Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Microsoft Designing and Implementing Multi-Agent AI Solutions AI-500 Exam Questions

Page: 1 / 8 Total 73 questions

Want more questions? Get Premium Access.

Question 1

You have a Microsoft Foundry Agent Service solution that includes two agents

You need to configure memory for the agents. The solution must meet the following requirements:

* Isolate the memory between end users

* Isolate the memory between the agent domains.

* Support the deletion of one user's memory without deleting other users' memory.

Solution: You create one memory store per end user and configure both agents to use each user's memory store with a static scope value.

Does this meet the goal?

Correct Answer: B. No
Explanation:

Creating one memory store for each end user separates users, but allowing both agents to use that user's store with the same static scope does not isolate the two agent domains. Memories produced by one agent can occupy the same logical collection as memories produced by the other agent. Microsoft Foundry Memory uses the `scope` parameter to partition a store, so a design that needs both user and domain isolation must preserve both dimensions, commonly through separate agent stores plus per-user scope. The per-user deletion requirement can also be handled more efficiently by deleting a user's scope rather than operating a separate store for every user. Because the proposed design fails agent-domain separation, it does not meet all requirements. Therefore B, No, is correct. In production, add telemetry and regression tests around this behavior so changes to prompts, models, tools, or orchestration do not silently alter the intended contract. The selected approach is the one that best matches the platform's native execution semantics.

Official Microsoft reference: Create and use memory in Foundry Agent Service


Question 2

You need to define a strategy to meet the business requirements for emergency room visits.

Which workflow node should you add to the Lead Orchestrator workflow?

Correct Answer: B. Ask a question
Explanation:

The business requirement says that a physician must approve any triage assessment that recommends an emergency room visit. The workflow must therefore pause and collect a human response before continuing. Ask a question is the option that introduces that interactive human-in-the-loop step. Deliver a message only informs someone; it does not capture a decision. Agent invokes another AI component, which would not satisfy the explicit requirement for a physician's approval. Go to changes the workflow path but likewise does not obtain human authorization. Microsoft Agent Framework documents human-in-the-loop request/response patterns for cases where execution must wait for approval or additional human input. For a medical escalation decision, the control must be deterministic and auditable rather than encoded as a prompt suggestion. Consequently, Ask a question is the workflow node that best enforces the business requirement. At implementation time, the same rule should be expressed through the framework or service configuration rather than left only as a natural-language convention. That makes the behavior repeatable across runs, easier to test, and less sensitive to model variability.

Official Microsoft reference: Microsoft Agent Framework - Human-in-the-loop workflows


Question 3

You have a Microsoft Foundry multi-agent solution for loan applications. Each agent scores a full application independently and does NOT require output from other agents.

You need to recommend an orchestration pattern that meets the following requirements:

Produces one aggregated recommendation

Preserves independent scoring -

Minimizes end-to-end latency -

Minimize development effort -

What should you recommend?

Correct Answer: D. concurrent
Explanation:

The scoring agents do not depend on each other's output, so their work should be fanned out in parallel and aggregated afterward. Microsoft Agent Framework concurrent orchestration is intended for independent participants that can process the same input simultaneously. That minimizes end-to-end latency because completion time approaches the slowest individual scorer instead of the sum of all scorers. The concurrent workflow also provides a fan-in stage that can aggregate the separate scores into one recommendation without requiring a complex custom conversation protocol. Sequential orchestration wastes time by serializing independent work. Group chat and Magentic-style collaboration introduce unnecessary coordination and planning overhead when the agents simply need independent scoring. Therefore D, concurrent, is the simplest and fastest orchestration pattern. In production, add telemetry and regression tests around this behavior so changes to prompts, models, tools, or orchestration do not silently alter the intended contract. The selected approach is the one that best matches the platform's native execution semantics.

Official Microsoft reference: Microsoft Agent Framework - Concurrent orchestration


Question 4

You have a Microsoft Foundry multi-agent solution that includes a orchestrator and agents named Agent1 and Agent2. The solution has the following characteristics:

* The orchestrator routes tasks to both agents.

* The agents invoice Model Context Protocol (MCP)-hosted tools.

* Agent? sends model-generated JSON parameters directly to tool endpoints.

* The agents use a shared managed identity that has contributor access to the resource group that contains the tool-backed Azure resources.

You need to implement a guardrail strategy for tool calls. The solution must meet the following requirements:

* Prevent invalid or out-of-range tool parameters from reaching the tool endpoints.

* Scope each agent's permissions to its assigned tools

* Limit Agent? to refund-processing tools only.

* Log tool invocations for audit purposes.

What should you do?

Correct Answer: D. Configure per-agent tool access policies, validate typed payload schemas at the tool boundary before execution, assign per-agent managed identities that have scoped roles, and enable Azure Monitor logging for tool invocations.
Explanation:

The solution needs deterministic validation before model-generated tool arguments reach MCP endpoints, per-agent authorization boundaries, tool scoping, and audit logging. Validating typed payload schemas at the tool boundary prevents malformed or out-of-range arguments before execution, which is stronger than validating outputs after a tool has already run. Per-agent managed identities and scoped RBAC roles reduce lateral movement and contain the impact of a compromised agent. A per-agent tool-access policy also ensures the refund-focused agent cannot invoke unrelated tools. Finally, Azure Monitor/trace logging provides an auditable record of tool invocations. A2A capability cards describe remote-agent capabilities rather than validate tool arguments. System instructions are not an authorization boundary, and shared Contributor access leaves an excessive blast radius. Option D is therefore the only answer that satisfies all four requirements at enforceable platform boundaries. From a security and governance perspective, the control should be enforced at the narrowest platform boundary that can deterministically block or constrain the action. Relying only on prompt text is weaker because the model can still be induced to behave unexpectedly.

Official Microsoft reference: AI-500 Study Guide - tool scopes, permission boundaries, and auditing


Question 5

You have a Microsoft Foundry multi-agent solution. The solution includes a parent agent that can call an Azure logic app and delegate to two subagents.

You need to implement a review process for flagged interactions. The solution must meet the following requirements;

* Identify requests that call third-party services.

* Moderate the prompts, steps, and tool calls.

* Include a governance review.

What should you do?

Correct Answer: D. Submit the requests by using central sensitive-use intake, enable guardrails and traces, and require reviewers to approve, edit, or reject messages.
Explanation:

The review process must cover the full sensitive interaction, including third-party calls, prompts, intermediate steps, and tool actions, and it must feed a governance review process. A centralized sensitive-use intake combined with guardrails and tracing provides the required evidence, while human reviewers must be able to approve, edit, or reject flagged interactions rather than reviewing only the final message. Content Safety alone does not provide full process governance over tool use. Routing only subagent findings or requiring approval only for the final response misses earlier third-party actions. CI/CD evaluation is important for release quality but does not control individual flagged production interactions. The source duplicated the label C for the final option; that final option should be labeled D. With that label correction, D is the best answer. From a security and governance perspective, the control should be enforced at the narrowest platform boundary that can deterministically block or constrain the action. Relying only on prompt text is weaker because the model can still be induced to behave unexpectedly.

Official Microsoft reference: AI-500 Study Guide - governance, guardrails, tracing, and HITL


Question 6

You are designing Microsoft Foundry multi-agent solution. The agents will use Agent-to-Agent (A2A) delegation and access separate Azure Storage containers within a resource group named RG1.

You need to recommend identity components for the design. The solution must meet the following requirements:

* Eliminate stored application secrets.

* Limit the impact of a compromised agent or deployment.

Solution: Use delegated user permissions for agent actions. Assign Azure roles by using a shared security group. Does this meet the goal?

Correct Answer: B. No
Explanation:

The proposed solution uses delegated user permissions for agent actions and assigns Azure roles through one shared security group. Even if it avoids storing an application secret, it does not create strong per-agent authorization boundaries. Sharing downstream permissions through one group can allow a compromised agent to inherit access intended for other agents, which conflicts with the requirement to limit blast radius. Microsoft Foundry identity guidance recommends distinct logical agent/workload identities and narrowly scoped role assignments when agents have different resource responsibilities or audit requirements. Delegated user access is appropriate when an operation genuinely needs the signed-in user's authorization context, not as a general service-to-service isolation model for autonomous A2A workers. Therefore the proposed design does not meet both goals, and B, No, remains correct. The same configuration should be paired with auditable identity, trace, and evaluation data so reviewers can prove which principal acted, which policy was applied, and why a request was allowed or blocked. That is particularly important for production multi-agent systems with external tools.

Official Microsoft reference: Microsoft Foundry agent identity


Question 7

Solution: Use separate a managed identity for each agent and environment Assign Azure roles at the resource level. Does this meet the goal?

Correct Answer: A. Yes
Explanation:

Separate managed identities for each agent and environment remove the need to store application secrets and create independent authorization boundaries. Assigning Azure roles at the resource level further limits each identity to only the Storage resource it requires. This sharply reduces lateral movement compared with a shared application principal or subscription-wide role. Microsoft Foundry and Azure identity guidance consistently recommend identity-based authentication, distinct identities when permissions differ, and the narrowest practical RBAC scope. In current Foundry deployments, the exact identity object may be represented through Microsoft Entra agent identity or a federated managed identity relationship, but the architectural principle in the option is correct. Therefore the solution meets both stated goals and the answer is A, Yes. From a security and governance perspective, the control should be enforced at the narrowest platform boundary that can deterministically block or constrain the action. Relying only on prompt text is weaker because the model can still be induced to behave unexpectedly.

Official Microsoft reference: Microsoft Foundry agent identity


Question 8

You have a Microsoft Foundry agent named Agent1.

You open Agent1 in the playground and update the instructions.

You need to run a full evaluation against the updated instructions. The solution must meet the following requirements:

* Test the changes by using a synthetic dataset.

* Ensure that the changes are available only for the development team that has access to Agent1.

What should you do first?

Correct Answer: A. Save Agent1 as a new version.
Explanation:

The instructions changed in the playground, but a full evaluation needs a stable, versioned agent definition. Saving the changes as a new version creates an immutable snapshot that can be evaluated against a synthetic dataset while remaining inside the project for the development team. Publishing is a later lifecycle action that makes a version available to broader consumers or production endpoints and is not required for a private development evaluation. Previewing exercises the current playground configuration interactively but does not establish the versioned target needed for repeatable evaluation. Creating an evaluation before saving the new version risks evaluating the previous configuration instead of the intended update. Microsoft Foundry's development lifecycle separates edit, save/version, evaluate, and publish stages, so A is the correct first action. A robust evaluation program separates process metrics from final-response metrics. The selected answer measures the layer where the stated failure actually occurs, which is essential for deciding whether to change retrieval, orchestration, prompt behavior, or the final generator.

Official Microsoft reference: Microsoft Foundry agents - development lifecycle


Question 9

You need to modify claim Approval to prevent the prompt injection issue. Which guardrail should you use?

Correct Answer: B. Prompt shields for documents
Explanation:

The malicious text is contained in an uploaded email rather than being typed directly as the user's prompt. Microsoft classifies malicious instructions embedded in external or retrieved content as an indirect prompt-injection attack. Prompt Shields for documents is designed to detect those attacks in document content before the content can steer the model away from its system instructions. Prompt Shields for user prompts addresses direct attacks originating in the user's prompt and therefore targets the wrong attack surface here. Groundedness evaluates whether a response is supported by context; it does not prevent an injected instruction from changing agent behavior. Task Adherence can assess whether an agent follows its task constraints, but it is not the primary control for document-borne prompt injection. Because the source of the attack is the uploaded email, the document-oriented Prompt Shields control is the technically aligned guardrail. The same configuration should be paired with auditable identity, trace, and evaluation data so reviewers can prove which principal acted, which policy was applied, and why a request was allowed or blocked. That is particularly important for production multi-agent systems with external tools.

Official Microsoft reference: Microsoft Foundry guardrails - intervention points and indirect attacks


Question 10

You have a Microsoft Foundry project that processes customer requests through several stages: A routing agent receives investigation requests, delegates calculations to a data analysis agent that can use Code Interpreter, and delegates source-grounded summaries to a literature review agent.

You discover the following issues:

* Tasks are sometimes routed to the incorrect agent.

* The format of the final response is inconsistent.

You need to ensure that compound requests are routed consistently, and the final response is in a consistent format. The solution must meet the following requirements:

* Minimize changes to the application code.

* Apply to every future conversation handled by the agents.

* Clarify the expected behavior for representative compound inputs.

Which prompt design should you implement?

Correct Answer: C. Add few-shot instruction examples that cover routing decisions and schema-compliant final outputs.
Explanation:

The requirements ask for behavior that applies to every future conversation, improves routing for representative compound inputs, and standardizes final output with minimal application-code change. Few-shot instruction examples satisfy all three by demonstrating both the desired routing decision and the expected schema-compliant response for representative cases. Repository-wide constraints list rules but do not demonstrate how ambiguous compound requests should be handled. Per-request prompt cues are not durable across future conversations and would require application logic to inject them repeatedly. System role instructions define domains and objectives but provide less behavioral specificity than examples. Microsoft AI-500 prompt-engineering objectives explicitly include examples and dynamic prompt techniques for shaping complex agent behavior. Therefore C is the strongest design. The implementation should also preserve clear inputs and outputs around this step so that later agents receive only the information they require. This improves debuggability and keeps token, permission, and state growth under control as the workflow becomes more complex.

Official Microsoft reference: AI-500 Study Guide - advanced prompt engineering