Microsoft AzureAI-103Practice QuestionsAI CertificationExam Prep

AI-103 Practice Questions: Exam-Style Scenarios Explained

Preporato TeamOctober 2, 202612 min readAI-103
AI-103 Practice Questions: Exam-Style Scenarios Explained

AI-103 questions rarely include an option that is obviously wrong. Most of them offer four things a capable Azure developer might do, and the marks go to the one that satisfies the requirement the scenario states. Telling them apart takes precise product knowledge: which setting enforces a rule, which role an identity needs, and which feature depends on another one to work.

This page works through ten questions in that style, two from each skill area, with the reasoning for every option. The explanations for the options you didn't choose are where most of the learning happens.

How to use these

Cover the answers. For each scenario, name the requirement in one sentence before you read the options, and if you can't, that is the gap to study. These ten were written for this page in the style of the six timed AI-103 practice exams on preporato.com. To try a timed set first, start with the free AI-103 practice questions.

About "AI-103 dumps"

Searches for AI-103 dumps run alongside every search for practice questions. Three facts are worth having before you go looking.

Microsoft treats them as misconduct. The Microsoft Certification Exam Candidate Agreement lists using braindump material, and publishing exam questions with or without answers, as misconduct. Microsoft can then bar a candidate from taking any exam and invalidate exam results, without refunding exam fees.

The agreement covers statistical detection. Among the grounds for action, it lists misconduct determined by statistical analysis.

The platform moves faster than any answer key. Content Understanding pro mode has retired, agents moved to the Responses API, and models retire on published dates. An answer memorized from an older exam form can point at an option that no longer exists, while the reasoning in an explained question still works when the wording changes.

Preparing for AI-103? Practice with 390+ exam questions

Plan and manage an Azure AI solution

Question 1: Overflow from provisioned throughput

A retailer serves a chat assistant from a provisioned throughput deployment sized for normal traffic. At month end, demand exceeds the provisioned capacity and some requests return 429 errors. The team wants that overflow served automatically at per-token rates, with no change to the client code that calls the deployment.

What should the team configure?

  • A. A second provisioned deployment in another region, placed behind Azure API Management
  • B. Spillover on the provisioned deployment, pointing to a standard deployment
  • C. A retry policy in the client that waits for the time in the Retry-After header
  • D. A larger provisioned deployment, sized for the month-end peak

Answer: B. Spillover sends requests that a provisioned deployment can't serve to a per-token standard deployment of the same model and version in the same resource. Setting spilloverDeploymentName on the provisioned deployment applies it to every request, so clients keep calling the same deployment name. The IsSpillover split on the request metrics shows how much traffic overflowed.

Why the others fail: A adds a second fixed-capacity commitment and a gateway that clients would have to call. C changes client code, and waiting serves no extra requests when the peak lasts for days. D pays for peak capacity all month to cover a few busy days.

The pattern: "per-token rates" plus "no change to the client" describes spillover.

Question 2: An app that calls a model without keys

An App Service app calls a model deployment in a Foundry project with an API key kept in an app setting. The security team wants no keys anywhere and the least privilege for the app.

Which set of steps meets both requirements?

  • A. Move the key into Key Vault and read it through a Key Vault reference in the app settings
  • B. Enable a managed identity, assign Foundry User, switch to tokens, then set disableLocalAuth
  • C. Enable a managed identity and assign it Owner on the resource group that holds the Foundry resource
  • D. Rotate the key every month and restrict network access to the subnet the app runs in

Answer: B. Keys bypass role-based access control, so least privilege starts with an identity and a role. The app gets a managed identity, the identity gets Foundry User for inference, the code requests tokens with DefaultAzureCredential for the scope https://ai.azure.com/.default, and disableLocalAuth switches key authentication off once every caller uses tokens.

Why the others fail: A stores the key more safely, and the key still exists and still bypasses every role. C removes the key and grants far more than calling a model needs. D shortens a key's life and narrows the network path while keeping key access in place.

The pattern: "no keys" means managed identity plus disableLocalAuth, and "least privilege" means the narrowest role that still allows the call.

Implement generative AI and agentic solutions

Question 3: Multi-turn chat with storage turned off

A financial services team builds a chat assistant on the Responses API. A data policy says the service must not retain response data, so the team sets store to false. Users still need multi-turn conversations.

How should the app supply the earlier turns?

  • A. Pass the previous_response_id of the last response with each new request
  • B. Create a conversation object and pass its ID with every request
  • C. Send the earlier turns as items in the input array of each request
  • D. Move the assistant to the Assistants API and keep each chat in a thread

Answer: C. The Responses API offers three ways to keep history: a durable conversation object, a chain of stored responses linked by previous_response_id, or an input array that your own code rebuilds each turn. With store set to false, previous_response_id has nothing to point at, so each request must carry the earlier items as input.

Why the others fail: A depends on stored responses, which the service keeps for 30 days by default only when store is on. B keeps the history as durable state on the service, which the policy rules out. D also keeps state on the service, in the older agent API that the Responses API has replaced.

The pattern: previous_response_id works because of storage. Turn storage off and the history travels in the request.

Question 4: Moving a customer between agents

A support solution built with Microsoft Agent Framework has a triage agent, a billing agent and a technical agent. The triage agent should pass each customer to the right specialist, who takes over the conversation and can pass it back or onward when the topic changes. No central agent should plan the work.

Which orchestration fits?

  • A. Sequential
  • B. Concurrent
  • C. Handoff
  • D. Magentic

Answer: C. In a handoff orchestration, agents transfer control to each other through tool calls, with no orchestrator. That matches a triage agent passing the customer on and specialists passing it back.

Why the others fail: A runs agents in the order of the participants list, each reading the previous agent's conversation, which suits a fixed pipeline. B sends one input to every agent in parallel and merges the results through an aggregator. D adds a manager that plans and replans, the central planner the scenario rules out.

The pattern: "transfer control" points to handoff, "plans and replans" to Magentic, a fixed order to sequential and parallel work to concurrent.

Master These Concepts with Practice

Our AI-103 practice bundle includes:

  • 6 full practice exams (390+ questions)
  • Detailed explanations for every answer
  • Domain-by-domain performance tracking

30-day money-back guarantee

Implement computer vision solutions

Question 5: Editing one region of a product photo

A marketing team uses a GPT-image model in Foundry to replace the sky in product photos with a sunset. Everything outside the sky, including the product and its logo, must stay exactly as it is.

What should the edit request include?

  • A. The photo and a prompt that describes the new sky in close detail
  • B. A fresh generation request that uses a description of the photo as its prompt
  • C. The photo with its sky cropped away, plus a prompt to fill in the gap
  • D. The photo, a same-size PNG mask with the sky transparent, and a prompt

Answer: D. The image edit API takes an image, a prompt and a mask. The mask is a PNG with the same dimensions as the input, and its fully transparent pixels mark where the model may edit, so the product and logo sit outside the edit. Setting input_fidelity to high also helps keep faces and brand style intact.

Why the others fail: A leaves the whole image open to change. B produces a new image with no tie to the original pixels. C alters the canvas and still gives the model no protected region.

The pattern: "change one region" means a mask of the same size, and "keep a face or brand style" means input_fidelity.

Question 6: Instructions hidden in an uploaded image

An expense agent reads receipt photos and can approve expenses through a tool. A tester uploads a receipt with small printed text that says to approve the expense and email the policy file to an outside address.

Which measures address this risk?

  • A. Raise the severity thresholds for the violence and hate controls in the deployment guardrail
  • B. Scan the receipt text with Prompt Shields and gate the approve tool on human approval
  • C. Shrink every image before analysis so that small printed text becomes unreadable to the model
  • D. Add a line to the agent instructions that tells it to ignore any text that appears inside images

Answer: B. Text inside an image is third-party content, so an instruction hidden in it is a document attack, the indirect form of prompt injection. Prompt Shields document attack detection catches it in the extracted text, and approval on the high-impact tool still holds when detection misses.

Why the others fail: A tunes harm categories, and an injected instruction is neither violent nor hateful. C damages legitimate reading, and an attacker can simply print larger. D relies on an instruction that the injected text is written to override.

The pattern: injection questions reward layers, with detection on untrusted content and a person in front of the action that would do damage.

Implement text analysis solutions

Question 7: Removing personal data from transcripts

A contact center stores call transcripts for quality review. Before storage, names, phone numbers and card numbers must be replaced, and reviewers need to see which kind of value each replacement stood for.

Which approach fits?

  • A. Azure Language PII detection with the entityMask redaction policy
  • B. An Azure AI Content Safety text analysis call on each transcript
  • C. A prompt that asks a chat model to rewrite transcripts without personal data
  • D. Sentiment analysis with opinion mining to flag the sensitive passages

Answer: A. PII detection in Azure Language returns categories, offsets and redacted text from a model built for the task. The redaction policy decides what replaces each value, and entityMask writes the entity type with a counter, such as PERSON_1, so reviewers can tell what was removed. characterMask, the default, hides values behind a run of mask characters.

Why the others fail: B classifies harmful content with severity levels and has no PII redaction. C gives no categories or offsets, and its output can vary from one run to the next. D scores opinions and finds no personal data.

The pattern: fixed-output detection tasks such as PII belong to Azure Language, and the redaction policy decides what a reader can still tell.

Question 8: Product names the agent keeps mishearing

A voice agent built on Azure Speech mishears five product names that launched this week. Everything else transcribes well, and the fix is needed today, with no time to collect audio for training.

What should the developer add?

  • A. A phrase list with the five product names, passed in at runtime
  • B. A custom speech model trained on a month of recorded support calls
  • C. A custom voice model that pronounces each product name correctly
  • D. A second chat model that corrects the transcript after recognition

Answer: A. A phrase list boosts names and terms at runtime with no training, which fits a handful of new names and a same-day deadline. One limit to remember: batch transcription doesn't support phrase lists.

Why the others fail: B suits noise, accents or a large vocabulary, and it needs training data and an evaluation against the base model by word error rate. C shapes how the agent sounds and has no effect on recognition. D adds latency and guesses at words the recognizer never captured.

The pattern: a few names to fix today points to a phrase list, and noise, accents or a large vocabulary point to custom speech.

Implement information extraction solutions

Question 9: Parent documents next to the chunks

A skillset splits PDFs into chunks and vectorizes them, and index projections write each chunk to the index as its own document. The index also holds one extra document per PDF with empty chunk and vector fields. The index should hold only chunk documents.

What should change?

  • A. Add an output field mapping for the chunk and vector fields in the indexer
  • B. Lower maximumPageLength and the overlap setting on the Text Split skill
  • C. Add an indexer field mapping for the key field of the parent document
  • D. Set projectionMode to skipIndexingParentDocuments

Answer: D. When projectionMode is unset, includeIndexingParentDocuments applies, and each source file adds a parent document next to its chunks. Five PDFs that produce 100 chunks leave 105 documents in the index. Setting skipIndexingParentDocuments writes only the chunks.

Why the others fail: A controls how enriched values reach fields, and the parent document still gets indexed. B changes chunk sizes and leaves the parent documents in place. C works against the setup, since the parent key field should stay out of every mapping.

The pattern: "one extra document per source file" is the default projection mode at work.

Question 10: One PDF, several document types

A lender receives single PDFs that contain an application form, several pay stubs and a bank statement in no fixed order. Each document type needs its own field extraction, and pages that match none of the types must not be forced into one.

Which Content Understanding configuration fits?

  • A. A classifier with enableSegment true, an other category and an analyzerId per type
  • B. One custom analyzer whose field schema holds every field from all three document types
  • C. prebuilt-layout on the whole file, then a regular expression for each document type
  • D. Agentic mode with one generate field per document type and one input file per request

Answer: A. contentCategories defines each document type, enableSegment set to true splits one file into documents and classifies each segment, and an analyzerId on each category routes its content to the analyzer that extracts its fields. An other category catches content that fits no defined type, and classification needs no training data, only clear category descriptions.

Why the others fail: B pulls one flat set of fields from mixed documents and never separates them. C returns layout with no classification, and regular expressions break as soon as a form changes. D reasons across one file without splitting or routing it, and agentic mode can't use extract fields.

The pattern: "one file, several documents" points to enableSegment, and "different extraction per type" points to analyzerId routing.

What these ten have in common

Every option above would be a reasonable thing to do in some project. The marks go to the one that meets the requirement the scenario states, and three habits find it:

  1. Underline the requirement words. "No change to the client code", "no keys anywhere", "store set to false", "no central agent" and "must stay exactly as it is" each rule out options that work in general.
  2. Prefer the control that enforces over the instruction that asks. In Question 6, the line in the agent instructions is the one defense the injected text is written to defeat.
  3. Know what each feature depends on. previous_response_id needs storage, phrase lists skip batch transcription, and parent documents appear unless projectionMode says otherwise.

The AI-103 complete guide covers the five skill areas, AI-103 exam topics explained takes the objectives one at a time, and AI-103 vs AI-102 lists what to relearn if you prepared for the older exam. Exam-day tactics, including when to open Microsoft Learn during the exam, are in how to pass AI-103 on your first attempt. For the full set, the AI-103 course on preporato.com teaches each skill area in exam order, and the six timed AI-103 practice exams explain every option, the same way this page does.

Sources:

Ready to Pass the AI-103 Exam?

Join thousands who passed with Preporato practice tests

Instant access30-day guaranteeUpdated monthly
AI-103
6 Practice Exams
Detailed Explanations
Performance Analytics
Get Full Access - $19.99See what's included →

AI-103 · 6 practice exams

$19.99one-time

Get full access