Microsoft Agentic AI Business Solutions Architect (AB-100)

Use this AB-100 practice test to prepare for the Microsoft Agentic AI Business Solutions Architect exam. Original questions are grounded in verified Microsoft Learn content, with explanations and source links for focused revision.

Q001 - Question

A company is scaling AI across several business units. Each team uses different frameworks and tools, so deployments are inconsistent and hard to compare. Which enterprise scaling practice should the architect apply first to address this problem?

Domain: Plan AI-powered business solutions Type: Single choice

C is correct.

Explanation: The evidence states that standardization involves using common frameworks and tools. This directly addresses the issue of teams using different frameworks and producing inconsistent deployments.

A is incorrect: Continuous learning enables models to evolve with new data. It does not standardize frameworks or tools across teams.

B is incorrect: User training enables a culture of continuous user learning. It does not resolve inconsistent tooling across teams.

D is incorrect: Automation streamlines deployment and monitoring. If each team automates using different tools, the deployments remain inconsistent.

Learn more in Microsoft Learn

Q002 - Question

A company is designing a helpdesk triage agent. The agent runs on a schedule with no signed-in user, reads ticket data in one Azure resource, and updates knowledge articles. The agent exists in dev, pre-prod, and prod environments. Security requires least-privilege access and no embedded secrets. What should you configure for agent-to-Azure authentication and authorization?

Domain: Deploy AI-powered business solutions Type: Single choice

B is correct.

Explanation: When an agent acts as itself, scope a service role with only the actions the agent needs. Use a unique managed identity for each agent in each environment. Managed identities remove secrets and simplify rotation, and narrowly scoped role assignments enforce least privilege.

A is incorrect: A shared identity removes the separation between dev, pre-prod, and prod. Contributor at the subscription scope grants far more access than the agent needs.

C is incorrect: A client secret in the configuration is an embedded secret. The design checklist requires managed identities and no embedded secrets.

D is incorrect: The agent runs with no user and acts as itself. Maker permissions are not scoped to the agent's tasks, and the Maker role is meant to stay separate from production publishing.

Learn more in Microsoft Learn

Q003 - Question

A support team uses Agent Builder in Microsoft 365 Copilot to create a case triage agent. The team has defined the agent's purpose, added instructions and guardrails, connected data sources, and configured actions and permissions. Leadership wants the agent available to support staff soon. What should the team do next?

Domain: Design AI-powered business solutions Type: Single choice

A is correct.

Explanation: In the Agent Builder workflow, you test the agent with sample prompts after you configure actions and permissions. You then publish the agent to targeted users or groups. Use the testing and validation workspace to verify behavior before release.

B is incorrect: Publishing to everyone skips the test step. Agent Builder includes publishing controls so you can target specific users or groups.

C is incorrect: Agents should solve a single high-value need. Adding unrelated capabilities makes intent less clear.

D is incorrect: Agent behavior should define conditions that escalate to human review. Removing them weakens the guardrails for case triage.

Learn more in Microsoft Learn

Q004 - Question

Monitoring shows that the output quality of a custom AI model in production has moved away from its expected performance. The model is still used for business tasks. What should you do?

Domain: Deploy AI-powered business solutions Type: Single choice

C is correct.

Explanation: When you detect model drift, trigger a retraining cycle with updated data. Use versioned data pipelines for reproducibility. Promote the new version only after it passes the evaluation, safety, performance, cost, and governance checks in the promotion gates.

A is incorrect: Production holds stable, approved model versions with monitoring and rollback controls. Experimentation and training belong in Dev.

B is incorrect: Retirement applies when a model no longer meets accuracy, safety, cost, or business expectations. Even then, document a transition plan to the next model version.

D is incorrect: Model registries use version locking and rollback paths. If you overwrite a version, you remove the rollback path and the traceable version history.

Learn more in Microsoft Learn

Q005 - Question

A customer service agent has had no changes to its logic or workflows for three months. Over the same period, accuracy declines on recurring tasks, response patterns shift, and users report more off-topic responses. Latency and dependency errors stay stable. Which monitoring area should you prioritize to investigate this behavior?

Domain: Deploy AI-powered business solutions Type: Single choice

B is correct.

Explanation: Model-driven behavior can shift over time even when agent logic is stable. Shifts in response patterns, declining accuracy in recurring tasks, and increased hallucination or off-topic responses are model drift indicators. Prioritize model drift monitoring.

A is incorrect: Token consumption measures the cost-to-performance ratio and the efficiency of prompting patterns. It doesn't directly measure declining accuracy or off-topic responses.

C is incorrect: Reliability indicators include sudden latency increases and errors related to external dependencies. The scenario states that latency and dependency errors stay stable.

D is incorrect: Throughput measures the volume of completed runs over a period. It doesn't show whether response quality changes.

Learn more in Microsoft Learn

Q006 - Question

An HR agent sometimes returns answers from a retired leave policy. Reviewers also find several copies of the same policy in different layouts. You need to improve the grounding data before you add it to the agent. Which two actions should you take? Each correct answer presents part of the solution.

Domain: Plan AI-powered business solutions Type: Multiple choice

A and C are correct.

Explanation: Evaluate content quality before upload and remove outdated or conflicting information to improve accuracy and timeliness. Remove duplicates and use consistent formatting to improve cleanliness and retrieval precision.

B is incorrect: Broader access does not fix stale or duplicate content. Review permissions regularly so agents ground from valid data sources only.

D is incorrect: Store authoritative content in SharePoint or OneDrive so it becomes part of the semantic index. Local copies do not meet this requirement.

Learn more in Microsoft Learn

Q007 - Question

A product owner asks you to approve a Microsoft 365 agent pilot. The agent will retrieve project files and write status updates to a tracking system through a connector. Before you approve the pilot, which two items should you confirm? Each correct answer presents part of the solution.

Domain: Design AI-powered business solutions Type: Multi-select

B and D are correct.

Explanation: The readiness checklist for solution architects requires confirming identity and access (runs-as model documented, least-privilege confirmed) and actions and tools (required tools/connectors identified, failure paths and human approval points defined).

A is incorrect: The readiness checklist does not specify using the largest available model; it focuses on business value, identity, data scope, actions, security, change control, measurement, and support.

C is incorrect: The evidence states that before considering any custom agents, out-of-the-box pilots should be assessed to determine whether they will adequately meet the requirements.

Learn more in Microsoft Learn

Q008 - Question

An organization has deployed several agents. Leadership now asks the architect for adoption guides and best practices to plan enterprise AI adoption. Which resource should the architect use?

Domain: Plan AI-powered business solutions Type: Single choice

C is correct.

Explanation: The evidence states that the Scenario Library provides access to adoption guides and best practices for enterprise AI.

A is incorrect: Prebuilt agents in Copilot Studio are used to automate common business processes. They do not provide adoption guides for leadership.

B is incorrect: Copilot Studio templates are used to create tailored AI solutions. They support agent creation, not enterprise adoption planning.

D is incorrect: Azure AI Services provide Vision, Speech, Language, and Decision capabilities. They do not provide adoption guides.

Learn more in Microsoft Learn

Q009 - Question

Your team uses Copilot to generate test cases for an agent that summarizes financial reports. The generated test cases use inconsistent formats, and many don't include failure conditions such as an empty report or a corrupted PDF. You need to improve the consistency and coverage of the generated test cases. What should you do?

Domain: Deploy AI-powered business solutions Type: Single choice

B is correct.

Explanation: Copilot performs best when it follows consistent patterns. Provide a test case template in the prompt for predictable output, and define quality expectations, such as at least two negative tests per scenario, to improve coverage of failure conditions.

A is incorrect: You must still review generated test cases for completeness, accuracy, clarity, and maintainability. Boundary and failure conditions must be verified, not assumed.

C is incorrect: Design the strategy around Copilot instead of using Copilot reactively. Define testing objectives, prompts, and quality thresholds before generating tests.

D is incorrect: Ad hoc prompts reduce consistency across releases. Maintain a reusable prompt library and version control prompts and test templates.

Learn more in Microsoft Learn

Q010 - Question

A financial services company is designing a Copilot Studio agent for a regulated account process. Users send consistent, structured commands such as "Reset password" and "Check balance." The business requires strict intent matching and deterministic responses with limited generative behavior. Which language understanding approach should you recommend?

Domain: Design AI-powered business solutions Type: Single choice

B is correct.

Explanation: Use standard NLU for predictable tasks that require high precision and low variability. It fits strict intent matching for regulated processes, consistent structured commands, and deterministic responses with limited generative behavior.

A is incorrect: Generative orchestration is best for unstructured or unpredictable messages and open-ended tasks. It is also more compute intensive, which adds cost without benefit for fixed commands.

C is incorrect: Azure CLU is the best choice when phrasing varies moderately within defined topic boundaries. For structured commands with regulatory accuracy needs, standard NLU is the best choice.

D is incorrect: Generative answers act as a fallback when no topic matches. They answer from knowledge sources and do not provide strict, deterministic intent routing.

Learn more in Microsoft Learn

Q011 - Question

A solution architect is preparing a total cost of ownership (TCO) estimate for a Copilot Studio agent. The draft includes licensing and API usage costs. The finance team asks the architect to add the recurring costs of running the agent after deployment. Which two costs should the architect add as operational costs? Each correct answer presents part of the solution.

Domain: Plan AI-powered business solutions Type: Multiple choice

B and D are correct.

Explanation: Operational costs recur after deployment. They include monitoring and evaluation, model retraining, prompt library maintenance, support and troubleshooting, and user training and adoption programs. Add these costs so the TCO estimate covers the full AI lifecycle.

A is incorrect: Data preparation is a development cost that occurs during the build. It is not a recurring operational cost.

C is incorrect: Retiring outdated models is a decommissioning cost. It belongs at the end of the lifecycle, not in ongoing operations.

Learn more in Microsoft Learn

Q012 - Question

A finance manager reports that an agent answers budget questions for some employees but not for others. The budget documents are stored on a SharePoint site that only the finance team can access. The manager asks why other employees do not get grounded answers. What should you tell the manager?

Domain: Plan AI-powered business solutions Type: Single choice

B is correct.

Explanation: Availability determines what an agent can ground on. The Copilot Retrieval API honors user permissions, so employees outside the finance team do not get content from the restricted site. To change the result, review the access controls on the site.

A is incorrect: The semantic index in Microsoft 365 continuously updates as content changes. Stale data does not explain why results differ by user.

C is incorrect: Relevance issues affect all users in the same way. The difference by user points to access permissions.

D is incorrect: Content stored in SharePoint or OneDrive and indexed in Microsoft Graph can be used for grounding. Moving the documents to Azure SQL is not a stated requirement.

Learn more in Microsoft Learn

Q013 - Question

A finance department wants in-app help in Dynamics 365 Finance to guide users through regulatory period-close procedures. Auditors require that help responses use only controlled, validated content. Which recommendation should you make?

Domain: Design AI-powered business solutions Type: Single choice

B is correct.

Explanation: The evidence states to restrict general knowledge when precision is critical for regulatory or financial workflows and only controlled, validated knowledge should influence responses. The recommended process is to prepare validated PDF/Word files, ingest them, test the knowledge behavior, and then publish.

A is incorrect: General knowledge should be restricted, not enabled, when precision is critical for regulatory workflows and only validated knowledge should be used.

C is incorrect: Dataverse virtual entities published from Finance & Operations are explicitly listed as not recommended or unsupported knowledge sources.

D is incorrect: The recommended process requires testing knowledge behavior (Step 3) after ingestion and before publishing to production (Step 4).

Learn more in Microsoft Learn

Q014 - Question

A custom AI model that classifies supplier invoices met all accuracy thresholds before deployment. The organization expects invoice formats and supplier patterns to change over the next year. You need to define a quantitative validation criterion that detects changes in output quality caused by these evolving data patterns. Which criterion should you include?

Domain: Deploy AI-powered business solutions Type: Single choice

A is correct.

Explanation: Drift indicators track changes in output quality due to evolving data or shifting patterns. Include them so you can evaluate the model consistently after deployment, not only before it.

B is incorrect: Throughput measures how many requests the model can process under peak loads. It doesn't detect quality changes caused by new data patterns.

C is incorrect: Latency and response time measure speed for mission-critical workflows. A model can stay fast while its output quality declines.

D is incorrect: Token efficiency measures model usage cost relative to output quality. It doesn't identify quality changes caused by shifting data.

Learn more in Microsoft Learn

Q015 - Question

You're designing a Microsoft Foundry agent that calls tools to prepare and submit financial approvals in an enterprise system. Which solution rule should you define?

Domain: Plan AI-powered business solutions Type: Single choice

A is correct.

Explanation: The evidence supports A because high-risk tasks such as financial approvals require human review. Solution rules for Foundry tools also mandate implementing least-privilege permissions for each tool and enabling mandatory auditing for tool invocation.

B is incorrect: Relying on platform-enforced governance and built-in safety filters applies to Copilot Studio. Microsoft Foundry requires explicit governance, and architects must apply evaluation pipelines to audit safety, correctness, and drift.

C is incorrect: Data constraints require restricting cross-domain data access (such as HR, Finance, and Legal) and providing agents only the data they require.

D is incorrect: Data movement and storage constraints dictate that you must prevent persistent storage of messages unless compliance requires it, and you must define an explicit memory policy.

Learn more in Microsoft Learn

Q016 - Question

A company is building a RAG solution on Azure AI Search to ground an agent in product documentation. The architect must maximize retrieval relevance and control index size and cost. Which two design choices should the architect make? Each correct answer presents part of the solution.

Domain: Design AI-powered business solutions Type: Multiple choice

B and D are correct.

Explanation: Extra field capabilities increase index size and cost, so mark fields only with the capabilities you use. Hybrid search, which combines vector, keyword, and semantic reranking, generally yields the most reliable relevance across phrasing, synonyms, and exact terms.

A is incorrect: Do not query live systems for every turn. Build an index that is optimized for your questions and updated on an SLO-driven freshness schedule.

C is incorrect: Enabling all capabilities increases storage and cost. Prefer a minimum viable schema.

Learn more in Microsoft Learn

Q017 - Question

An accounts payable team receives a high volume of supplier invoices. They want a Power Automate flow to extract invoice data automatically so that they can process it without manual entry. They want to prototype quickly without training a model on their own data. Which Power Platform AI feature should you propose?

Domain: Design AI-powered business solutions Type: Single choice

A is correct.

Explanation: AI Builder prebuilt models are useful for rapid prototyping or high-volume automation, and specifically include receipt and invoice extraction.

B is incorrect: Copilot Studio is used to build custom conversational agents with multi-turn reasoning, not for automated document extraction in a flow.

C is incorrect: Copilot in Power Pages is used to build site pages, forms, and data models with natural language, not for extracting data from invoices.

D is incorrect: Copilot in Power Apps is used to generate app screens, tables, and logic from natural language, not for document extraction.

Learn more in Microsoft Learn

Q018 - Question

A company is building an agent in Copilot Studio to answer engineering questions. The content set is large and continues to grow. Users need high-precision results, and the content is already prepared for vector search. Which knowledge source should you recommend?

Domain: Plan AI-powered business solutions Type: Single choice

C is correct.

Explanation: The evidence supports C because Azure AI Search integrates as a powerful index-based information source when vector search or semantic ranking is required. It is the preferred solution when content volume is large and requires scalable indexing, enterprise-grade search relevance, and vector search for embedding-aligned retrieval.

A is incorrect: Public website knowledge is ideal for FAQs, external product information, or publicly available policy materials, not for high-precision retrieval over a large internal vector-indexed content set.

B is incorrect: Classic orchestration selects topics based on matching a user query with trigger phrases and uses knowledge only as a fallback. It does not provide semantic ranking or vector search.

D is incorrect: Dataverse knowledge is used for structured tables and relational data, whereas the requirement is high-precision retrieval over a large indexed content set prepared for vector search.

Learn more in Microsoft Learn

Q019 - Question

A regulated organization uses grounding data that contains sensitive customer records. Auditors require evidence of sensitivity label changes, data ingestion events, and data movement across regions. The compliance team also wants to avoid unnecessary exposure of sensitive information in the audit system. How should you design the audit trail for data changes?

Domain: Deploy AI-powered business solutions Type: Single choice

A is correct.

Explanation: Audit logs for data changes must capture metadata, not content, to avoid unnecessary exposure of sensitive information. Use immutable logs, timestamped change records, and role-based attribution linked to the identity provider to show who changed what and when.

B is incorrect: Copying full content into logs exposes sensitive customer records in another location. This conflicts with the requirement to log metadata only.

C is incorrect: Audit logs must be immutable. Editable entries reduce the value of the logs as evidence for audits and investigations.

D is incorrect: You must audit data changes such as ingestion events, sensitivity label changes, and data movement across regions. Model events alone do not meet the auditor requirement.

Learn more in Microsoft Learn

Q020 - Question

Procurement users want to ask the Dynamics 365 Finance and Operations Copilot agent three things in one chat: whether a vendor is approved, when the vendor's latest compliance certificate expires, and to update the vendor's payment terms. Compliance certificates are stored in a SharePoint library. Which design should you recommend?

Domain: Design AI-powered business solutions Type: Single choice

D is correct.

Explanation: The evidence demonstrates mapping business questions to knowledge sources: F&O data for vendor status, SharePoint for compliance certificates, and plugin actions for updates. It also specifies that plugins must respect F&O security roles.

A is incorrect: F&O data alone may not answer all questions, as the compliance certificates are stored externally in a SharePoint library.

B is incorrect: SharePoint is an external knowledge base for retrieving documents, not a mechanism for executing actions like updating payment terms.

C is incorrect: The evidence explicitly states under governance and security that plugins must respect F&O security roles.

Learn more in Microsoft Learn

Q021 - Question

You are designing promotion gates for Microsoft Foundry agents. The Dev to Test gate already includes functional validation, initial guardrail checks, and data source mapping verification. Which two checks should you add to the Test to Prod gate? Each correct answer presents part of the solution.

Domain: Deploy AI-powered business solutions Type: Multi-select

A and D are correct.

Explanation: The Test to Prod gate confirms production readiness. Include human validation of agent reasoning and a performance and cost assessment. Also include regression test completion, data access and policy compliance approval, and documentation of version, dependencies, and risk analysis.

B is incorrect: Initial safety and guardrail checks belong to the Dev to Test gate. The scenario already covers them before the agent reaches Test.

C is incorrect: Verification of data source mappings is part of the Dev to Test gate. It does not replace the production-readiness checks needed before Prod.

Learn more in Microsoft Learn

Q022 - Question

A retailer has historical sales data and wants a custom model that it can build, train, and deploy to forecast demand. Which Microsoft AI technology should the architect recommend?

Domain: Plan AI-powered business solutions Type: Single choice

B is correct.

Explanation: Azure Machine Learning is the platform for building, training, and deploying machine learning models. It is the correct choice for creating a custom demand forecasting model.

A is incorrect: Cognitive Services provides prebuilt APIs for Vision, Speech, Language, and Decision. It is not the platform for building and training custom forecasting models.

C is incorrect: Azure OpenAI Service provides access to advanced generative AI models for natural language and creative tasks, not for custom demand forecasting based on sales data.

D is incorrect: Copilot solutions embed AI in Microsoft 365 for productivity tasks. They do not provide a platform to build, train, and deploy custom machine learning models.

Learn more in Microsoft Learn

Q023 - Question

A business unit wants AI support for policy Q&A and document summarization. Moderate accuracy is acceptable, and time-to-value is the priority. The organization has little labeled domain data and no data scientists or MLOps engineers. What should you recommend?

Domain: Plan AI-powered business solutions Type: Single choice

B is correct.

Explanation: The evidence supports B because prebuilt or catalog models fit well when the use case is general-purpose (such as policy Q&A and document summarization), moderate accuracy is acceptable, and time-to-value is a priority. Furthermore, if requirements like large volumes of labeled data and skilled data scientists are not met, extending Microsoft 365 Copilot is often the better starting point.

A is incorrect: Custom models are justified only when existing models cannot meet accuracy, domain, or compliance needs. They also require large labeled datasets and skilled personnel, which this organization lacks.

C is incorrect: Delaying deployment to build a custom model conflicts with the time-to-value priority, and the use case does not demonstrate an accuracy gap that existing models cannot close.

D is incorrect: Policy Q&A is explicitly listed as an example where prebuilt or catalog models fit well. The scenario does not require deterministic or near-deterministic output.

Learn more in Microsoft Learn

Q024 - Question

You are building an ROI analysis for a Copilot Studio agent that handles invoice exception processing. You plan to use the agent Savings capability to estimate value. An admin has disabled money-based savings for the environment. Finance still requires a currency-based annual benefit. What should you do?

Domain: Plan AI-powered business solutions Type: Single choice

C is correct.

Explanation: When admins disable money-based savings, you can still track time saved. Convert that time to currency in your ROI workbook by using the minutes saved per run, the number of successful runs, and a fully loaded labor rate.

A is incorrect: A satisfaction survey does not measure time or cost savings. You lose the measured time data that the Savings capability still provides.

B is incorrect: You don't need to delay the analysis. Time-based savings remain available and can be converted to currency.

D is incorrect: Session count is a usage metric, not a financial benefit. It does not include time saved or a labor rate.

Learn more in Microsoft Learn

Q025 - Question

Your team drafted two versions of a Copilot prompt that summarizes quarterly performance for executives. Before you approve one version for enterprise-scale reuse, you need to compare the versions and confirm that output quality holds for new analysts and senior architects across different business contexts. Which two validation methods should you use? Each correct answer presents part of the solution.

Domain: Deploy AI-powered business solutions Type: Multiple choice

B and D are correct.

Explanation: Use A/B prompt testing to compare two variations of the same prompt on accuracy, clarity, relevance, and required follow-up prompts. Use scenario-based testing to validate the selected prompt across user types, business contexts, and task complexities.

A is incorrect: Include examples only when they add clarity, and keep them concise and targeted. Long examples for every user type add clutter and don't compare the two versions.

C is incorrect: Avoid multi-task prompts because they can confuse the model. Combining tasks makes the prompt harder to validate.

Learn more in Microsoft Learn

Q026 - Question

A procurement team wants an agent that starts a multi-step process when a purchase request is submitted. The process must send the request for approval, notify stakeholders, and generate a confirmation document. Which tools should you recommend for this process automation requirement?

Domain: Plan AI-powered business solutions Type: Single choice

D is correct.

Explanation: The requirement is to trigger workflows and multi-step tasks such as approvals, notifications, and content generation. Copilot Studio and Power Automate are the tools for process automation.

A is incorrect: Word and OneNote support documentation tasks such as first-draft reports and content rewrites. They do not trigger an approval workflow.

B is incorrect: Copilot Search with Graph grounding answers questions by using enterprise data. It retrieves knowledge but does not run a multi-step approval process.

C is incorrect: Summarizing Teams threads is a communication task. It does not start approvals or notifications.

Learn more in Microsoft Learn

Q027 - Question

A utility company designs a Copilot Studio agent in voice mode to support field technicians. Technicians call the agent hands-free to request parts orders and check job status. Some requests trigger actions in downstream systems. Which behavior design should you recommend?

Domain: Design AI-powered business solutions Type: Single choice

B is correct.

Explanation: Voice agents should use short, clear phrasing, provide confirmation steps, and include confidence checks before executing actions. Voice relies on real-time interaction, so design for responsiveness, fallback handling, and user-friendly error messages.

A is incorrect: Avoid long multi-sentence responses in voice mode. The agent should provide concise spoken output.

C is incorrect: The voice interaction flow includes a step where the agent confirms or clarifies intent before it executes the action. Skipping this step increases the risk of incorrect actions.

D is incorrect: Deep reasoning is in preview and targets complex multi-step tasks. Standard reasoning provides fast responses and lower compute usage, which fits routine, high-volume requests such as job status checks.

Learn more in Microsoft Learn

Q028 - Question

A company uses separate Dev, Test, and Prod environments for Copilot Studio agents. Users report a critical error in an agent topic in Prod. The business wants the fix released as soon as possible. Which approach should you use?

Domain: Deploy AI-powered business solutions Type: Single choice

D is correct.

Explanation: Make changes in the unmanaged Dev environment. Validate them in Test, and then deploy to Prod by using managed solutions. An emergency patch process handles critical fixes without bypassing environment separation or version control.

A is incorrect: Do not edit directly in production. A direct edit creates configuration drift and has no tested, versioned source.

B is incorrect: Test and Prod should contain managed solutions only. An unmanaged import into Prod breaks solution layering and change isolation.

C is incorrect: Build and author changes in Dev. Test validates and approves changes. If you edit in Test, the change bypasses the authoring stage and source control.

Learn more in Microsoft Learn

Q029 - Question

You review the backlog for an HR agent. Conversation transcripts show that the agent correctly identifies what users ask about leave policy. However, the agent answers with content from a policy document that was replaced last quarter. No connector or API errors appear in the logs. Which backlog category should you assign to this item?

Domain: Deploy AI-powered business solutions Type: Single choice

A is correct.

Explanation: Assign the item to Knowledge Issues. This category covers outdated content and insufficient grounding sources. The agent interprets the question correctly but uses a replaced document, so the knowledge source is the problem.

B is incorrect: Accuracy and Reasoning covers misinterpreted queries, missing context, and low-confidence responses. The transcripts show that the agent understood the user intent.

C is incorrect: Integration Issues covers API failures, connector limits, and data access problems. The logs show no connector or API errors.

D is incorrect: Governance and Compliance covers guardrail triggers, DLP conflicts, and restricted actions. Nothing in the scenario shows that a policy blocked or restricted the agent.

Learn more in Microsoft Learn

Q030 - Question

A customer service agent accepts documents that customers upload. A review finds that some files contain hidden instructions embedded in HTML that attempt to override the agent's system instructions. Which two input controls should you configure? Each correct answer presents part of the solution.

Domain: Deploy AI-powered business solutions Type: Multiple choice

A and C are correct.

Explanation: Hidden instructions in text, HTML, or files are a prompt manipulation technique. To strengthen input filtering, strip unsafe HTML or embedded prompts, and limit the file types that the AI may accept. These controls reduce the content that can carry hidden instructions.

B is incorrect: You need to capture and analyze user prompts, tool calls, and actions to detect prompt attacks. Removing this telemetry reduces your ability to investigate suspicious behavior.

D is incorrect: Excessive permissions are a data exposure vulnerability. Restrict data access to only what the AI needs instead of expanding it.

Learn more in Microsoft Learn

Q031 - Question

An AI solution supports an order process where sales orders created in Dynamics 365 Sales sync to Dynamics 365 Finance, and the AI then validates credit risk based on Finance data. Each app passed its own tests. During user acceptance testing, credit risk recommendations are sometimes based on outdated order data. What should you add to the end-to-end test design?

Domain: Deploy AI-powered business solutions Type: Single choice

D is correct.

Explanation: AI output quality depends on consistent, trusted, and well-timed input data across apps. Add cross-app readiness checks for entity mappings, data refresh timing and latency, and grounding data sources to find where the order data becomes outdated.

A is incorrect: Testing each app in isolation already passed and missed the issue. End-to-end testing must validate the entire business process, not individual modules alone.

B is incorrect: Include both structured and unstructured data scenarios in end-to-end tests. Removing data types reduces coverage and doesn't test data timing.

C is incorrect: Test with both normal load and stress conditions. Limiting load doesn't validate how data moves between Sales and Finance.

Learn more in Microsoft Learn

Q032 - Question

An organization started with a centralized AI Center of Excellence (AI CoE) that approves every AI project. Product teams now have mature skills and want to own AI delivery. Project approvals are becoming a bottleneck. How should you evolve the AI CoE operating model?

Domain: Plan AI-powered business solutions Type: Single choice

D is correct.

Explanation: The evidence supports D because in a mature stage, the AI CoE evolves into an advisory model where it acts as a consultant rather than a gatekeeper. Product teams own AI delivery, and governance is embedded into platforms and workflows.

A is incorrect: Keeping the centralized model maintains the AI CoE as a gatekeeper, which leads to overcentralization and bottlenecks.

B is incorrect: Removing AI CoE governance leads to undergovernance and shadow AI. Governance must remain, but it should be embedded into platforms and workflows.

C is incorrect: A standalone AI transformation function is recommended only when no supporting team exists, and it does not address the approval bottleneck issue.

Learn more in Microsoft Learn

Q033 - Question

A services company has defined its business outcome: reduce response time for common customer service requests. It needs an AI agent deployed quickly with minimal development. Which resource should the architect recommend?

Domain: Plan AI-powered business solutions Type: Single choice

D is correct.

Explanation: The evidence states that prebuilt AI agents are available through Microsoft Copilot Studio and are designed for common business scenarios such as customer service. They should be used for quick deployment.

A is incorrect: Building and training a custom model in Azure Machine Learning requires significant development time. The requirement is for quick deployment with minimal development.

B is incorrect: Integrating Azure AI Services APIs into a new application requires more development effort than using a prebuilt agent.

C is incorrect: The Scenario Library provides best practices and adoption guides. It is not an AI agent that automates customer service workflows.

Learn more in Microsoft Learn

Q034 - Question

You are designing a Copilot Studio agent for an operations team. When a new row is added to a Dataverse table, the agent must send a summary to the team without waiting for a user to send a message. Which mechanism should you use?

Domain: Design AI-powered business solutions Type: Single choice

D is correct.

Explanation: Event triggers let an agent act without waiting for a user prompt. A Dataverse row added is an example trigger event, and the trigger can start actions such as sending a summary. Triggers must be explicitly authorized and may impact billing consumption.

A is incorrect: Use generative answers when a user question is not covered by topics and the agent needs to answer from knowledge sources. It still responds to a user question.

B is incorrect: System topics handle common conversation situations, such as greeting, fallback, escalation, and errors. They are not designed to start work from a Dataverse event.

C is incorrect: Condition nodes branch a dialog based on variables and values. They do not start the agent when an event occurs.

Learn more in Microsoft Learn

Q035 - Question

A company is designing an AI agent for its Dynamics 365 Contact Center live chat channel. The compliance team requires least-privileged access to customer data. The agent must still route and respond based on the case, the channel, and the issue type. How should you design the agent context?

Domain: Design AI-powered business solutions Type: Single choice

A is correct.

Explanation: When you configure agent context, define the entity types and map the fields that the agent needs. Include only the needed attributes. This approach improves accuracy, reduces noise, and supports privacy, compliance, and least-privileged access.

B is incorrect: Exposing all attributes conflicts with the requirement to expose only required context attributes for privacy and least-privileged access.

C is incorrect: Enable Copilot per environment and per user role to ensure correct permissions. Do not enable it for every user in the tenant.

D is incorrect: The transcript is only one part of agent context. The agent also needs structured data, such as case history, channel, and routing queues, to respond and route correctly.

Learn more in Microsoft Learn

Q036 - Question

A sales operations director wants to introduce AI agents across several teams. Leadership asks you how to plan the first phase so that the agents add measurable value. What should you do first?

Domain: Plan AI-powered business solutions Type: Single choice

C is correct.

Explanation: Start with the business outcome you want to improve. Then use agent automation to reduce repetitive work that supports that outcome.

A is incorrect: A broad rollout without a defined outcome gives you no baseline to measure value against. You should also monitor performance and refine prompts, workflows, and data inputs over time.

B is incorrect: Use agent automation to reduce repetitive work, not to replace critical thinking.

D is incorrect: Train teams so they can use Copilot effectively. Postponing training does not support reliable adoption.

Learn more in Microsoft Learn

Q037 - Question

A manufacturer plans a role-specific AI agent in Microsoft Teams. The agent will route workflows and send notifications based on Dynamics 365 Supply Chain Management data, outside the application UI. The security team requires that actions started from Teams follow the same controls as actions performed in Dynamics 365. Which design approach should you recommend?

Domain: Design AI-powered business solutions Type: Single choice

C is correct.

Explanation: The evidence states that for external orchestration with Copilot, you should use Dataverse or custom APIs for consistent and governed data access, and validate that actions triggered externally match security and approval constraints in Dynamics.

A is incorrect: Embedded AI brings Copilot capabilities directly inside workspace pages or operational views, which does not meet the requirement for an agent operating outside the application UI in Teams.

B is incorrect: Giving broad access violates the architectural consideration to apply role-based access so users only retrieve data appropriate to their permissions.

D is incorrect: Prompt-defined behaviors are used within sidecar experiences, not for external orchestration and enforcing system security constraints.

Learn more in Microsoft Learn

Q038 - Question

A company is consolidating CRM, ERP, and document data so that Copilot, Copilot Studio agents, and custom RAG apps can use it. The compliance team requires access policies, sensitivity labels, lineage tracking, and data quality rules before any AI system uses the data. Which service should you plan to use for these governance requirements?

Domain: Plan AI-powered business solutions Type: Single choice

A is correct.

Explanation: Implement governance early. Use Microsoft Purview for access policies, sensitivity labels, lineage, and data quality rules.

B is incorrect: Azure AI Search is part of the intelligence layer. It supports grounding, retrieval, and semantic search, not the governance controls listed.

C is incorrect: Fabric Lakehouse is an analytical store that prepares curated data for AI and machine learning. It does not meet the labeling and lineage requirements on its own.

D is incorrect: Semantic indexing converts enterprise content into semantic representations for grounding. It does not define access policies or data quality rules.

Learn more in Microsoft Learn

Q039 - Question

A company uses a Copilot Studio agent for HR case triage. The agent calls several tools. One tool drafts responses and saves several minutes. Another tool only looks up an employee record and saves very little time. The run path varies from case to case. You need a savings estimate that reflects these differences. How should you configure savings?

Domain: Plan AI-powered business solutions Type: Single choice

A is correct.

Explanation: Use savings per tool when an agent uses multiple tools that have different impacts. This model gives a more granular estimate than a single per-run value.

B is incorrect: Savings per run works best when the run path is predictable. Here the run path varies and the tools have different impacts.

C is incorrect: Only successful, resolved runs count toward savings. Including unresolved runs overstates the benefit.

D is incorrect: Active users is a usage metric. It does not quantify time or cost saved per task.

Learn more in Microsoft Learn

Q040 - Question

Telemetry for a procurement agent shows a spike in blocked actions. Your diagnostic workflow identifies the root cause as governance interference from DLP policies and sensitivity labels. The business still needs the agent to complete approved procurement tasks. Which tuning approach should you apply?

Domain: Deploy AI-powered business solutions Type: Single choice

D is correct.

Explanation: Blocked actions caused by governance require governance-aligned tuning. Review DLP, sensitivity labels, and access rules, and then adjust roles or labels so that agent capabilities align with enterprise compliance requirements. Verify that logging and auditing remain intact after the changes.

A is incorrect: Knowledge tuning addresses incorrect responses caused by knowledge gaps. It doesn't resolve actions that DLP policies or sensitivity labels block.

B is incorrect: Behavioral tuning addresses unexpected behavior from model logic or ambiguous queries. The root cause here is a policy restriction, not agent instructions.

C is incorrect: Performance tuning addresses slow execution and workflow complexity. Optimizing connectors doesn't change the governance rules that block the actions.

Learn more in Microsoft Learn

Q041 - Question

An accounts payable team wants an agent in Copilot Studio to log in to a vendor portal that has no API or connector, download the latest invoice, and save it to SharePoint. You plan to use Computer Use. The vendor sometimes changes the portal layout. Which two design choices improve the reliability of the agent? Each correct answer presents part of the solution. Select two.

Domain: Design AI-powered business solutions Type: Multi-select

B and D are correct.

Explanation: A clear step-by-step workflow improves reliability, even though the agent can reason about next actions. UI elements can change and break automation. Validate results after each step, and build monitoring and fallback plans to handle these changes.

A is incorrect: Limit which apps the agent can access and use least-privilege principles. Broad access increases risk and does not address UI changes.

C is incorrect: Use Computer Use only when APIs are unavailable. Replacing working connectors with UI automation adds a dependency on UI layouts that can change.

Learn more in Microsoft Learn

Q042 - Question

Telemetry for a sales agent shows a sustained increase in token usage and cost. Latency, error rates, and guardrail interventions remain within baseline. Correlation of signals shows that the agent produces verbose outputs. Which two actions should you take? Each correct answer presents part of the solution.

Domain: Deploy AI-powered business solutions Type: Multi-select

B and D are correct.

Explanation: High token usage that results from verbose outputs calls for prompt pattern adjustments, which reduce unnecessary token usage as part of cost optimization. After you apply targeted tuning, validate the improvement by comparing before-and-after telemetry patterns.

A is incorrect: Updating knowledge sources is the action for a quality drop caused by model drift or missing context. The scenario shows a cost issue from verbose outputs, not a quality drop.

C is incorrect: Adjusting governance rules is the action for guardrail triggers caused by policy conflicts. Guardrail interventions remain within baseline, so a governance change doesn't address the token usage.

Learn more in Microsoft Learn

Q043 - Question

An application sends all requests to a large language model (LLM). Most requests are simple classification tasks. A smaller share requires complex reasoning. Token costs are higher than planned. You use the model router in Azure AI Foundry. You need to reduce cost while you maintain performance for complex requests. Which routing configuration should you use?

Domain: Plan AI-powered business solutions Type: Single choice

B is correct.

Explanation: Use SLMs for simple tasks and LLMs only when needed to reduce token consumption. A static rule such as "If task = classification → use SLM" routes by task type, so complex requests still reach the LLM.

A is incorrect: Fallback routing sends requests to a backup model only when the primary model fails. Classification requests still go to the LLM, so cost does not drop.

C is incorrect: Weighted routing distributes traffic for A/B testing and gradual rollout. An even split ignores task type and can send complex reasoning requests to the SLM.

D is incorrect: Version-based routing selects a model version. All requests still use the LLM, so token cost for simple tasks stays the same.

Learn more in Microsoft Learn

Q044 - Question

A manufacturing company plans an AI solution that classifies defect types from inspection notes. The task is lightweight and runs at very high volume. It must return results quickly and run on edge devices on the factory floor. The company also wants to reduce inference cost. Which custom model path should you recommend in Microsoft Foundry?

Domain: Design AI-powered business solutions Type: Single choice

C is correct.

Explanation: Domain-built small models are useful for lightweight tasks that require speed and edge compatibility. Small, specialized custom models can also provide performance and cost advantages over large foundation models for high-volume inference.

A is incorrect: A standard Copilot fits scenarios with low domain specificity and moderate inference cost optimization. It does not address the edge and high-volume cost requirements.

B is incorrect: Fine-tuning adjusts a foundation model's behavior with domain datasets, but a large model does not meet the edge compatibility and cost optimization goals as well as a small model.

D is incorrect: A hybrid architecture combines custom models with prebuilt copilots for augmented reasoning. This scenario requires a fast, lightweight classification task, not augmented reasoning.

Learn more in Microsoft Learn

Q045 - Question

A team proposes building a customized small language model (SLM) to answer general employee questions from existing policy documents. Their main justification is that an SLM will eliminate incorrect information. Which two concerns should you raise? Each correct answer presents part of the solution.

Domain: Plan AI-powered business solutions Type: Multiple choice

B and D are correct.

Explanation: The evidence supports B and D because building a custom SLM when RAG over a general model would suffice is an identified anti-pattern. Additionally, treating SLMs as a silver bullet for incorrect information is an anti-pattern; it is a common misconception that they are always safer than LLMs and always reduce incorrect information.

A is incorrect: SLMs are highly suitable for operationally constrained environments, including mobile, IoT, or edge devices, and on-premises deployments.

C is incorrect: SLMs provide value by delivering high performance while maintaining small memory footprints and low latency, making them more cost-effective and less compute-intensive than large language models.

Learn more in Microsoft Learn

Q046 - Question

A regulated organization plans to deploy a Copilot feature for a workload. In-region capacity is not available for the feature. The organization's policy does not allow overflow processing for this workload tier. What should the solution architect do?

Domain: Deploy AI-powered business solutions Type: Single choice

B is correct.

Explanation: Use the residency decision path. If in-region capacity is not available and overflow is not allowed for the workload tier, block the feature or defer it. In regulated scenarios, set the default to in-region and require explicit approval before you enable overflow processing.

A is incorrect: Recording an exception after deployment skips the required explicit approval. The policy for this workload tier does not allow overflow.

C is incorrect: In regulated scenarios, the default is in-region processing. Overflow processing requires explicit approval and is not a default setting.

D is incorrect: A purge schedule does not make cross-region processing acceptable. The data is still processed outside the region when policy does not allow overflow for this tier.

Learn more in Microsoft Learn

Q047 - Question

A finance organization designs an MCP-enabled agent in Copilot Studio for Dynamics 365 Finance & Operations. Auditors must be able to review the decisions the agent makes. Each user must only reach the business data they are allowed to access. Which design should you recommend?

Domain: Design AI-powered business solutions Type: Single choice

D is correct.

Explanation: For MCP-enabled agents, govern data access by user identity by using least privilege. Align MCP context boundaries with compliance controls, and log agent decisions for auditability. This design meets both the access and audit requirements.

A is incorrect: A shared account with broad access does not limit data by user identity. It does not follow least privilege.

B is incorrect: Instructions that enforce responsible AI behavior are needed, but they do not replace logging. Auditors cannot review decisions that are not logged.

C is incorrect: Exposing all context ignores the requirement to align MCP context boundaries with compliance controls.

Learn more in Microsoft Learn

Q048 - Question

A solution architect plans to extend Copilot in Dynamics 365 Sales with data from an external order management API. A developer proposes to build the custom connector in the tenant's default environment, which does not have Dynamics 365 apps enabled. What should the architect require?

Domain: Design AI-powered business solutions Type: Single choice

C is correct.

Explanation: You must create the connector in an environment with Dynamics 365 apps enabled. Environments without Dynamics 365, such as the default environment, are not supported. Use OAuth 2.0 with Microsoft Entra ID as the identity provider for authentication.

A is incorrect: The default environment is not supported, and the authentication model for these connectors is OAuth 2.0 with Microsoft Entra ID, not an API key.

B is incorrect: Certification makes a connector available organization-wide. It does not remove the requirement to build the connector in an environment with Dynamics 365 apps enabled.

D is incorrect: The default environment is not supported, and an admin must enable the published action before it is visible to Sales users.

Learn more in Microsoft Learn

Q049 - Question

A company plans to adopt generative AI across the enterprise to automate repetitive tasks and generate content. The architect must recommend practices that create business value. Which two practices should the architect recommend? Each correct answer presents part of the solution.

Domain: Plan AI-powered business solutions Type: Multiple choice

A and D are correct.

Explanation: The evidence states that best practices for business value include starting with measurable business outcomes and using cloud scalability for enterprise-wide adoption.

B is incorrect: The evidence states that you must implement AI with responsible AI in mind, which includes fairness, reliability, and safety. You should not delay this until after deployment.

C is incorrect: The evidence states that Azure OpenAI Service provides access to advanced generative AI models. You do not need to build all generative AI models from scratch using Azure Machine Learning.

Learn more in Microsoft Learn

Q050 - Question

A financial services company builds a Copilot Studio agent for a sensitive workload. Regulations require that customer data stays within an approved geographic region. The team plans to use generative AI features. What should you do to validate and enforce data residency compliance?

Domain: Deploy AI-powered business solutions Type: Single choice

C is correct.

Explanation: Generative AI features can move data for evaluation, orchestration, or enrichment. To validate compliance, determine which components can transmit data outside the region, review environment settings for cross-geographic model operations, and apply policies that block cross-region routing for sensitive workloads.

A is incorrect: You need to validate whether unpublished agents and preview features follow different residency rules. Do not assume they behave the same way.

B is incorrect: Custom connectors must not bypass regional data boundaries. A connector that sends data to another region conflicts with the residency requirement.

D is incorrect: Document all data flows, including logs, telemetry, and inference outputs. Logs and conversations are stored data that must follow residency rules.

Learn more in Microsoft Learn

← Read the full AB-100 study guide