Microsoft AI-901 (Azure AI Fundamentals)

Microsoft Foundry: Resources, Projects & Endpoints

18 free practice questions with explanations

18 free questions · instant explanations · no sign-up

PassNova has 18 free Microsoft AI-901 (Azure AI Fundamentals) practice questions on Microsoft Foundry: Resources, Projects & Endpoints, each with a clear explanation. Practise them in the browser with instant feedback — 100% free, no sign-up, on any device. Updated for 2026.

Sample questions

Microsoft Foundry: Resources, Projects & Endpoints: example questions & answers

18 worked examples with answers and explanations below. Practise them in the browser with instant feedback on every answer.

  1. In Azure's organisational structure, which construct is described as a billing container that ties your cloud usage to a payment method and sets boundaries for cost, quotas and access control?

    • AAn Azure tenant
    • BA resource group
    • CA Foundry project
    • DAn Azure subscription✓

    Answer: An Azure subscription is the billing container for cloud resources, and one tenant can hold one or many of them. The tenant is the organisation's home base and identity in Microsoft's cloud rather than a billing boundary, and a resource group is a folder that holds related resources so they can be managed together. A Foundry project is a workspace inside a Foundry resource, not an Azure billing construct.

  2. A company wants to keep the storage account, database and Foundry resource for one AI solution together so that it can apply custom permissions and policies to them as a set. Which Azure construct should it use?

    • AA resource group✓
    • BA Foundry resource
    • CAn Azure subscription
    • DAn Azure tenant

    Answer: A resource group is a folder that holds related Azure resources so they can be managed together, with custom permissions and policies applied at the resource-group level. A tenant is the organisation's identity home in Microsoft's cloud and a subscription is a billing container, so neither is the unit for grouping related assets. A Foundry resource is itself a single Azure resource that provides model hosting, not a container for storage accounts and databases.

  3. A developer wants a single, centralised web-based interface where they can create Azure resources, monitor usage and health, manage roles, and view billing and spending across all Azure services. Which should they use?

    • AThe Azure portal✓
    • BThe Azure CLI
    • CThe Foundry portal
    • DThe Foundry Playground

    Answer: The Azure portal at https://portal.azure.com is the centralised, web-based management interface for all Azure services, covering resource creation, monitoring, identity and access, and billing. The Foundry portal is the web interface for developing and operating AI solutions such as models and agents, not for billing across every Azure service. The Azure CLI is a command-line route for creating resources programmatically rather than a web UI, and the Foundry Playground is where you test prompts against a deployed model.

  4. According to the unit on using a generative AI model, the Foundry SDK exposes which two clients?

    • AA model client for inference and a storage client for secrets
    • BA Project client for Foundry-native ops and an OpenAI-compatible client✓
    • CA tenant client for identity and a subscription client for billing
    • DA portal client for the Playground and a CLI client for scripting

    Answer: The Foundry SDK exposes a Project client for Foundry-native operations and an OpenAI-compatible client for calling models through the Responses API, and most apps use both. There are no tenant, subscription, portal, CLI or storage clients in the SDK; identity and billing are handled by Microsoft Entra ID and Azure subscriptions, and secrets live in Azure Key Vault rather than in an SDK client.

  5. An AI chatbot built on Azure authenticates its calls to a model endpoint with a key. Where does the unit say such a secret should be stored, rather than in code or GitHub?

    • AIn the Azure portal's All resources pane
    • BIn Microsoft Entra ID as a role assignment
    • CIn a resource group's custom policies
    • DIn Azure Key Vault as a secret✓

    Answer: In Azure, secrets such as API keys, connection strings and OAuth tokens are typically stored in Azure Key Vault, and the application retrieves them at runtime using a managed identity. Resource group policies govern how resources are managed, not where sensitive values are kept. The All resources pane in the Azure portal lists resources for management, and Microsoft Entra ID handles identity and role-based access control rather than storing keys.

  6. How does the unit describe Microsoft Foundry?

    • AA centralised, web-based management interface for creating, monitoring and billing every Azure service
    • BA suite of prebuilt Azure services for speech, vision and language that can be added to web or mobile apps
    • CA unified, enterprise-grade platform-as-a-service for building, deploying and managing AI applications and agents✓
    • DA managed, permission-aware knowledge layer that connects an organisation's data sources to its agents through reusable knowledge bases

    Answer: Microsoft Foundry is a unified, enterprise-grade platform-as-a-service (PaaS) that consolidates models, agent orchestration, monitoring and governance tools in one platform. The permission-aware knowledge layer built on reusable knowledge bases is Foundry IQ, and the suite of prebuilt speech, vision and language services is Foundry Tools. The centralised web-based management interface for all Azure services is the Azure portal.

  7. A department has a single Foundry resource and wants several separate workspaces inside it, each focused on a different AI use case with its own agents, evaluations and connections. What does the unit call each of these workspaces?

    • AA model deployment
    • BA Foundry project✓
    • CA resource group
    • DA Foundry Tool

    Answer: A Foundry project is a workspace inside a Foundry resource where you build AI apps, agents and evaluations, and one resource for a team can contain many projects, each for a separate use case. A resource group is an Azure folder for grouping related resources, not a workspace inside Foundry. A model deployment makes one model available at an endpoint, and a Foundry Tool is a prebuilt AI service such as Azure Speech.

  8. Which of the following does the unit list as something the Foundry resource itself provides, rather than an asset you build and manage inside a Foundry project?

    • AEvaluations and vector indexes
    • BFiles, datasets and flows
    • CConnections and project-specific settings
    • DQuotas and operational controls✓

    Answer: A Foundry resource provides models, the agent service, deployment governance, monitoring and observability, security boundaries, and quotas and operational controls. Evaluations, vector indexes, files and datasets, flows, connections and project-specific settings are all listed as things a Foundry project lets you build and manage inside that resource.

  9. A developer wants to add speech-to-text and text-to-speech capabilities to a mobile app by using a Foundry Tool. Which tool should they use?

    • AAzure Vision
    • BAzure Speech✓
    • CFoundry IQ
    • DAzure Language

    Answer: Azure Speech is the Foundry Tool that converts speech to text and text to speech. Azure Language summarises text, classifies information and extracts key phrases, while Azure Vision analyses images. Foundry IQ is the knowledge layer that grounds agents in an organisation's data rather than a speech service.

  10. Which Foundry capability is described as the centralised connection point for data sources: a permission-aware, multi-source knowledge layer that gives agents grounded answers from an organisation's own data?

    • AFoundry IQ✓
    • BFoundry portal
    • CFoundry Models
    • DFoundry Tools

    Answer: Foundry IQ is the permission-aware, multi-source knowledge layer that lets you build a configurable knowledge base from sources such as Azure Blob Storage, SharePoint, OneLake or public web data, handling indexing, chunking and embeddings automatically. Foundry Tools are the prebuilt speech, vision and language services, Foundry Models is the model catalog, and the Foundry portal is the web interface for developing and operating AI solutions.

  11. A developer's code needs to work with a Foundry project and the resources it contains, rather than simply send prompts to a deployed model. According to the endpoints unit, which type of endpoint should the code use?

    • AA model endpoint
    • BA project-level endpoint✓
    • CA tenant endpoint
    • DA Key Vault endpoint

    Answer: Project-level endpoints are for working with your Foundry project and its resources, while model endpoints are for sending prompts to deployed models. A tenant is an organisational identity container rather than something exposed as a Foundry endpoint. A Key Vault endpoint would be used to retrieve secrets, not to work with a Foundry project.

  12. To keep a Foundry resource secure, its endpoint is protected. What must an application present to be allowed access?

    • AThe Azure subscription ID and the name of the resource group
    • BThe resource type together with the unique resource ID
    • CThe tenant ID together with the model deployment name
    • DAn API key or a token confirming valid Microsoft Entra ID credentials✓

    Answer: Applications can only access a Foundry endpoint if they present the correct API key or a token confirming that their Microsoft Entra ID credentials are valid. Subscription IDs, resource group names, tenant IDs and deployment names identify where a resource lives and which model to call, but none of them authenticates a request. A resource type and resource ID describe the resource's behaviour and identity rather than proving the caller's right to use it.

  13. Your application starts receiving rate-limit errors from a Foundry model deployment because its deployment-level quota is being exceeded. According to the unit, what should you do in your code?

    • ASwitch from the SDK to direct REST calls
    • BLower max tokens or reduce concurrent requests✓
    • CRaise the temperature or pad the prompt
    • DMove the API key from Key Vault into the code

    Answer: Deployment-level quotas define how many tokens or requests can be processed before throttling occurs, and larger prompts and higher max output token settings consume more TPM. If you see throttling, the unit advises lowering max tokens or reducing concurrent requests in code. Temperature affects creativity rather than token consumption and a longer prompt consumes more TPM, SDKs simply wrap the same REST calls, and moving a key out of Key Vault weakens security without changing the quota.

  14. In the curl example in the endpoints unit, which HTTP header carries the authentication token for the request to the Foundry endpoint?

    • AAuthorization: Bearer $AUTH_TOKEN✓
    • BContent-Type: application/json
    • Capi-key: $AUTH_TOKEN
    • DOcp-Apim-Subscription-Key: $AUTH_TOKEN

    Answer: A Foundry REST request carries its Microsoft Entra token in an Authorization header using the Bearer scheme. The Content-Type header in the same request only declares that the body is JSON. Headers named api-key and Ocp-Apim-Subscription-Key are used by other Azure APIs for key-based access and do not appear in the unit's Foundry example.

  15. An application sends a POST request to https://YOUR-FOUNDRY-RESOURCE-NAME.services.ai.azure.com/api/projects/YOUR-PROJECT-NAME/openai/responses?api-version=2025-11-15-preview with a JSON body containing "model" and "input" fields. Which API is it calling?

    • AThe Assistants API
    • BThe Azure AI Search REST API
    • CThe Chat Completions API
    • DThe OpenAI Responses API✓

    Answer: Deploying a model in Foundry creates an API endpoint that you invoke through the OpenAI Responses API, and the /openai/responses path with a model and an input field is that API's request shape. The chat/completions path belongs to the older chat completions interface shown in the unit's example of a model endpoint address. The Assistants API is not what the /openai/responses path exposes, and the Azure AI Search REST API serves search indexes rather than model inference.

  16. In the Python sample that connects to a Foundry project endpoint, which class from azure.identity is passed as the credential argument to AIProjectClient?

    • AManagedIdentityCredential
    • BDefaultAzureCredential✓
    • CClientSecretCredential
    • DAzureKeyCredential

    Answer: The Foundry agent sample imports DefaultAzureCredential from azure.identity and passes it as credential when constructing AIProjectClient with the project endpoint. ManagedIdentityCredential and ClientSecretCredential are other azure.identity credential types that the unit does not use, and AzureKeyCredential is a key-based credential that is not the pattern shown for the project client.

  17. Which set of deployment types does the unit list for a Foundry model deployment?

    • AStandard, global batch and regional provisioned throughput✓
    • BHorizontal, vertical and automatic scaling
    • CTokens per minute, requests per minute and capacity units
    • DProject-level, model-level and tenant-level

    Answer: Deployment types such as standard, global batch and regional provisioned throughput determine where and how inference is processed and are tied to throughput and data-processing requirements. Horizontal and vertical scaling describe adding instances or CPU and memory to a hosted application, not model deployment types. Project-level and model endpoints are endpoint types, and tokens per minute, requests per minute and capacity units are rate limits rather than deployment types.

  18. When you configure an Azure resource, which setting determines where the resource is deployed?

    • AThe region setting✓
    • BThe security settings
    • CThe resource type
    • DThe performance tier

    Answer: The region setting determines where an Azure resource is deployed, and it is one of the settings you choose alongside performance tier and permissions. The performance tier is associated with cost rather than location, the resource type (for example Microsoft.Storage/storageAccounts) defines the resource's behaviour and capabilities, and the security settings govern permissions rather than placement.

Start practising Microsoft Foundry: Resources, Projects & Endpoints →