Topic module

Responsible AI, Security, Governance, Risk and Compliance

This topic covers agent security, governance, model security, vulnerability analysis, prompt manipulation, responsible AI review, data residency, movement compliance, access controls on grounding data and model tuning, and audit trails.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Microsoft AB-100

Treat each item as an architecture decision: identify the business process, select the Microsoft AI pattern, then add ALM, telemetry, security, responsible AI, and governance controls.

Core concepts

Concept 1

Secure AI-powered business solutions need agent security, model security, access controls, protected grounding data, secure tuning workflows, and audit trails.

Exam cue: Use prompt manipulation defenses when user input can override agent instructions or actions.

Concept 2

Responsible AI review should assess solution behavior against fairness, reliability, safety, privacy, security, inclusiveness, transparency, and accountability.

Exam cue: Use data residency checks when grounding data or model workflows cross geographic or tenant boundaries.

Concept 3

Compliance checks should validate data residency, data movement, model changes, tuning access, prompt manipulation defenses, and governance evidence.

Exam cue: Use audit trails when changes to models, prompts, grounding data, and access need accountability.

Risk pitfalls and guardrails

Giving agents broad access to grounding data without least privilege.

Guardrail: Avoid defaulting to custom agents, skipping grounding-data checks, or treating prompts and connectors as outside the release process.

Treating responsible AI as a launch checklist instead of ongoing governance.

Guardrail: Avoid defaulting to custom agents, skipping grounding-data checks, or treating prompts and connectors as outside the release process.

Skipping audit trails for prompt, model, and data changes.

Guardrail: Avoid defaulting to custom agents, skipping grounding-data checks, or treating prompts and connectors as outside the release process.

Memory anchors

Agent Security

Agent security protects identities, actions, data access, channels, and tool permissions.

Model Security

Model security protects model access, tuning workflows, outputs, and deployment configuration.

Prompt Manipulation

Prompt manipulation attempts to override, bypass, or misuse agent instructions and safeguards.

Data Residency

Data residency controls where data is stored, processed, and moved.

Grounding Access Control

Grounding access control limits source data access based on user and solution permissions.

Tuning Access

Tuning access controls who can modify model behavior and what data may be used.

Audit Trail

An audit trail records changes and actions for accountability and investigation.

Responsible AI Review

A responsible AI review evaluates the solution against responsible AI principles and risk controls.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A Copilot Studio agent uses a service account with access to every Dataverse table, although it reads only customer cases. What should the architect change?

An internal agent is configured with no authentication and linked to restricted knowledge. What is the correct design response?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.