Free AB-100 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
AB 100 Agentic AI Solution Architect Pra…
Q: 1
A finance team is enabling prompt actions so an agent can look up invoices, update cases,
and initiate refunds from within Copilot Studio. The solution must enforce least privilege
and separation of duties across dev/test/prod, and high-risk actions must require approval
with full auditability. The organization also has a "no public exposure" requirement and
cannot add any new connectors.
Which three design choices best meet the constraints while keeping actions maintainable
at scale? (Select THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
After enabling voice mode, the agent’s average response time increases to 3 seconds and
callers report long pauses before answers. You must stop recurrence within one hour with
no downtime, and you cannot redeploy or introduce new connectors. Compliance also
flags that the voice agent sometimes verbalizes step-by-step reasoning during sensitive
identity checks.
Requirements
•
Voice responses must meet a 2-second average target
•
The agent must not verbalize internal reasoning
•
Changes must apply consistently in test and production
What is the best immediate mitigation that also prevents recurrence under the
requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
After enabling a Copilot customization in Dynamics 365 Customer Service, you discover
agents can send case details to a consumer ticketing connector from production. You
must contain the incident today without downtime, and security requires centrally
enforced connector restrictions with auditable evidence. The business also insists the
Copilot experience remains available for internal Dataverse-grounded assistance during
containment.
Requirements
•
Block the consumer connector in production and test
•
Preserve auditable evidence of the policy change
•
Keep Dataverse grounding available
What should you do first?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
After a topic update, the System Fallback topic is triggering on 20% of Teams messages
and is executing an UpdateSupplierBank action through an existing cloud flow. You must
stop recurrence within one hour with no downtime, and you can’t redeploy the flow or
change any app code. Audit requires you to preserve missed utterances and write actions
must only run from explicit intent topics with approvals.
Requirements
•
Fallback must not execute write actions in any environment
•
Missed utterances must be captured for trigger tuning
•
Production and test behavior must remain aligned
What is the best immediate mitigation that also prevents recurrence under the
requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
A manufacturer wants to automate triage decisions using an agent, but auditors require
traceable grounding provenance retained for seven years. Knowledge sources span
SharePoint, Dataverse, and a third-party ticketing system, and cross-border data
movement is prohibited. You must decide the best next step to validate that the data is fit
for grounding before selecting an agent autonomy level.
What is the best next action under these constraints?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A compliance-heavy team needs a new in-app experience that summarizes records and
guides users through a multi-step workflow with AI assistance. You must support
dev/test/prod ALM with code review and maintain private-only access with least privilege,
and you can’t rely on post-deployment manual edits. Supervisors also want a separate
place to review autonomous work items without building a bespoke monitoring dashboard.
What should you propose as the primary approach for the new in-app experience?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
A logistics company is rolling out a standard prompt guideline pack across dev/test/prod
for multiple Copilot Studio agents. The environment is regulated with approval gates for
production changes, and you must demonstrate consistency without downtime during a
weekend change window. Teams currently mix role instructions, formatting rules, and tool
constraints in ad-hoc ways that cause inconsistent behavior.
Steps
1. Define non-negotiable policies and refusal behaviors
2. Collect representative user journeys and constraints
3. Draft reusable prompt patterns and placeholders
4. Build an evaluation pack and regression checks
What is the correct order of operations?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
A utilities provider is building an autonomous agent that can open service tickets, schedule
field visits, and issue refunds through existing Power Platform connectors. Data is
regulated and must remain in-region, high-risk actions must require approvals with
separation of duties, and you can’t introduce new middleware or data stores. The sponsor
wants “hands-off” automation, but security insists least privilege and centrally enforced
governance across dev/test/prod.
Which three design choices best support safe autonomous operation under these
constraints? (Select THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
A service team is redesigning their Copilot Studio bot to reduce hallucinations while
keeping response time under two seconds and avoiding new connectors. They must keep
regulated PII inside tenant-governed boundaries and require approvals for any action that
changes case status. The team also needs a repeatable approach that works across
dev/test/prod without introducing downtime.
Steps
1. Pick the orchestration pattern for all user messages
2. Confirm constraints, data boundaries, and success metrics
3. Choose the right technique per interaction type
4. Define evaluation, regression tests, and rollout gates
What is the correct order of operations?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
A public sector agency wants a task agent to triage inbound requests, draft responses, and
update case records in Dynamics 365. All data is regulated with private-only access and
strict least privilege, and any record update must be approval-gated with a complete audit
trail. You must keep production latency low and avoid adding new connectors while
maintaining dev/test/prod separation.
What is the best task-agent design recommendation under these constraints?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
A retail chain wants the same Copilot Studio agent to run in chat and voice mode, and
voice must stay under 2 seconds while remaining concise. Compliance requires that the
agent never reads internal reasoning aloud and write actions must remain approval-gated.
The team still needs better reasoning for a small subset of complex “identity mismatch”
cases without raising overall credits spend.
What is the best behavior design under these constraints?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
A global manufacturer is rolling out a Microsoft 365 Copilot agent for supplier onboarding
that must surface current policy and initiate approved actions. Supplier data is regulated
with in-region residency and the solution must be centrally enforced across dev/test/prod
without copying content into new stores. High-risk actions (like vendor master updates)
must require approvals with separation of duties, but low-risk lookups must stay fast
during peak hours.
Which three design choices best fit a Microsoft 365 Copilot agent that is extensible,
governable, and safe under these constraints? (Select THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
A customer service organization is building a Copilot Studio solution to triage chats, route
cases, and draft replies inside Dynamics 365 Customer Service. They must meet a 300 ms
routing SLA at peak, stay under a strict monthly model-cost ceiling, and avoid any new
external data store for grounding due to regulated PII. High-risk actions (refund initiation,
case closure) must be approval-gated with audit evidence retained for seven years.
Which design choices best meet the constraints while keeping the solution maintainable?
(Select THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
A production agent suddenly started accepting user instructions that bypass tool approval
gates and change output formatting, causing audit findings within hours. You can't change
the calling apps or redeploy them today, audit logs must be retained for one year, and
controls must be centrally enforced across dev/test/prod. The incident commander needs
the fastest prompt-level containment action that preserves least privilege and governance.
Requirements
•
No downtime or user-facing interruption
•
No new connectors or data movement
•
Change must be auditable and centrally enforced
What should you do first?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
A sales org wants Copilot in Dynamics 365 to generate account summaries and
recommend follow-ups using only Dataverse data. The business requires record-level
security to remain intact across business units and forbids adding new connectors or
exporting data to a separate store. You must improve adoption in the existing Dynamics
app without introducing a new portal experience.
What is the best customization approach?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
Your team is rolling out an agent that drafts customer responses inside Dynamics 365
Customer Service and triggers a refund workflow in Power Automate. Production changes
must be approved by a separate release manager, and you must deploy configuration
updates with no downtime across dev/test/prod. An audit requires traceability of who
approved each release for five years, and you cannot change app code.
Snippet
Which single change best fixes the control gap while meeting the constraints?
Which single change best fixes the control gap while meeting the constraints?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
A regulated claims agent must meet an accuracy SLO and operate under a monthly credits
cap, and it cannot use public internet grounding. The team has a daily labeled evaluation
set approved by compliance, and changes must be validated across dev/test/prod with no
downtime. Leadership wants one primary “health metric” that will catch early regressions
before callers notice.
What is the best primary metric to monitor under these constraints?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
During an incident, a Computer Use automation begins attempting irreversible actions in a
vendor portal after the UI layout changed, and approvals are not being recorded
consistently. You must contain risk within 20 minutes without downtime for read-only
assistance, and the mitigation must be centrally enforced across environments. Audit
evidence of tool execution must be preserved, and you can’t redeploy apps or rebuild the
portal integration today.
Requirements
• Stop any irreversible UI actions immediately
• Keep read-only assistance available
• Preserve evidence for post-incident review
Which immediate remediation best meets the requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
A company is standardizing how Copilot Studio solutions behave across customer service
apps to meet audit requirements and cost targets. They must keep all regulated data
within tenant-governed boundaries and cannot add new connectors or external stores. The
solution must still handle multilingual customers and support approval-gated actions for
high-risk workflows.
Exhibit 1
Based on Exhibit 1, what should be the primary technique for the queue routing row?
Based on Exhibit 1, what should be the primary technique for the queue routing row?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
A production autonomous agent started invoking a high-risk “UpdateBankDetails” action
without approvals after a configuration promotion. You can’t redeploy apps today,
governance requires centrally enforced controls with audit logs retained for one year, and
there must be no downtime for procurement operations. The incident response lead needs
the fastest compliant change that restores approval gating across dev/test/prod.
Requirements
•
No downtime or user-facing interruption
•
No new connectors or data movement
•
Change must be auditable and centrally enforced
What should you do first?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20