certslothcertsloth
← AI-901 overview

Azure AI Fundamentals / STUDY TOOLS

AI-901 quick review

This guide follows AI-901, the current Azure AI Fundamentals exam. It includes Foundry implementation concepts; older AI-900-only notes are not a complete match.

Memory hook: Task → model → deployment → evaluation.

Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.

Scope/version: This guide follows AI-901, the current Azure AI Fundamentals exam. It includes Foundry implementation concepts; older AI-900-only notes are not a complete match.

Must remember by domain

Domain Rapid revision
AI concepts A generative model predicts content; an agent also selects tools and maintains state. Classification predicts categories; regression predicts numbers; clustering finds groups. Embeddings represent similarity; they neither encrypt data nor answer questions by themselves.
Model selection Match input/output modality, task quality, context size, latency, region and cost. A vision model can understand an image without being able to generate one. Temperature changes sampling, not factual reliability.
Responsible AI Fairness: compare affected groups. Reliability/safety: test failures. Privacy/security: minimize and control data. Inclusion: accessible experiences. Transparency: disclose limits. Accountability: name the responsible owner.
Foundry implementation Create/configure the project, deploy a supported model, test it, then connect a client with the actual endpoint, deployment and authorized credential. A catalogue model name can differ from a deployment name. Playground success does not grant your application permission.
Apps and agents System instructions define behavior; user content is a request; retrieved documents/tool results remain untrusted. An agent proposes tool calls; trusted code validates and executes them. Retain state, limit loops and verify the external result.
Text, speech and vision Entity/key-phrase extraction identifies information; sentiment estimates expressed attitude; summarization condenses. Speech recognition is audio → text; synthesis reverses it. Translation changes language. Multimodal input must match supported model capabilities.
Information extraction Content Understanding analyzers specify the desired fields/schema for documents, images, audio or video. Submit, await completion, validate fields and preserve supporting location/timestamps. Acceptance of an analysis job is not its final output.

Choose correctly

  • Fresh company facts: authorized retrieval with citations; a higher temperature adds no knowledge.
  • Exact financial arithmetic: validated code; a fluent model answer is insufficient.
  • Sensitive extracted field: source evidence plus business validation/human review; model confidence alone is insufficient.

Implementation order

Identify input/output → select supported model/tool → configure deployment and access → send a bounded request → inspect result and usage → test error, safety and no-answer cases. Re-test with the application identity, not just the portal account.

Last-pass self-check

1. Does a content filter guarantee truth?

No. It addresses selected safety risks; factual grounding needs separate evaluation.

2. Why store an embedding?

For similarity retrieval, such as finding relevant document chunks.

3. What proves an agent completed a tool action?

The authorized tool response and verified resulting state, not the agent’s narration.

4. What should a lightweight client handle?

Authentication, deployment selection, schema validation, timeouts, throttling and safe retry.

5. What distinguishes extraction from generation?

Extraction derives specified information from source evidence; generation creates content.

Sources

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · AI Models, Workloads and Responsible Use

Memory hook: Identify the input, output and consequence before selecting a model.

Must remember

  • Machine learning predicts patterns from data; generative models create content; agents combine models with state and tools to pursue tasks. Supervised classification predicts categories, regression numbers, clustering finds groups, and reinforcement learning improves behaviour through rewards.
  • Foundation models support broad tasks after pretraining. Large/small models trade capability, latency, footprint and cost. Multimodal models accept or produce supported combinations of text, images, audio or video. Model capability and deployment availability vary by version and Region.
  • Tokens are model-specific units; context/output limits constrain requests. Temperature and related sampling settings influence variability, not truth. Embeddings represent content for similarity retrieval; they are not encryption or final answers.
  • Choose text analysis for entities, key phrases, sentiment or summaries; speech recognition for audio-to-text; synthesis for text-to-audio; vision for visual interpretation; generation for new media; extraction for structured information from source content. A fixed exact calculation may be safer as ordinary code.
  • Responsible AI considers fairness, reliability/safety, privacy/security, inclusion, transparency and accountability. Evaluate representative groups and failure costs. Explain intended use and limitations, offer accessible experiences and assign a responsible owner for correction/escalation.
  • Hallucinations can be fluent and wrong. Ground responses in suitable evidence, validate structured outputs and use human review where consequence requires it. Filters reduce selected risks but cannot guarantee correctness, fairness or legal suitability.

Choose under exam pressure

Requirement Choice and reason
Classify an incoming request A suitable classifier/model with measured category performance.
Answer using current company documents Retrieval-grounded generation with access controls.
Perform an exact regulated calculation Deterministic validated logic when prediction is unnecessary.

Traps

  • Model confidence is not independent evidence.
  • A larger model is not always the best operational choice.
  • Removing a sensitive column does not remove every proxy for that attribute.

Practise this topic

02 · Foundry Projects, Prompts and Lightweight Clients

Memory hook: Authenticate, select the deployment, send a bounded request, inspect the result and handle failure.

Must remember

  • A Foundry project organises supported AI application resources/connections. Choose a model and deployment option using capability, Region, quota, throughput, latency and cost. A catalogue model name and your deployment identifier are not always interchangeable.
  • In the portal, deploy an available model, test representative prompts and inspect output/usage. A successful playground example does not validate application authentication, networking or error handling. Record the model/deployment and configuration used.
  • System instructions define application behaviour; user input provides the request; retrieved text/tool output is untrusted data. Use clear tasks, context, constraints and output schemas. Zero-shot uses no examples; few-shot includes demonstrations. Keep prompts versioned with evaluation cases.
  • A lightweight client needs the supported SDK, endpoint/project configuration, a credential and deployment/model selection. Prefer Entra/default-credential patterns for supported keyless access, with the required roles. Create a client, submit messages/input, inspect text/structured results and usage, and handle authentication, rate-limit and timeout errors.
  • Streaming returns incremental output; it requires correct accumulation, cancellation and partial-failure handling. Never put keys in source code. SDK shapes evolve, so use the current language quickstart for exact imports and methods rather than memorising an old preview signature.
  • A single agent adds a goal/instructions, tools and conversation state. Test it in the portal, then integrate the supported agent client lifecycle: create/reference the agent, submit a user turn, process required tool actions under policy and collect the final result. Bound loops and verify real tool outcomes.

Choose under exam pressure

Requirement Choice and reason
Prototype model suitability Portal deployment/playground with representative tests.
Production app needs credentials without a stored key Supported Entra/managed-identity authentication.
Model requests a tool action Validate and authorise the action before execution.

Traps

  • Deployment ID and base model name may differ.
  • A successful portal call does not prove the app identity has permission.
  • Agent text saying “done” is not proof an external action succeeded.

Practise this topic

03 · Text, Speech, Vision and Content Understanding

Memory hook: Interpret existing evidence, generate new content and extract structured fields as different tasks.

Must remember

  • Text analysis includes entity/key-phrase extraction, sentiment, summarisation and sensitive-content detection. Use supported Foundry Tools or model prompting according to accuracy, format and control requirements. Validate returned JSON/types before using results downstream.
  • Azure Speech supports speech recognition and synthesis; translation and multimodal audio models address related but different tasks. Match language, audio format, streaming/batch mode and latency. A spoken prompt can be transcribed before a text model or sent to a compatible multimodal model.
  • Vision-capable models interpret image inputs for captions, questions or visual evidence. Image-generation models create new visual outputs from prompts/references. Supported models may offer editing/masks; accepting an image does not mean a model can generate one.
  • Content Understanding uses configured analyzers to extract information from supported documents, images, audio and video. Define desired fields/schema, submit source content and consume the resulting structured output/evidence. Layout, timestamps and provenance can matter as much as the extracted value.
  • Long-running analysis may return an operation identifier; poll/await completion according to the SDK rather than treating acceptance as a final result. Validate confidence/evidence and route uncertain high-impact fields for review. An extracted invoice total still needs a business validation rule.
  • Protect input data, apply content/safety controls and preserve consent/licensing. Embedded text in images or documents can contain prompt injection. Accessibility captions should describe useful visible information without inventing details. Measure performance on the actual languages, document layouts and recording conditions.

Choose under exam pressure

Requirement Choice and reason
Extract invoice fields into a schema A suitable Content Understanding analyzer.
Generate spoken output Speech synthesis.
Answer a question about an existing image A vision-capable multimodal model with grounded evaluation.

Traps

  • Recognition and synthesis run in opposite directions.
  • A job accepted response is not completed analysis.
  • OCR text can contain hostile instructions.

Practise this topic

Search across every published topic.