for trigger management and runtime bookkeeping.
    4. D.An Azure Front Door profile placed in front of the key vault to terminate TLS for rotation traffic.
    5. E.A dedicated App Service Environment, since standard multi-tenant App Service cannot host rotation functions.
    6. F.An Azure Bastion host used exclusively to relay the new password from the function to SQL Server.
    Show answer & explanation

    Correct answers: A, B, C — A function app with a system-assigned managed identity granted a role to access secrets in the key vault.; An Event Grid subscription for the `SecretNearExpiry` event, routed to the function app's endpoint.; A storage account used by the function app for trigger management and runtime bookkeeping.

    • A. The pattern requires a function app whose managed identity has been granted a role, such as Key Vault Secrets Officer or a scoped RBAC role, so it can read and write the secret being rotated.
    • B. An Event Grid event subscription for `SecretNearExpiry` is what routes Key Vault's near-expiry notification to the function app's HTTP or Event Grid trigger, starting the rotation.
    • C. The function app requires a storage account for its own trigger management and runtime bookkeeping, which is one of the components the deployment template provisions alongside the function.
    • D. Front Door is a global HTTP load-balancing and CDN service; it has no role in the Key Vault rotation pattern, which does not route rotation traffic through a TLS-terminating edge service.
    • E. A dedicated App Service Environment is not required; the documented tutorial deploys the rotation function on a standard App Service plan without needing an isolated environment.
    • F. Azure Bastion provides secure RDP/SSH access to virtual machines; it plays no part in relaying a rotated password, which the function delivers directly to the database over its normal connection.

    Subdomain 4.1: Implement secure Azure solutions

    32.Meridian Health's Bicep template provisions a key vault for the triage API: ```bicep resource kv 'Microsoft.KeyVault/vaults@2023-07-01' = { name: 'meridian-triage-kv' location: location properties: { sku: { family: 'A' name: 'standard' } tenantId: subscription().tenantId accessPolicies: [] enableRbacAuthorization: false enableSoftDelete: true } } ``` The team wants the container app's managed identity to be granted access purely through Azure role assignments, with no access policy entries. Which property must change?

    1. A.`enableRbacAuthorization: false` must become `enableRbacAuthorization: true` so data-plane access is granted only through RBAC role assignments.
    2. B.`accessPolicies: []` must be changed to include a wildcard policy granting every principal in the tenant full access to the vault.
    3. C.`enableSoftDelete: true` must become `enableSoftDelete: false`, since soft-delete is what forces the vault into access-policy mode.
    4. D.`sku.name: 'standard'` must become `sku.name: 'premium'`, since only Premium tier vaults can support RBAC-based authorization at all.
    Show answer & explanation

    Correct answer: A — `enableRbacAuthorization: false` must become `enableRbacAuthorization: true` so data-plane access is granted only through RBAC role assignments.

    • A. With `enableRbacAuthorization` set to `false`, the vault uses the classic access policy model for data access; setting it to `true` switches the vault to Azure RBAC as the sole authorization model, matching the stated goal of no access policy entries.
    • B. Adding a wildcard access policy would grant broad, unmanaged permissions through the very access-policy model the team wants to avoid, and it is the opposite of restricting access to RBAC role assignments.
    • C. Soft-delete controls recoverability of deleted vault objects and has no relationship to which authorization model, RBAC or access policies, the vault uses for granting data access.
    • D. RBAC-based authorization is available on both Standard and Premium tiers; the tier controls cryptographic protection level, not which authorization model the vault can use.

    Subdomain 4.2: Monitor and troubleshoot Azure solutions

    33.A developer wrote the following Python startup code, but custom spans never appear correctly nested with auto-instrumented spans in Application Insights: ``` from azure.monitor.opentelemetry import configure_azure_monitor from opentelemetry import trace tracer = trace.get_tracer(__name__) def handle_order(order_id): with tracer.start_span("handle_order"): process(order_id) ``` Which line must change to fix it?

    1. A.Line 6 must call tracer.start_as_current_span("handle_order") instead of start_span, since start_span does not attach the span to the active context that auto-instrumentation reads from.
    2. B.Line 1 must import trace from opentelemetry.sdk instead of azure.monitor.opentelemetry, since the Azure Monitor distribution overrides manual tracer calls once it installs its own global provider instance.
    3. C.Line 4 must call trace.get_tracer(__name__) before configure_azure_monitor() runs, since the SDK permanently binds context propagation to whichever tracer provider instance existed at the first call.
    4. D.Line 6 must pass order_id as an argument to start_span so that the span receives its correlated attributes at creation time, since spans instantiated without their identifying context data cannot attach to the parent span.
    Show answer & explanation

    Correct answer: A — Line 6 must call tracer.start_as_current_span("handle_order") instead of start_span, since start_span does not attach the span to the active context that auto-instrumentation reads from.

    • A. start_as_current_span both creates a span and makes it the active span in context, which is required for it to nest correctly with auto-instrumented spans; start_span alone does not set the active context.
    • B. The azure.monitor.opentelemetry package is designed to coexist with manual OpenTelemetry API usage, so this import is not the cause of the nesting problem.
    • C. The order in which get_tracer() is called relative to configure_azure_monitor() does not determine whether a specific span attaches to the active context; the choice of start_span versus start_as_current_span does.
    • D. Passing order_id as an argument would not be valid usage of start_span and does not address why the span fails to nest within the active trace context.

    Subdomain 4.2: Monitor and troubleshoot Azure solutions

    34.An analyst repeats the same ago(7d) time window and a threshold value across five queries in a shared workbook. What KQL construct reduces this repetition while keeping the queries consistent?

    1. A.Define a let statement at the top of the query to name the time window and threshold, then reference those names in later operators.
    2. B.Define a .create function management command each time, since let statements cannot be reused across pipe-separated operators.
    3. C.Copy the literal ago(7d) value into every where clause, since KQL does not support variables inside tabular expression statements.
    4. D.Store the threshold in a Key Vault secret and reference it directly inside the KQL query string using an app registration secret at runtime.
    Show answer & explanation

    Correct answer: A — Define a let statement at the top of the query to name the time window and threshold, then reference those names in later operators.

    • A. A let statement names a value once at the top of a query so it can be reused consistently across multiple operators, which is the standard KQL mechanism for avoiding repeated literals.
    • B. let statements do work across the pipe-separated operators of a single query, so a management command is unnecessary overhead for this repeated-value problem.
    • C. KQL does support named values through let statements, so copying the literal into every clause is more error-prone than necessary and contradicts documented KQL capability.
    • D. Key Vault secrets are not referenced directly inside KQL query text, and a let statement already solves the stated repetition problem without introducing a secret store.

    Subdomain 4.2: Monitor and troubleshoot Azure solutions

    35.Meridian's on-call engineer wants a near-real-time view of request rates and failures while actively investigating an ongoing incident. Which capability supports this need?

    1. A.Live Metrics, which the Azure Monitor OpenTelemetry Distro supports for monitoring telemetry from a live, in-production application.
    2. B.The exceptions table queried on a five-minute refresh cycle, since Application Insights has no dedicated live monitoring view.
    3. C.Azure Resource Graph queries scheduled every 60 seconds against the Container Apps revision and replica status for the affected service.
    4. D.A scheduled Logic App that polls the requests table and posts a summary message to a chat channel once per minute.
    Show answer & explanation

    Correct answer: A — Live Metrics, which the Azure Monitor OpenTelemetry Distro supports for monitoring telemetry from a live, in-production application.

    • A. Live Metrics is a dedicated capability of the Azure Monitor OpenTelemetry Distro built specifically for observing live, in-production telemetry with near-real-time latency during incidents.
    • B. A five-minute polling cycle against the exceptions table is not near-real-time and ignores the purpose-built Live Metrics feature that already covers this scenario.
    • C. Resource Graph reports on infrastructure state such as revision status, not live application request and failure rates, so it does not meet the stated need.
    • D. A once-per-minute polling job introduces delay and extra infrastructure compared to the built-in Live Metrics stream designed for exactly this incident-response scenario.

    Want the full experience?

    These are just samples. Practice the full Microsoft Certified: Azure AI Cloud Developer Associate (AI-200) question bank in quiz mode — free, no signup, with domain practice and exam simulation.