Microsoft Certified: Azure AI Engineer AssociatePlan and manage an Azure AI solutionHard

A financial services company is developing an Azure AI solution to detect fraudulent transactions. The solution uses Azure Cognitive Services for anomaly detection and must comply with strict data residency regulations, requiring all data to remain within a specific geographical boundary. Additionally, the company needs to ensure that the AI services are accessible only from approved internal networks. Which combination of Azure services should be used to meet these requirements?

  1. ADeploy Cognitive Services as containers on Azure Container Instances (ACI) in a different region.
  2. BDeploy Cognitive Services in any available region and use Azure Front Door.
  3. CDeploy Cognitive Services in a specific region and expose them via public endpoints.
  4. DDeploy Cognitive Services in the required region and use VNet Service Endpoints.
Show answer & explanation

Correct answer: D. Deploy Cognitive Services in the required region and use VNet Service Endpoints.

Deploying Cognitive Services in the required region addresses data residency. Using VNet Service Endpoints ensures that traffic to the Cognitive Service resource stays within the Azure backbone network and is accessible only from approved virtual networks, meeting the access restriction requirement.

Why the other options are wrong

  • A. Deploying in a different region violates data residency. ACI might offer containerization but doesn't inherently solve data residency or VNet access without proper VNet configuration in the correct region.
  • B. Azure Front Door is for global traffic management and performance, not for enforcing data residency or restricting access to internal networks.
  • C. Exposing services via public endpoints violates the requirement for access only from approved internal networks, creating a security vulnerability.

VNet Service Endpoints for AI

VNet Service Endpoints extend your virtual network's private address space to Azure services, allowing private access to Azure service resources from your VNet.

  • Secures Azure service resources to your virtual network.
  • Traffic travels over the Azure backbone network, not the public internet.
  • Helps enforce data residency and network isolation.

Memory trick: Region-specific endpoints keep data home and secure.

More Plan and manage an Azure AI solution questions