Q001 - Question
A company is scaling AI across several business units. Each team uses different frameworks and tools, so deployments are inconsistent and hard to compare. Which enterprise scaling practice should the architect apply first to address this problem?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Continuous learning
- B. User training
- C. Standardization
- D. Automation
C is correct.
Explanation: The evidence states that standardization involves using common frameworks and tools. This directly addresses the issue of teams using different frameworks and producing inconsistent deployments.
A is incorrect: Continuous learning enables models to evolve with new data. It does not standardize frameworks or tools across teams.
B is incorrect: User training enables a culture of continuous user learning. It does not resolve inconsistent tooling across teams.
D is incorrect: Automation streamlines deployment and monitoring. If each team automates using different tools, the deployments remain inconsistent.
Q002 - Question
A company is designing a helpdesk triage agent. The agent runs on a schedule with no signed-in user, reads ticket data in one Azure resource, and updates knowledge articles. The agent exists in dev, pre-prod, and prod environments. Security requires least-privilege access and no embedded secrets. What should you configure for agent-to-Azure authentication and authorization?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Use one managed identity that all three environments share, and assign it the Contributor role at the subscription scope.
- B. Create a managed identity for each agent in each environment, and assign a role at the narrowest scope with only the actions that the agent needs.
- C. Store a service principal client secret in the agent configuration, and rotate the secret every quarter.
- D. Configure the agent to use the permissions of the maker who built it.
B is correct.
Explanation: When an agent acts as itself, scope a service role with only the actions the agent needs. Use a unique managed identity for each agent in each environment. Managed identities remove secrets and simplify rotation, and narrowly scoped role assignments enforce least privilege.
A is incorrect: A shared identity removes the separation between dev, pre-prod, and prod. Contributor at the subscription scope grants far more access than the agent needs.
C is incorrect: A client secret in the configuration is an embedded secret. The design checklist requires managed identities and no embedded secrets.
D is incorrect: The agent runs with no user and acts as itself. Maker permissions are not scoped to the agent's tasks, and the Maker role is meant to stay separate from production publishing.
Q003 - Question
A support team uses Agent Builder in Microsoft 365 Copilot to create a case triage agent. The team has defined the agent's purpose, added instructions and guardrails, connected data sources, and configured actions and permissions. Leadership wants the agent available to support staff soon. What should the team do next?
Domain: Design AI-powered business solutions Type: Single choice
- A. Test the agent with sample prompts, and then publish it to targeted users or groups.
- B. Publish the agent to the entire organization, and then use user feedback to find errors.
- C. Add capabilities for policy Q&A and lead preparation so the agent serves more teams before release.
- D. Remove the escalation conditions so the agent can complete more cases without human review.
A is correct.
Explanation: In the Agent Builder workflow, you test the agent with sample prompts after you configure actions and permissions. You then publish the agent to targeted users or groups. Use the testing and validation workspace to verify behavior before release.
B is incorrect: Publishing to everyone skips the test step. Agent Builder includes publishing controls so you can target specific users or groups.
C is incorrect: Agents should solve a single high-value need. Adding unrelated capabilities makes intent less clear.
D is incorrect: Agent behavior should define conditions that escalate to human review. Removing them weakens the guardrails for case triage.
Q004 - Question
Monitoring shows that the output quality of a custom AI model in production has moved away from its expected performance. The model is still used for business tasks. What should you do?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Retrain the model directly in Production by using live inputs so that the fix takes effect immediately.
- B. Decommission the current version immediately without documenting a transition plan.
- C. Trigger a retraining cycle with updated, versioned data, and then evaluate the new version through the promotion gates before you deploy it.
- D. Overwrite the current version in the model registry with the retrained model to avoid a new release.
C is correct.
Explanation: When you detect model drift, trigger a retraining cycle with updated data. Use versioned data pipelines for reproducibility. Promote the new version only after it passes the evaluation, safety, performance, cost, and governance checks in the promotion gates.
A is incorrect: Production holds stable, approved model versions with monitoring and rollback controls. Experimentation and training belong in Dev.
B is incorrect: Retirement applies when a model no longer meets accuracy, safety, cost, or business expectations. Even then, document a transition plan to the next model version.
D is incorrect: Model registries use version locking and rollback paths. If you overwrite a version, you remove the rollback path and the traceable version history.
Q005 - Question
A customer service agent has had no changes to its logic or workflows for three months. Over the same period, accuracy declines on recurring tasks, response patterns shift, and users report more off-topic responses. Latency and dependency errors stay stable. Which monitoring area should you prioritize to investigate this behavior?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Token consumption
- B. Model drift
- C. Reliability indicators
- D. Throughput
B is correct.
Explanation: Model-driven behavior can shift over time even when agent logic is stable. Shifts in response patterns, declining accuracy in recurring tasks, and increased hallucination or off-topic responses are model drift indicators. Prioritize model drift monitoring.
A is incorrect: Token consumption measures the cost-to-performance ratio and the efficiency of prompting patterns. It doesn't directly measure declining accuracy or off-topic responses.
C is incorrect: Reliability indicators include sudden latency increases and errors related to external dependencies. The scenario states that latency and dependency errors stay stable.
D is incorrect: Throughput measures the volume of completed runs over a period. It doesn't show whether response quality changes.
Q006 - Question
An HR agent sometimes returns answers from a retired leave policy. Reviewers also find several copies of the same policy in different layouts. You need to improve the grounding data before you add it to the agent. Which two actions should you take? Each correct answer presents part of the solution.
Domain: Plan AI-powered business solutions Type: Multiple choice
- A. Remove outdated or conflicting policy content before you add it as knowledge.
- B. Grant all employees access to every HR library so the agent can retrieve more content.
- C. Remove duplicate files and apply consistent formatting to the policy documents.
- D. Move the policy documents to local devices so the agent reads a smaller set of files.
A and C are correct.
Explanation: Evaluate content quality before upload and remove outdated or conflicting information to improve accuracy and timeliness. Remove duplicates and use consistent formatting to improve cleanliness and retrieval precision.
B is incorrect: Broader access does not fix stale or duplicate content. Review permissions regularly so agents ground from valid data sources only.
D is incorrect: Store authoritative content in SharePoint or OneDrive so it becomes part of the semantic index. Local copies do not meet this requirement.
Q007 - Question
A product owner asks you to approve a Microsoft 365 agent pilot. The agent will retrieve project files and write status updates to a tracking system through a connector. Before you approve the pilot, which two items should you confirm? Each correct answer presents part of the solution.
Domain: Design AI-powered business solutions Type: Multi-select
- A. The agent uses the largest available model so that output quality is as high as possible.
- B. The runs-as model is documented, and least-privilege access is confirmed.
- C. A custom agent is built first, and out-of-the-box agents are assessed after the custom build is complete.
- D. The required tools and connectors are identified, and failure paths and human approval points are defined.
B and D are correct.
Explanation: The readiness checklist for solution architects requires confirming identity and access (runs-as model documented, least-privilege confirmed) and actions and tools (required tools/connectors identified, failure paths and human approval points defined).
A is incorrect: The readiness checklist does not specify using the largest available model; it focuses on business value, identity, data scope, actions, security, change control, measurement, and support.
C is incorrect: The evidence states that before considering any custom agents, out-of-the-box pilots should be assessed to determine whether they will adequately meet the requirements.
Q008 - Question
An organization has deployed several agents. Leadership now asks the architect for adoption guides and best practices to plan enterprise AI adoption. Which resource should the architect use?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Prebuilt agents in Copilot Studio
- B. Copilot Studio templates
- C. The Scenario Library
- D. Azure AI Services
C is correct.
Explanation: The evidence states that the Scenario Library provides access to adoption guides and best practices for enterprise AI.
A is incorrect: Prebuilt agents in Copilot Studio are used to automate common business processes. They do not provide adoption guides for leadership.
B is incorrect: Copilot Studio templates are used to create tailored AI solutions. They support agent creation, not enterprise adoption planning.
D is incorrect: Azure AI Services provide Vision, Speech, Language, and Decision capabilities. They do not provide adoption guides.
Q009 - Question
Your team uses Copilot to generate test cases for an agent that summarizes financial reports. The generated test cases use inconsistent formats, and many don't include failure conditions such as an empty report or a corrupted PDF. You need to improve the consistency and coverage of the generated test cases. What should you do?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Accept the generated test cases without review, because Copilot identifies edge cases.
- B. Provide a test case template in the prompt that includes fields such as Expected Results and Edge Case Variations, and define quality expectations such as a minimum number of negative tests per scenario.
- C. Use Copilot only after deployment to generate tests for issues that users report.
- D. Write a new prompt for each release based on the team's current priorities.
B is correct.
Explanation: Copilot performs best when it follows consistent patterns. Provide a test case template in the prompt for predictable output, and define quality expectations, such as at least two negative tests per scenario, to improve coverage of failure conditions.
A is incorrect: You must still review generated test cases for completeness, accuracy, clarity, and maintainability. Boundary and failure conditions must be verified, not assumed.
C is incorrect: Design the strategy around Copilot instead of using Copilot reactively. Define testing objectives, prompts, and quality thresholds before generating tests.
D is incorrect: Ad hoc prompts reduce consistency across releases. Maintain a reusable prompt library and version control prompts and test templates.
Q010 - Question
A financial services company is designing a Copilot Studio agent for a regulated account process. Users send consistent, structured commands such as "Reset password" and "Check balance." The business requires strict intent matching and deterministic responses with limited generative behavior. Which language understanding approach should you recommend?
Domain: Design AI-powered business solutions Type: Single choice
- A. Generative AI orchestration
- B. Standard natural language processing (NLU)
- C. Azure Conversational Language Understanding (CLU)
- D. A Generative Answers (NLU Boost) node as the primary routing method
B is correct.
Explanation: Use standard NLU for predictable tasks that require high precision and low variability. It fits strict intent matching for regulated processes, consistent structured commands, and deterministic responses with limited generative behavior.
A is incorrect: Generative orchestration is best for unstructured or unpredictable messages and open-ended tasks. It is also more compute intensive, which adds cost without benefit for fixed commands.
C is incorrect: Azure CLU is the best choice when phrasing varies moderately within defined topic boundaries. For structured commands with regulatory accuracy needs, standard NLU is the best choice.
D is incorrect: Generative answers act as a fallback when no topic matches. They answer from knowledge sources and do not provide strict, deterministic intent routing.
Q011 - Question
A solution architect is preparing a total cost of ownership (TCO) estimate for a Copilot Studio agent. The draft includes licensing and API usage costs. The finance team asks the architect to add the recurring costs of running the agent after deployment. Which two costs should the architect add as operational costs? Each correct answer presents part of the solution.
Domain: Plan AI-powered business solutions Type: Multiple choice
- A. Data preparation for the initial agent build
- B. Monitoring and evaluation of the agent
- C. Retiring outdated models at the end of the lifecycle
- D. Prompt library maintenance
B and D are correct.
Explanation: Operational costs recur after deployment. They include monitoring and evaluation, model retraining, prompt library maintenance, support and troubleshooting, and user training and adoption programs. Add these costs so the TCO estimate covers the full AI lifecycle.
A is incorrect: Data preparation is a development cost that occurs during the build. It is not a recurring operational cost.
C is incorrect: Retiring outdated models is a decommissioning cost. It belongs at the end of the lifecycle, not in ongoing operations.
Q012 - Question
A finance manager reports that an agent answers budget questions for some employees but not for others. The budget documents are stored on a SharePoint site that only the finance team can access. The manager asks why other employees do not get grounded answers. What should you tell the manager?
Domain: Plan AI-powered business solutions Type: Single choice
- A. The semantic index does not update as content changes, so the documents are stale.
- B. The agent can ground responses only from data the user can access, and the Retrieval API does not return content outside the user's access scope.
- C. The documents are irrelevant to the agent's use case, so semantic search skips them.
- D. The agent requires the documents to be stored in Azure SQL before it can ground responses.
B is correct.
Explanation: Availability determines what an agent can ground on. The Copilot Retrieval API honors user permissions, so employees outside the finance team do not get content from the restricted site. To change the result, review the access controls on the site.
A is incorrect: The semantic index in Microsoft 365 continuously updates as content changes. Stale data does not explain why results differ by user.
C is incorrect: Relevance issues affect all users in the same way. The difference by user points to access permissions.
D is incorrect: Content stored in SharePoint or OneDrive and indexed in Microsoft Graph can be used for grounding. Moving the documents to Azure SQL is not a stated requirement.
Q013 - Question
A finance department wants in-app help in Dynamics 365 Finance to guide users through regulatory period-close procedures. Auditors require that help responses use only controlled, validated content. Which recommendation should you make?
Domain: Design AI-powered business solutions Type: Single choice
- A. Enable general knowledge so that users get broader natural language explanations of close procedures.
- B. Restrict general knowledge, add validated and labeled Word or PDF process documents through Copilot Studio, test the responses, and then publish.
- C. Add Dataverse virtual entities published from Finance and Operations as the main knowledge source for close procedures.
- D. Upload the process documents in Copilot Studio and publish them as soon as the knowledge source shows Ready.
B is correct.
Explanation: The evidence states to restrict general knowledge when precision is critical for regulatory or financial workflows and only controlled, validated knowledge should influence responses. The recommended process is to prepare validated PDF/Word files, ingest them, test the knowledge behavior, and then publish.
A is incorrect: General knowledge should be restricted, not enabled, when precision is critical for regulatory workflows and only validated knowledge should be used.
C is incorrect: Dataverse virtual entities published from Finance & Operations are explicitly listed as not recommended or unsupported knowledge sources.
D is incorrect: The recommended process requires testing knowledge behavior (Step 3) after ingestion and before publishing to production (Step 4).
Q014 - Question
A custom AI model that classifies supplier invoices met all accuracy thresholds before deployment. The organization expects invoice formats and supplier patterns to change over the next year. You need to define a quantitative validation criterion that detects changes in output quality caused by these evolving data patterns. Which criterion should you include?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Drift indicators
- B. Throughput
- C. Latency and response time
- D. Token efficiency
A is correct.
Explanation: Drift indicators track changes in output quality due to evolving data or shifting patterns. Include them so you can evaluate the model consistently after deployment, not only before it.
B is incorrect: Throughput measures how many requests the model can process under peak loads. It doesn't detect quality changes caused by new data patterns.
C is incorrect: Latency and response time measure speed for mission-critical workflows. A model can stay fast while its output quality declines.
D is incorrect: Token efficiency measures model usage cost relative to output quality. It doesn't identify quality changes caused by shifting data.
Q015 - Question
You're designing a Microsoft Foundry agent that calls tools to prepare and submit financial approvals in an enterprise system. Which solution rule should you define?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Require human review for financial approvals, scope each tool with least-privilege permissions, and enable mandatory auditing for tool invocation
- B. Rely on platform-enforced governance and built-in safety filters instead of defining evaluation pipelines
- C. Grant the agent access to HR, Finance, and Legal data so it has full context for each approval
- D. Store all agent messages persistently by default so that every conversation is available for later review
A is correct.
Explanation: The evidence supports A because high-risk tasks such as financial approvals require human review. Solution rules for Foundry tools also mandate implementing least-privilege permissions for each tool and enabling mandatory auditing for tool invocation.
B is incorrect: Relying on platform-enforced governance and built-in safety filters applies to Copilot Studio. Microsoft Foundry requires explicit governance, and architects must apply evaluation pipelines to audit safety, correctness, and drift.
C is incorrect: Data constraints require restricting cross-domain data access (such as HR, Finance, and Legal) and providing agents only the data they require.
D is incorrect: Data movement and storage constraints dictate that you must prevent persistent storage of messages unless compliance requires it, and you must define an explicit memory policy.
Q016 - Question
A company is building a RAG solution on Azure AI Search to ground an agent in product documentation. The architect must maximize retrieval relevance and control index size and cost. Which two design choices should the architect make? Each correct answer presents part of the solution.
Domain: Design AI-powered business solutions Type: Multiple choice
- A. Query the live product systems on every conversation turn instead of building an index.
- B. Mark fields as searchable, filterable, sortable, or retrievable only when queries use them.
- C. Enable every capability on every field so that the schema supports any future query.
- D. Use hybrid retrieval that combines vector queries, keyword search, and semantic reranking.
B and D are correct.
Explanation: Extra field capabilities increase index size and cost, so mark fields only with the capabilities you use. Hybrid search, which combines vector, keyword, and semantic reranking, generally yields the most reliable relevance across phrasing, synonyms, and exact terms.
A is incorrect: Do not query live systems for every turn. Build an index that is optimized for your questions and updated on an SLO-driven freshness schedule.
C is incorrect: Enabling all capabilities increases storage and cost. Prefer a minimum viable schema.
Q017 - Question
An accounts payable team receives a high volume of supplier invoices. They want a Power Automate flow to extract invoice data automatically so that they can process it without manual entry. They want to prototype quickly without training a model on their own data. Which Power Platform AI feature should you propose?
Domain: Design AI-powered business solutions Type: Single choice
- A. An AI Builder prebuilt model for receipt and invoice extraction
- B. Copilot Studio to build a custom conversational agent
- C. Copilot in Power Pages to generate forms from natural language
- D. Copilot in Power Apps to generate app screens from natural language
A is correct.
Explanation: AI Builder prebuilt models are useful for rapid prototyping or high-volume automation, and specifically include receipt and invoice extraction.
B is incorrect: Copilot Studio is used to build custom conversational agents with multi-turn reasoning, not for automated document extraction in a flow.
C is incorrect: Copilot in Power Pages is used to build site pages, forms, and data models with natural language, not for extracting data from invoices.
D is incorrect: Copilot in Power Apps is used to generate app screens, tables, and logic from natural language, not for document extraction.
Q018 - Question
A company is building an agent in Copilot Studio to answer engineering questions. The content set is large and continues to grow. Users need high-precision results, and the content is already prepared for vector search. Which knowledge source should you recommend?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Public website knowledge that points to the company's external product pages
- B. Classic orchestration with topics that match user queries to trigger phrases
- C. Azure AI Search with semantic ranking over enterprise vector indexes
- D. Dataverse knowledge based on structured tables and relational data
C is correct.
Explanation: The evidence supports C because Azure AI Search integrates as a powerful index-based information source when vector search or semantic ranking is required. It is the preferred solution when content volume is large and requires scalable indexing, enterprise-grade search relevance, and vector search for embedding-aligned retrieval.
A is incorrect: Public website knowledge is ideal for FAQs, external product information, or publicly available policy materials, not for high-precision retrieval over a large internal vector-indexed content set.
B is incorrect: Classic orchestration selects topics based on matching a user query with trigger phrases and uses knowledge only as a fallback. It does not provide semantic ranking or vector search.
D is incorrect: Dataverse knowledge is used for structured tables and relational data, whereas the requirement is high-precision retrieval over a large indexed content set prepared for vector search.
Q019 - Question
A regulated organization uses grounding data that contains sensitive customer records. Auditors require evidence of sensitivity label changes, data ingestion events, and data movement across regions. The compliance team also wants to avoid unnecessary exposure of sensitive information in the audit system. How should you design the audit trail for data changes?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Capture metadata, not content, in immutable, timestamped logs that attribute each change to an identity.
- B. Copy the full content of each changed document into the audit log so auditors can compare versions.
- C. Store audit logs in a location where data owners can edit entries to correct mistakes.
- D. Log only model version promotions, because data changes are tracked by the data source.
A is correct.
Explanation: Audit logs for data changes must capture metadata, not content, to avoid unnecessary exposure of sensitive information. Use immutable logs, timestamped change records, and role-based attribution linked to the identity provider to show who changed what and when.
B is incorrect: Copying full content into logs exposes sensitive customer records in another location. This conflicts with the requirement to log metadata only.
C is incorrect: Audit logs must be immutable. Editable entries reduce the value of the logs as evidence for audits and investigations.
D is incorrect: You must audit data changes such as ingestion events, sensitivity label changes, and data movement across regions. Model events alone do not meet the auditor requirement.
Q020 - Question
Procurement users want to ask the Dynamics 365 Finance and Operations Copilot agent three things in one chat: whether a vendor is approved, when the vendor's latest compliance certificate expires, and to update the vendor's payment terms. Compliance certificates are stored in a SharePoint library. Which design should you recommend?
Domain: Design AI-powered business solutions Type: Single choice
- A. Ground the agent on Finance and Operations data only, because system data can answer all vendor questions.
- B. Use the SharePoint library as the source for all three requests, including the payment terms update.
- C. Create a client plugin that writes payment terms without checking Finance and Operations security roles, to reduce latency.
- D. Use Finance and Operations data for vendor approval, SharePoint for the certificate, and a Copilot client plugin that respects Finance and Operations security roles for the payment terms update.
D is correct.
Explanation: The evidence demonstrates mapping business questions to knowledge sources: F&O data for vendor status, SharePoint for compliance certificates, and plugin actions for updates. It also specifies that plugins must respect F&O security roles.
A is incorrect: F&O data alone may not answer all questions, as the compliance certificates are stored externally in a SharePoint library.
B is incorrect: SharePoint is an external knowledge base for retrieving documents, not a mechanism for executing actions like updating payment terms.
C is incorrect: The evidence explicitly states under governance and security that plugins must respect F&O security roles.
Q021 - Question
You are designing promotion gates for Microsoft Foundry agents. The Dev to Test gate already includes functional validation, initial guardrail checks, and data source mapping verification. Which two checks should you add to the Test to Prod gate? Each correct answer presents part of the solution.
Domain: Deploy AI-powered business solutions Type: Multi-select
- A. Human validation of agent reasoning
- B. Initial safety and guardrail checks
- C. Verification of data source mappings
- D. Performance and cost assessment
A and D are correct.
Explanation: The Test to Prod gate confirms production readiness. Include human validation of agent reasoning and a performance and cost assessment. Also include regression test completion, data access and policy compliance approval, and documentation of version, dependencies, and risk analysis.
B is incorrect: Initial safety and guardrail checks belong to the Dev to Test gate. The scenario already covers them before the agent reaches Test.
C is incorrect: Verification of data source mappings is part of the Dev to Test gate. It does not replace the production-readiness checks needed before Prod.
Q022 - Question
A retailer has historical sales data and wants a custom model that it can build, train, and deploy to forecast demand. Which Microsoft AI technology should the architect recommend?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Cognitive Services
- B. Azure Machine Learning
- C. Azure OpenAI Service
- D. Copilot solutions
B is correct.
Explanation: Azure Machine Learning is the platform for building, training, and deploying machine learning models. It is the correct choice for creating a custom demand forecasting model.
A is incorrect: Cognitive Services provides prebuilt APIs for Vision, Speech, Language, and Decision. It is not the platform for building and training custom forecasting models.
C is incorrect: Azure OpenAI Service provides access to advanced generative AI models for natural language and creative tasks, not for custom demand forecasting based on sales data.
D is incorrect: Copilot solutions embed AI in Microsoft 365 for productivity tasks. They do not provide a platform to build, train, and deploy custom machine learning models.
Q023 - Question
A business unit wants AI support for policy Q&A and document summarization. Moderate accuracy is acceptable, and time-to-value is the priority. The organization has little labeled domain data and no data scientists or MLOps engineers. What should you recommend?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Build a custom AI model now so the organization fully controls model behavior
- B. Use prebuilt or catalog models, or extend Microsoft 365 Copilot, as the starting point
- C. Collect a large labeled dataset first, and then train a custom model before any deployment
- D. Build a custom model because policy Q&A requires deterministic output
B is correct.
Explanation: The evidence supports B because prebuilt or catalog models fit well when the use case is general-purpose (such as policy Q&A and document summarization), moderate accuracy is acceptable, and time-to-value is a priority. Furthermore, if requirements like large volumes of labeled data and skilled data scientists are not met, extending Microsoft 365 Copilot is often the better starting point.
A is incorrect: Custom models are justified only when existing models cannot meet accuracy, domain, or compliance needs. They also require large labeled datasets and skilled personnel, which this organization lacks.
C is incorrect: Delaying deployment to build a custom model conflicts with the time-to-value priority, and the use case does not demonstrate an accuracy gap that existing models cannot close.
D is incorrect: Policy Q&A is explicitly listed as an example where prebuilt or catalog models fit well. The scenario does not require deterministic or near-deterministic output.
Q024 - Question
You are building an ROI analysis for a Copilot Studio agent that handles invoice exception processing. You plan to use the agent Savings capability to estimate value. An admin has disabled money-based savings for the environment. Finance still requires a currency-based annual benefit. What should you do?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Stop using the Savings capability and base the annual benefit on a user satisfaction survey.
- B. Wait to start the ROI analysis until the admin enables money-based savings again.
- C. Track time saved in the Savings capability and convert the time to currency in your ROI workbook.
- D. Report only the number of agent sessions as the financial benefit.
C is correct.
Explanation: When admins disable money-based savings, you can still track time saved. Convert that time to currency in your ROI workbook by using the minutes saved per run, the number of successful runs, and a fully loaded labor rate.
A is incorrect: A satisfaction survey does not measure time or cost savings. You lose the measured time data that the Savings capability still provides.
B is incorrect: You don't need to delay the analysis. Time-based savings remain available and can be converted to currency.
D is incorrect: Session count is a usage metric, not a financial benefit. It does not include time saved or a labor rate.
Q025 - Question
Your team drafted two versions of a Copilot prompt that summarizes quarterly performance for executives. Before you approve one version for enterprise-scale reuse, you need to compare the versions and confirm that output quality holds for new analysts and senior architects across different business contexts. Which two validation methods should you use? Each correct answer presents part of the solution.
Domain: Deploy AI-powered business solutions Type: Multiple choice
- A. Add several long examples to the prompt that cover every user type.
- B. Use A/B prompt testing to compare accuracy, clarity, relevance, and required follow-up prompts.
- C. Combine the summary task with other reporting tasks into a single prompt to reduce the number of prompts to test.
- D. Use scenario-based testing across user types, business contexts, and task complexities.
B and D are correct.
Explanation: Use A/B prompt testing to compare two variations of the same prompt on accuracy, clarity, relevance, and required follow-up prompts. Use scenario-based testing to validate the selected prompt across user types, business contexts, and task complexities.
A is incorrect: Include examples only when they add clarity, and keep them concise and targeted. Long examples for every user type add clutter and don't compare the two versions.
C is incorrect: Avoid multi-task prompts because they can confuse the model. Combining tasks makes the prompt harder to validate.
Q026 - Question
A procurement team wants an agent that starts a multi-step process when a purchase request is submitted. The process must send the request for approval, notify stakeholders, and generate a confirmation document. Which tools should you recommend for this process automation requirement?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Word and OneNote to generate first-draft reports
- B. Copilot Search with Graph grounding
- C. Microsoft 365 Copilot to summarize Teams threads
- D. Copilot Studio and Power Automate
D is correct.
Explanation: The requirement is to trigger workflows and multi-step tasks such as approvals, notifications, and content generation. Copilot Studio and Power Automate are the tools for process automation.
A is incorrect: Word and OneNote support documentation tasks such as first-draft reports and content rewrites. They do not trigger an approval workflow.
B is incorrect: Copilot Search with Graph grounding answers questions by using enterprise data. It retrieves knowledge but does not run a multi-step approval process.
C is incorrect: Summarizing Teams threads is a communication task. It does not start approvals or notifications.
Q027 - Question
A utility company designs a Copilot Studio agent in voice mode to support field technicians. Technicians call the agent hands-free to request parts orders and check job status. Some requests trigger actions in downstream systems. Which behavior design should you recommend?
Domain: Design AI-powered business solutions Type: Single choice
- A. Provide detailed, multi-sentence spoken responses so technicians receive full context on each request.
- B. Use short, clear phrasing, provide confirmation steps, and include confidence checks before the agent executes actions.
- C. Execute actions immediately after the agent interprets intent so technicians do not wait for confirmation.
- D. Enable deep reasoning for every voice request so all responses go through structured multi-step evaluation.
B is correct.
Explanation: Voice agents should use short, clear phrasing, provide confirmation steps, and include confidence checks before executing actions. Voice relies on real-time interaction, so design for responsiveness, fallback handling, and user-friendly error messages.
A is incorrect: Avoid long multi-sentence responses in voice mode. The agent should provide concise spoken output.
C is incorrect: The voice interaction flow includes a step where the agent confirms or clarifies intent before it executes the action. Skipping this step increases the risk of incorrect actions.
D is incorrect: Deep reasoning is in preview and targets complex multi-step tasks. Standard reasoning provides fast responses and lower compute usage, which fits routine, high-volume requests such as job status checks.
Q028 - Question
A company uses separate Dev, Test, and Prod environments for Copilot Studio agents. Users report a critical error in an agent topic in Prod. The business wants the fix released as soon as possible. Which approach should you use?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Edit the topic directly in Prod, and then export the change back to Dev later.
- B. Import an unmanaged solution that contains the fixed topic into Prod.
- C. Edit the topic in the Test managed solution, and then promote it to Prod.
- D. Fix the topic in Dev, validate it in Test, and then promote a managed solution to Prod through the emergency patch process.
D is correct.
Explanation: Make changes in the unmanaged Dev environment. Validate them in Test, and then deploy to Prod by using managed solutions. An emergency patch process handles critical fixes without bypassing environment separation or version control.
A is incorrect: Do not edit directly in production. A direct edit creates configuration drift and has no tested, versioned source.
B is incorrect: Test and Prod should contain managed solutions only. An unmanaged import into Prod breaks solution layering and change isolation.
C is incorrect: Build and author changes in Dev. Test validates and approves changes. If you edit in Test, the change bypasses the authoring stage and source control.
Q029 - Question
You review the backlog for an HR agent. Conversation transcripts show that the agent correctly identifies what users ask about leave policy. However, the agent answers with content from a policy document that was replaced last quarter. No connector or API errors appear in the logs. Which backlog category should you assign to this item?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Knowledge Issues
- B. Accuracy and Reasoning
- C. Integration Issues
- D. Governance and Compliance
A is correct.
Explanation: Assign the item to Knowledge Issues. This category covers outdated content and insufficient grounding sources. The agent interprets the question correctly but uses a replaced document, so the knowledge source is the problem.
B is incorrect: Accuracy and Reasoning covers misinterpreted queries, missing context, and low-confidence responses. The transcripts show that the agent understood the user intent.
C is incorrect: Integration Issues covers API failures, connector limits, and data access problems. The logs show no connector or API errors.
D is incorrect: Governance and Compliance covers guardrail triggers, DLP conflicts, and restricted actions. Nothing in the scenario shows that a policy blocked or restricted the agent.
Q030 - Question
A customer service agent accepts documents that customers upload. A review finds that some files contain hidden instructions embedded in HTML that attempt to override the agent's system instructions. Which two input controls should you configure? Each correct answer presents part of the solution.
Domain: Deploy AI-powered business solutions Type: Multiple choice
- A. Strip unsafe HTML and embedded prompts from input before the content reaches the model.
- B. Stop capturing user prompts and tool calls so that malicious content is not stored.
- C. Limit the file types that the agent accepts.
- D. Grant the agent access to additional data sources so it can cross-check the embedded instructions.
A and C are correct.
Explanation: Hidden instructions in text, HTML, or files are a prompt manipulation technique. To strengthen input filtering, strip unsafe HTML or embedded prompts, and limit the file types that the AI may accept. These controls reduce the content that can carry hidden instructions.
B is incorrect: You need to capture and analyze user prompts, tool calls, and actions to detect prompt attacks. Removing this telemetry reduces your ability to investigate suspicious behavior.
D is incorrect: Excessive permissions are a data exposure vulnerability. Restrict data access to only what the AI needs instead of expanding it.
Q031 - Question
An AI solution supports an order process where sales orders created in Dynamics 365 Sales sync to Dynamics 365 Finance, and the AI then validates credit risk based on Finance data. Each app passed its own tests. During user acceptance testing, credit risk recommendations are sometimes based on outdated order data. What should you add to the end-to-end test design?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Separate sign-off for the AI feature in each app, tested in isolation.
- B. Structured data scenarios only, to reduce variability in the test results.
- C. Tests under normal load only, to isolate the issue from performance factors.
- D. Cross-app checks that confirm entity mappings, validate data refresh timing and latency, and verify that the AI uses the correct grounding data sources.
D is correct.
Explanation: AI output quality depends on consistent, trusted, and well-timed input data across apps. Add cross-app readiness checks for entity mappings, data refresh timing and latency, and grounding data sources to find where the order data becomes outdated.
A is incorrect: Testing each app in isolation already passed and missed the issue. End-to-end testing must validate the entire business process, not individual modules alone.
B is incorrect: Include both structured and unstructured data scenarios in end-to-end tests. Removing data types reduces coverage and doesn't test data timing.
C is incorrect: Test with both normal load and stress conditions. Limiting load doesn't validate how data moves between Sales and Finance.
Q032 - Question
An organization started with a centralized AI Center of Excellence (AI CoE) that approves every AI project. Product teams now have mature skills and want to own AI delivery. Project approvals are becoming a bottleneck. How should you evolve the AI CoE operating model?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Keep the centralized model and require AI CoE approval for every AI project
- B. Remove AI CoE governance so product teams can adopt AI tools without standards
- C. Create a new standalone AI transformation function separate from the existing Cloud Center of Excellence
- D. Move toward an advisory model where the AI CoE acts as a consultant and governance is embedded into platforms and workflows
D is correct.
Explanation: The evidence supports D because in a mature stage, the AI CoE evolves into an advisory model where it acts as a consultant rather than a gatekeeper. Product teams own AI delivery, and governance is embedded into platforms and workflows.
A is incorrect: Keeping the centralized model maintains the AI CoE as a gatekeeper, which leads to overcentralization and bottlenecks.
B is incorrect: Removing AI CoE governance leads to undergovernance and shadow AI. Governance must remain, but it should be embedded into platforms and workflows.
C is incorrect: A standalone AI transformation function is recommended only when no supporting team exists, and it does not address the approval bottleneck issue.
Q033 - Question
A services company has defined its business outcome: reduce response time for common customer service requests. It needs an AI agent deployed quickly with minimal development. Which resource should the architect recommend?
Domain: Plan AI-powered business solutions Type: Single choice
- A. A custom model built and trained in Azure Machine Learning
- B. Azure AI Services integrated into a new application
- C. The Scenario Library
- D. A prebuilt AI agent in Microsoft Copilot Studio
D is correct.
Explanation: The evidence states that prebuilt AI agents are available through Microsoft Copilot Studio and are designed for common business scenarios such as customer service. They should be used for quick deployment.
A is incorrect: Building and training a custom model in Azure Machine Learning requires significant development time. The requirement is for quick deployment with minimal development.
B is incorrect: Integrating Azure AI Services APIs into a new application requires more development effort than using a prebuilt agent.
C is incorrect: The Scenario Library provides best practices and adoption guides. It is not an AI agent that automates customer service workflows.
Q034 - Question
You are designing a Copilot Studio agent for an operations team. When a new row is added to a Dataverse table, the agent must send a summary to the team without waiting for a user to send a message. Which mechanism should you use?
Domain: Design AI-powered business solutions Type: Single choice
- A. A Generative Answers (NLU Boost) node
- B. A system topic
- C. A condition node
- D. An event trigger
D is correct.
Explanation: Event triggers let an agent act without waiting for a user prompt. A Dataverse row added is an example trigger event, and the trigger can start actions such as sending a summary. Triggers must be explicitly authorized and may impact billing consumption.
A is incorrect: Use generative answers when a user question is not covered by topics and the agent needs to answer from knowledge sources. It still responds to a user question.
B is incorrect: System topics handle common conversation situations, such as greeting, fallback, escalation, and errors. They are not designed to start work from a Dataverse event.
C is incorrect: Condition nodes branch a dialog based on variables and values. They do not start the agent when an event occurs.
Q035 - Question
A company is designing an AI agent for its Dynamics 365 Contact Center live chat channel. The compliance team requires least-privileged access to customer data. The agent must still route and respond based on the case, the channel, and the issue type. How should you design the agent context?
Domain: Design AI-powered business solutions Type: Single choice
- A. Define the needed entity types and map only the required fields, such as CaseID, Channel, and IssueCategory.
- B. Expose all customer, case, and subscription attributes so that the agent has the most grounding data.
- C. Turn on Copilot features for every user in the tenant so that the agent can access all records.
- D. Skip agent context mapping and have the agent use only the conversation transcript.
A is correct.
Explanation: When you configure agent context, define the entity types and map the fields that the agent needs. Include only the needed attributes. This approach improves accuracy, reduces noise, and supports privacy, compliance, and least-privileged access.
B is incorrect: Exposing all attributes conflicts with the requirement to expose only required context attributes for privacy and least-privileged access.
C is incorrect: Enable Copilot per environment and per user role to ensure correct permissions. Do not enable it for every user in the tenant.
D is incorrect: The transcript is only one part of agent context. The agent also needs structured data, such as case history, channel, and routing queues, to respond and route correctly.
Q036 - Question
A sales operations director wants to introduce AI agents across several teams. Leadership asks you how to plan the first phase so that the agents add measurable value. What should you do first?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Deploy agents to every department at the same time, and measure adoption after rollout.
- B. Use agents to replace the review steps where managers apply critical judgment.
- C. Identify the business outcome you want to improve, and then select the tasks that agents should automate.
- D. Postpone Copilot training until the agents are in production.
C is correct.
Explanation: Start with the business outcome you want to improve. Then use agent automation to reduce repetitive work that supports that outcome.
A is incorrect: A broad rollout without a defined outcome gives you no baseline to measure value against. You should also monitor performance and refine prompts, workflows, and data inputs over time.
B is incorrect: Use agent automation to reduce repetitive work, not to replace critical thinking.
D is incorrect: Train teams so they can use Copilot effectively. Postponing training does not support reliable adoption.
Q037 - Question
A manufacturer plans a role-specific AI agent in Microsoft Teams. The agent will route workflows and send notifications based on Dynamics 365 Supply Chain Management data, outside the application UI. The security team requires that actions started from Teams follow the same controls as actions performed in Dynamics 365. Which design approach should you recommend?
Domain: Design AI-powered business solutions Type: Single choice
- A. Use an embedded Copilot experience on the workspace page so that users start all actions from inside the application.
- B. Give the Teams agent broad access to all Supply Chain Management data so that it can answer any user request.
- C. Use Dataverse or custom APIs for data access, and validate that externally triggered actions match the security and approval constraints in Dynamics 365.
- D. Use only prompt-defined behaviors in the sidecar Copilot to control what the Teams agent can do.
C is correct.
Explanation: The evidence states that for external orchestration with Copilot, you should use Dataverse or custom APIs for consistent and governed data access, and validate that actions triggered externally match security and approval constraints in Dynamics.
A is incorrect: Embedded AI brings Copilot capabilities directly inside workspace pages or operational views, which does not meet the requirement for an agent operating outside the application UI in Teams.
B is incorrect: Giving broad access violates the architectural consideration to apply role-based access so users only retrieve data appropriate to their permissions.
D is incorrect: Prompt-defined behaviors are used within sidecar experiences, not for external orchestration and enforcing system security constraints.
Q038 - Question
A company is consolidating CRM, ERP, and document data so that Copilot, Copilot Studio agents, and custom RAG apps can use it. The compliance team requires access policies, sensitivity labels, lineage tracking, and data quality rules before any AI system uses the data. Which service should you plan to use for these governance requirements?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Microsoft Purview
- B. Azure AI Search
- C. Fabric Lakehouse
- D. Semantic indexing for Microsoft 365 Copilot
A is correct.
Explanation: Implement governance early. Use Microsoft Purview for access policies, sensitivity labels, lineage, and data quality rules.
B is incorrect: Azure AI Search is part of the intelligence layer. It supports grounding, retrieval, and semantic search, not the governance controls listed.
C is incorrect: Fabric Lakehouse is an analytical store that prepares curated data for AI and machine learning. It does not meet the labeling and lineage requirements on its own.
D is incorrect: Semantic indexing converts enterprise content into semantic representations for grounding. It does not define access policies or data quality rules.
Q039 - Question
A company uses a Copilot Studio agent for HR case triage. The agent calls several tools. One tool drafts responses and saves several minutes. Another tool only looks up an employee record and saves very little time. The run path varies from case to case. You need a savings estimate that reflects these differences. How should you configure savings?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Configure savings per tool and assign separate time or cost values to each tool.
- B. Configure savings per run with one average value for every run.
- C. Count all runs, including unresolved runs, to increase the volume in the estimate.
- D. Skip the savings configuration and use the active user count as the benefit.
A is correct.
Explanation: Use savings per tool when an agent uses multiple tools that have different impacts. This model gives a more granular estimate than a single per-run value.
B is incorrect: Savings per run works best when the run path is predictable. Here the run path varies and the tools have different impacts.
C is incorrect: Only successful, resolved runs count toward savings. Including unresolved runs overstates the benefit.
D is incorrect: Active users is a usage metric. It does not quantify time or cost saved per task.
Q040 - Question
Telemetry for a procurement agent shows a spike in blocked actions. Your diagnostic workflow identifies the root cause as governance interference from DLP policies and sensitivity labels. The business still needs the agent to complete approved procurement tasks. Which tuning approach should you apply?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Add or update knowledge files to fill content gaps in procurement topics.
- B. Add clarifying instructions and fallback strategies for ambiguous queries.
- C. Optimize connectors and reduce oversized payloads in external data calls.
- D. Review DLP, sensitivity labels, and access rules, and align agent capabilities with compliance requirements while you keep logging and auditing intact.
D is correct.
Explanation: Blocked actions caused by governance require governance-aligned tuning. Review DLP, sensitivity labels, and access rules, and then adjust roles or labels so that agent capabilities align with enterprise compliance requirements. Verify that logging and auditing remain intact after the changes.
A is incorrect: Knowledge tuning addresses incorrect responses caused by knowledge gaps. It doesn't resolve actions that DLP policies or sensitivity labels block.
B is incorrect: Behavioral tuning addresses unexpected behavior from model logic or ambiguous queries. The root cause here is a policy restriction, not agent instructions.
C is incorrect: Performance tuning addresses slow execution and workflow complexity. Optimizing connectors doesn't change the governance rules that block the actions.
Q041 - Question
An accounts payable team wants an agent in Copilot Studio to log in to a vendor portal that has no API or connector, download the latest invoice, and save it to SharePoint. You plan to use Computer Use. The vendor sometimes changes the portal layout. Which two design choices improve the reliability of the agent? Each correct answer presents part of the solution. Select two.
Domain: Design AI-powered business solutions Type: Multi-select
- A. Allow the agent to access any application or website so it can find another path when the portal changes.
- B. Break the task into clear steps, such as open the website, log in, navigate to invoices, download the file, and upload it to SharePoint.
- C. Replace existing connector-based integrations in the workflow with Computer Use so all steps use one method.
- D. Validate results after each step, and build monitoring and fallback plans for UI changes.
B and D are correct.
Explanation: A clear step-by-step workflow improves reliability, even though the agent can reason about next actions. UI elements can change and break automation. Validate results after each step, and build monitoring and fallback plans to handle these changes.
A is incorrect: Limit which apps the agent can access and use least-privilege principles. Broad access increases risk and does not address UI changes.
C is incorrect: Use Computer Use only when APIs are unavailable. Replacing working connectors with UI automation adds a dependency on UI layouts that can change.
Q042 - Question
Telemetry for a sales agent shows a sustained increase in token usage and cost. Latency, error rates, and guardrail interventions remain within baseline. Correlation of signals shows that the agent produces verbose outputs. Which two actions should you take? Each correct answer presents part of the solution.
Domain: Deploy AI-powered business solutions Type: Multi-select
- A. Update knowledge sources to correct model drift and missing context.
- B. Adjust prompt patterns to reduce verbose outputs and unnecessary token usage.
- C. Adjust governance rules to resolve policy conflicts.
- D. Compare before-and-after telemetry patterns to validate the tuning change.
B and D are correct.
Explanation: High token usage that results from verbose outputs calls for prompt pattern adjustments, which reduce unnecessary token usage as part of cost optimization. After you apply targeted tuning, validate the improvement by comparing before-and-after telemetry patterns.
A is incorrect: Updating knowledge sources is the action for a quality drop caused by model drift or missing context. The scenario shows a cost issue from verbose outputs, not a quality drop.
C is incorrect: Adjusting governance rules is the action for guardrail triggers caused by policy conflicts. Guardrail interventions remain within baseline, so a governance change doesn't address the token usage.
Q043 - Question
An application sends all requests to a large language model (LLM). Most requests are simple classification tasks. A smaller share requires complex reasoning. Token costs are higher than planned. You use the model router in Azure AI Foundry. You need to reduce cost while you maintain performance for complex requests. Which routing configuration should you use?
Domain: Plan AI-powered business solutions Type: Single choice
- A. Configure fallback routing so that requests go to a small language model (SLM) only when the LLM fails.
- B. Configure a static rule that routes classification tasks to an SLM and keeps the LLM for complex reasoning.
- C. Configure weighted routing that splits all traffic evenly between the SLM and the LLM.
- D. Configure version-based routing that sends all traffic to the latest stable LLM version.
B is correct.
Explanation: Use SLMs for simple tasks and LLMs only when needed to reduce token consumption. A static rule such as "If task = classification → use SLM" routes by task type, so complex requests still reach the LLM.
A is incorrect: Fallback routing sends requests to a backup model only when the primary model fails. Classification requests still go to the LLM, so cost does not drop.
C is incorrect: Weighted routing distributes traffic for A/B testing and gradual rollout. An even split ignores task type and can send complex reasoning requests to the SLM.
D is incorrect: Version-based routing selects a model version. All requests still use the LLM, so token cost for simple tasks stays the same.
Q044 - Question
A manufacturing company plans an AI solution that classifies defect types from inspection notes. The task is lightweight and runs at very high volume. It must return results quickly and run on edge devices on the factory floor. The company also wants to reduce inference cost. Which custom model path should you recommend in Microsoft Foundry?
Domain: Design AI-powered business solutions Type: Single choice
- A. Use a standard Copilot without a custom model.
- B. Fine-tune a large foundation model from the model catalog and call it for each inspection note.
- C. Train a domain-built small model in Microsoft Foundry.
- D. Build a hybrid architecture that combines a custom model with a prebuilt copilot for augmented reasoning.
C is correct.
Explanation: Domain-built small models are useful for lightweight tasks that require speed and edge compatibility. Small, specialized custom models can also provide performance and cost advantages over large foundation models for high-volume inference.
A is incorrect: A standard Copilot fits scenarios with low domain specificity and moderate inference cost optimization. It does not address the edge and high-volume cost requirements.
B is incorrect: Fine-tuning adjusts a foundation model's behavior with domain datasets, but a large model does not meet the edge compatibility and cost optimization goals as well as a small model.
D is incorrect: A hybrid architecture combines custom models with prebuilt copilots for augmented reasoning. This scenario requires a fast, lightweight classification task, not augmented reasoning.
Q045 - Question
A team proposes building a customized small language model (SLM) to answer general employee questions from existing policy documents. Their main justification is that an SLM will eliminate incorrect information. Which two concerns should you raise? Each correct answer presents part of the solution.
Domain: Plan AI-powered business solutions Type: Multiple choice
- A. SLMs can't be deployed in on-premises or edge environments
- B. Retrieval-augmented generation (RAG) over a general model might meet the requirement without building a custom SLM
- C. SLMs always require more compute and memory than large language models
- D. SLMs aren't a reliable solution for incorrect information and aren't always safer than large language models
B and D are correct.
Explanation: The evidence supports B and D because building a custom SLM when RAG over a general model would suffice is an identified anti-pattern. Additionally, treating SLMs as a silver bullet for incorrect information is an anti-pattern; it is a common misconception that they are always safer than LLMs and always reduce incorrect information.
A is incorrect: SLMs are highly suitable for operationally constrained environments, including mobile, IoT, or edge devices, and on-premises deployments.
C is incorrect: SLMs provide value by delivering high performance while maintaining small memory footprints and low latency, making them more cost-effective and less compute-intensive than large language models.
Q046 - Question
A regulated organization plans to deploy a Copilot feature for a workload. In-region capacity is not available for the feature. The organization's policy does not allow overflow processing for this workload tier. What should the solution architect do?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Enable cross-region processing, and then record a residency exception after deployment.
- B. Block the feature or defer the deployment for this workload.
- C. Turn on overflow processing by default for all workloads, and then review usage each quarter.
- D. Process prompts in a region that has capacity, and then purge transcripts on a schedule.
B is correct.
Explanation: Use the residency decision path. If in-region capacity is not available and overflow is not allowed for the workload tier, block the feature or defer it. In regulated scenarios, set the default to in-region and require explicit approval before you enable overflow processing.
A is incorrect: Recording an exception after deployment skips the required explicit approval. The policy for this workload tier does not allow overflow.
C is incorrect: In regulated scenarios, the default is in-region processing. Overflow processing requires explicit approval and is not a default setting.
D is incorrect: A purge schedule does not make cross-region processing acceptable. The data is still processed outside the region when policy does not allow overflow for this tier.
Q047 - Question
A finance organization designs an MCP-enabled agent in Copilot Studio for Dynamics 365 Finance & Operations. Auditors must be able to review the decisions the agent makes. Each user must only reach the business data they are allowed to access. Which design should you recommend?
Domain: Design AI-powered business solutions Type: Single choice
- A. Connect the agent to MCP context by using a shared account that can access all business entities.
- B. Rely on agent instructions to enforce responsible AI behavior, and do not log agent decisions.
- C. Expose all available data entities and domain models through MCP so the agent has complete context.
- D. Govern data access by user identity with least privilege, align MCP context boundaries with compliance controls, and log agent decisions.
D is correct.
Explanation: For MCP-enabled agents, govern data access by user identity by using least privilege. Align MCP context boundaries with compliance controls, and log agent decisions for auditability. This design meets both the access and audit requirements.
A is incorrect: A shared account with broad access does not limit data by user identity. It does not follow least privilege.
B is incorrect: Instructions that enforce responsible AI behavior are needed, but they do not replace logging. Auditors cannot review decisions that are not logged.
C is incorrect: Exposing all context ignores the requirement to align MCP context boundaries with compliance controls.
Q048 - Question
A solution architect plans to extend Copilot in Dynamics 365 Sales with data from an external order management API. A developer proposes to build the custom connector in the tenant's default environment, which does not have Dynamics 365 apps enabled. What should the architect require?
Domain: Design AI-powered business solutions Type: Single choice
- A. Build the connector in the default environment and use an API key for authentication.
- B. Build the connector in the default environment, and then certify the connector and the plugin.
- C. Build the connector in an environment that has Dynamics 365 apps enabled, and use OAuth 2.0 with Microsoft Entra ID.
- D. Build the connector in the default environment, and then publish the Copilot action directly to Sales users without admin enablement.
C is correct.
Explanation: You must create the connector in an environment with Dynamics 365 apps enabled. Environments without Dynamics 365, such as the default environment, are not supported. Use OAuth 2.0 with Microsoft Entra ID as the identity provider for authentication.
A is incorrect: The default environment is not supported, and the authentication model for these connectors is OAuth 2.0 with Microsoft Entra ID, not an API key.
B is incorrect: Certification makes a connector available organization-wide. It does not remove the requirement to build the connector in an environment with Dynamics 365 apps enabled.
D is incorrect: The default environment is not supported, and an admin must enable the published action before it is visible to Sales users.
Q049 - Question
A company plans to adopt generative AI across the enterprise to automate repetitive tasks and generate content. The architect must recommend practices that create business value. Which two practices should the architect recommend? Each correct answer presents part of the solution.
Domain: Plan AI-powered business solutions Type: Multiple choice
- A. Start with measurable business outcomes.
- B. Delay responsible AI implementation until after deployment.
- C. Build all generative AI models from scratch using Azure Machine Learning.
- D. Use cloud scalability for enterprise-wide adoption.
A and D are correct.
Explanation: The evidence states that best practices for business value include starting with measurable business outcomes and using cloud scalability for enterprise-wide adoption.
B is incorrect: The evidence states that you must implement AI with responsible AI in mind, which includes fairness, reliability, and safety. You should not delay this until after deployment.
C is incorrect: The evidence states that Azure OpenAI Service provides access to advanced generative AI models. You do not need to build all generative AI models from scratch using Azure Machine Learning.
Q050 - Question
A financial services company builds a Copilot Studio agent for a sensitive workload. Regulations require that customer data stays within an approved geographic region. The team plans to use generative AI features. What should you do to validate and enforce data residency compliance?
Domain: Deploy AI-powered business solutions Type: Single choice
- A. Assume that unpublished agents and preview features follow the same residency rules as published agents.
- B. Connect the agent to a custom connector that calls a service in another region to improve response quality.
- C. Review environment settings that allow or restrict cross-geographic model operations, and apply configuration policies that block cross-region routing for this workload.
- D. Document only the inference outputs, because logs and telemetry are not part of the residency boundary.
C is correct.
Explanation: Generative AI features can move data for evaluation, orchestration, or enrichment. To validate compliance, determine which components can transmit data outside the region, review environment settings for cross-geographic model operations, and apply policies that block cross-region routing for sensitive workloads.
A is incorrect: You need to validate whether unpublished agents and preview features follow different residency rules. Do not assume they behave the same way.
B is incorrect: Custom connectors must not bypass regional data boundaries. A connector that sends data to another region conflicts with the residency requirement.
D is incorrect: Document all data flows, including logs, telemetry, and inference outputs. Logs and conversations are stored data that must follow residency rules.