Free AI-500 Questions for Microsoft Designing and Implementing Multi-Agent AI Solutions AI-500 Exam as PDF & Practice Test Engine

  • Exam Code/Number: AI-500
  • Exam Name/Title: Designing and Implementing Multi-Agent AI Solutions
  • Certification Provider: Microsoft
  • Corresponding Certification: Microsoft Certified: Multi-Agent AI Solutions Expert
  • Exam Questions: 75
  • Updated On: Sep 30, 2026
You need to modify claim Approval to prevent the prompt injection issue. Which guardrail should you use?
Correct Answer: D Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
You have a Microsoft Foundry multi-agent solution that uses Microsoft Agent Framework and LangGraph.
Telemetry from the workload is sent to Application Insights.
You need to implement observability components to meet the following requirements:
* Support the investigation of user interactions across agents, models, tools, functions, and API boundaries without relying on verbose production logs.
* Produce recurring and comparable measurements of deployed response quality and safety over time.
What should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Runtime instrumentation: OpenTelemetry distributed tracing with correlation IDs; Post-deployment assessment: A scheduled evaluation that uses test datasets.
Distributed tracing is the correct runtime mechanism because the objective is to reconstruct a user interaction across agents, models, tools, functions, and API boundaries without relying on verbose log text. Microsoft Foundry uses OpenTelemetry-compatible traces and Application Insights so related spans can be correlated into one execution path. Correlation identifiers allow operators to isolate one conversation and inspect where latency, failures, or unexpected behavior originated. The second requirement is different: it asks for recurring, comparable measurements of deployed response quality and safety. Scheduled evaluations against stable test datasets provide that longitudinal benchmark and are more appropriate than ad hoc tracing or infrastructure- only dashboards. Together, OpenTelemetry answers "what happened in this run?" while scheduled evaluation answers "is behavior getting better or worse over time?" The selected pair therefore covers both operational diagnosis and quality regression monitoring. For operational use, the measurement should be captured in a repeatable dataset, trace, or automated gate so that the same criterion can be compared across versions. That is more useful than a one-off manual observation and makes regressions visible before they become production incidents.
Official Microsoft reference: Microsoft Foundry observability concepts
You are designing an enterprise automation solution that has a web portal for users and the following types of workflows:
* Routine workflows that use prompt-defined agents, approved knowledge stores, and HTTPS tools
* Modernization workflows that use custom Microsoft Agent Framework code packaged as container images with predefined handoffs and task states You need to recommend Azure services that meets the following requirements:
* The routine workflows must run agents in a fully managed environment.
* The user portal must be deployed as a managed platform as a service (PaaS) web app
* The modernization workflows must run agents in serverless containers that support automatic scaling What should you recommend for each requirement? To answer, drag the appropriate services to the correct components. Each service may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Routine workflows: Microsoft Foundry Agent Service; User portal: Azure App Service; Modernization workflows: Azure Container Apps.
The three workload types map to three different managed Azure services. Prompt-defined agents that use approved knowledge and HTTPS tools fit Microsoft Foundry Agent Service because it provides a managed agent runtime and hosted agent capabilities without requiring the team to operate the underlying orchestration infrastructure. The user portal is a conventional managed web application, making Azure App Service the direct PaaS fit. The modernization workflow is custom Microsoft Agent Framework code packaged as container images and therefore needs a serverless container platform; Azure Container Apps supplies managed container execution and automatic scaling while preserving control of the custom application image.
Logic Apps targets integration workflows rather than arbitrary Agent Framework containers, and Copilot Studio is not the requested general-purpose container runtime. The answer therefore selects the managed service that matches each component ' s execution model. From a security and governance perspective, the control should be enforced at the narrowest platform boundary that can deterministically block or constrain the action. Relying only on prompt text is weaker because the model can still be induced to behave unexpectedly.
Official Microsoft reference: Microsoft Foundry Agent Service overview
You have a Microsoft Agent Framework solution for customer support that includes the following agents:
* A triage agent
* A refund specialist agent that runs in the same process as the triage agent
* A compliance review agent that is exposed by a partner team as a remote service You need to identify which integration components the triage agent will use to coordinate interactions with the other agents.
What should you identify for each agent? To answer, drag the appropriate components to the correct agents Each component may be used once, more than once, or not at all You may need to drag the split bar between panes or scroll to view content NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Refund specialist agent: Agent-as-tools; Compliance review agent: Agent-to-Agent (A2A) protocol.
The refund specialist runs in the same process as the triage agent, so exposing it as an agent-as-tool is the lightweight composition pattern. The outer triage agent can decide when to invoke the specialist while retaining overall task ownership. The compliance reviewer is different: it is a remote service owned by a partner team. Agent-to-Agent (A2A) is the interoperable protocol intended for independently hosted agents that may use a different runtime or framework. It supports capability discovery and remote task interaction without coupling the caller to the partner ' s implementation. Using A2A for the in-process specialist would add unnecessary network/protocol complexity, while treating the partner agent as an in-process tool would not match the deployment boundary. The two selections therefore reflect Microsoft ' s distinction between local agent composition and remote agent interoperability. The implementation should also preserve clear inputs and outputs around this step so that later agents receive only the information they require. This improves debuggability and keeps token, permission, and state growth under control as the workflow becomes more complex.
Official Microsoft reference: Microsoft Agent Framework - agents as tools and A2A
You have a Microsoft Foundry Agent Service solution that includes two agents You need to configure memory for the agents. The solution must meet the following requirements:
* Isolate the memory between end users
* Isolate the memory between the agent domains.
* Support the deletion of one user ' s memory without deleting other users ' memory.
Solution: You create one memory store per end user and configure both agents to use each user ' s memory store with a static scope value.
Does this meet the goal?
Correct Answer: B Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
You have the following tool integration configuration for a Microsoft Foundry claims-processing assistant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Yes / Yes / No
The first statement is true because the tool-integration contract returns only the explicitly defined `final_text` from FraudReview to ClaimsPlanner; the planner does not automatically receive the specialist ' s entire internal execution history. The second statement is also true because an external REST service such as PremiumRates can be exposed as an OpenAPI-defined tool. The OpenAPI schema describes operations and parameters, while the surrounding agent system retains conversational state; the REST tool itself does not need a developer-managed chat transcript. The third statement is false under the shown configuration because the partner publishes tool descriptors as published while the planner defines which schemas it accepts or rejects. Compatibility handling therefore occurs at the consumer/tool boundary rather than requiring PartnerIntegrations to rewrite every unsupported schema before invocation. The correct sequence is Yes, Yes, No. At implementation time, the same rule should be expressed through the framework or service configuration rather than left only as a natural-language convention. That makes the behavior repeatable across runs, easier to test, and less sensitive to model variability.
Official Microsoft reference: Microsoft Foundry agents - OpenAPI tools
You have a Microsoft Foundry multi-agent customer support solution that routes requests from an intake agent to a retrieval agent, and then to a resolution agent. A custom guardrail is assigned to the agents.
You discover that some legitimate support requests are blocked, and some injected instructions in retrieved documents are allowed.
You need to validate the updated guardrail. The solution must meet the following requirements:
* Identify false positives and false negatives.
* Verify policy coverage across the agent solution
* Prevent changing the production agent behavior during testing
* Measure intervention accuracy by using a control and intervention point.
What should you do?
Correct Answer: A Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
You are designing a Microsoft Foundry multi-agent solution for claims processing. The design includes multiple specialized agents.
You need to specify the agent personas. scopes, boundaries, and autonomy levels. The solution must meet the following requirements:
* Provide a clear owner for conflicts between specialist agents.
* Validate agent outputs before downstream agents consume the outputs.
* Prevent specialist agents from invoking tools outside the assigned domain.
* Isolate each business domain so that adding a specialist agent affects only that domain.
What should you do?
Correct Answer: A Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
0
0
0
10