This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Choose the best response for each of the following questions.
Your healthcare organization is deploying Azure OpenAI to summarize patient medical records. HIPAA regulations require that all patient data remains within the United States and uses customer-managed encryption keys. Which combination of Azure Policy definitions should you assign to enforce these requirements?
Assign Allowed locations policy restricting deployments to US regions and 'Cognitive Services should use customer-managed key for encryption' policy with Deny effect at the subscription scope containing healthcare workloads
Assign Audit usage of custom RBAC roles policy and 'Diagnostic logs in Azure AI services should be enabled' policy at the resource group scope to monitor compliance through manual review
Assign 'Require tag on resources' policy mandating 'compliance:HIPAA' tag and 'Allowed resource types' policy limiting deployments to Azure OpenAI Standard tier only at the management group scope
Your data science team needs to deploy Azure OpenAI models for internal research on customer sentiment analysis. The team should be able to create resources and configure models but must not access production customer data or modify deployed production models. Which RBAC role assignment strategy implements least-privilege access for this scenario?
Assign Cognitive Services Contributor role at the development resource group scope and Cognitive Services User role at the production resource group scope, with separate resource groups isolating development and production environments
Assign Owner role at the subscription scope to enable full development flexibility and rely on Azure Policy to prevent unauthorized production changes through approval workflows
Create a custom role with wildcard permissions for all Cognitive Services operations and assign it at the resource group scope, then configure conditional access policies requiring manager approval for production resource access
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?