Loading your practice set…
Loading your practice set…
Explanation: Creating a Private Endpoint ensures that traffic between the AI service and the virtual network is routed over a private connection, enhancing security by isolating the service from the public internet. Customer-Managed Keys (CMK) provide control over encryption keys, but they do not isolate the service from the public internet. Network Isolation can be achieved through Virtual Networks, but it does not create a private endpoint. Directly enabling encryption on the AI service does not provide network isolation.
Explanation: Customer-Managed Keys (CMK) allow you to manage your own encryption keys for Azure services, providing more control over key management. Implementing a Private Endpoint or Network Isolation does not affect key management. Enabling encryption on the AI service itself does not change who manages the keys. Using a Virtual Network for isolation also does not manage encryption keys.
Explanation: The correct answer is B because Microsoft Purview's data classification feature allows you to automatically label and classify data based on sensitivity levels. This ensures that sensitive data is identified and protected as per company policies. Option A is incorrect because it refers to manual tagging, which can be error-prone and less efficient. Option C is incorrect because it involves using external tools, which may not integrate seamlessly with your existing systems. Option D is incorrect because it suggests using a generic security tool, which may not have the specific features required for data classification and protection.
Explanation: The correct answer is B because setting up Content Safety filters in Microsoft Purview allows you to define rules and policies that prevent sensitive content from being processed or stored. This ensures compliance with company policies and regulatory requirements. Option A is incorrect because it suggests ignoring Content Safety filters, which would leave sensitive data unprotected. Option C is incorrect because it implies using a generic filter without customization, which may not meet specific needs. Option D is incorrect because it suggests disabling filters, which would also leave sensitive data unprotected.
Explanation: The correct answer is B because the 'Azure OpenAI Contributor' role provides the necessary permissions to manage Azure OpenAI services, including the ability to manage Cognitive Services Custom Readers and workspace managed identities. The 'Cognitive Services Contributor' role only allows management of Cognitive Services resources but not Azure OpenAI services. The 'Contributor' role is too broad and would provide unnecessary permissions. The 'Reader' role does not provide sufficient permissions for managing both Azure OpenAI services and Cognitive Services Custom Readers.
Explanation: The correct answer is C because the 'Workspace Managed Identity Operator' role is specifically designed to manage managed identities within an Azure workspace. It provides the necessary permissions to manage managed identities without granting broader permissions that could be unnecessary or risky. The 'Contributor' role is too broad and would provide unnecessary permissions. The 'Reader' role does not provide sufficient permissions for managing managed identities. The 'Azure OpenAI Contributor' role is not relevant to managing managed identities in this context.