Courseiva
Describe cloud conceptsmediumMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

A company deploys a line-of-business application on an Azure virtual machine. The IT team wants to ensure the application remains secure. According to the shared responsibility model, which of the following security tasks is the sole responsibility of the customer (the company)?

⚠ Common exam trap

It's easy for candidates to confuse 'security of the cloud' (physical and hypervisor security, which Azure handles) with 'security in the cloud' (customer-managed configurations like NSGs), leading them to incorrectly assign physical or hypervisor security to the customer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configuring the network security group (NSG) rules to restrict inbound traffic to the virtual machine.

Configuring Network Security Group (NSG) rules to restrict inbound traffic is a customer responsibility under the shared responsibility model. The customer controls the virtual network and VM-level access, including defining allow/deny rules for protocols like TCP/UDP on specific ports. Azure manages the underlying infrastructure, but the customer must secure their own application traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Protecting the physical servers in the Azure datacenter with video surveillance and access controls.

    Why it's wrong here

    Physical security of Azure datacenters, such as video surveillance, biometric access controls, and security personnel, is enforced by Microsoft as part of the provider's obligations. Customers cannot physically access Azure datacenter floors or server racks, nor do they have any ability to affect or manage physical security. This responsibility applies across Azure services and is never transferred to the customer, regardless of deployment type.

    When this WOULD be correct

    If the question asked 'Which security task is the sole responsibility of Microsoft?' or 'Which task is part of Microsoft's responsibility for physical security?', then this option would be correct.

  • Configuring the network security group (NSG) rules to restrict inbound traffic to the virtual machine.

    Why this is correct

    Configuring NSG rules is a customer-managed security control in Azure IaaS. NSGs filter inbound and outbound traffic to a VM's network interface, and the customer defines the allow/deny rules. Because the VM resides in the customer's subscription, the customer owns network-level access control, while Microsoft only provides the networking infrastructure. This responsibility holds even for Azure Marketplace images, where the customer must lock down exposed ports.

  • Ensuring the hypervisor that isolates virtual machines is free from vulnerabilities.

    Why it's wrong here

    The hypervisor is a core virtualization component that Microsoft designs, patches, and hardens to isolate each customer's VMs. Azure uses the Hyper-V hypervisor, and Microsoft guarantees its security and availability as part of the infrastructure layer. Customers only interact with their VMs through the virtual network and have no direct access to the hypervisor, so patching and vulnerability remediation are Microsoft's responsibility.

    When this WOULD be correct

    This option would be correct in a question asking about responsibilities under a model where the customer manages the entire stack, such as on-premises deployment or IaaS with a self-managed hypervisor (e.g., running Hyper-V on Azure BareMetal).

  • Maintaining the security of the Azure Fabric Controller that manages the host servers.

    Why it's wrong here

    The Azure Fabric Controller is the back-end orchestration layer that manages host servers, including deploying OS images, monitoring host health, and coordinating upgrades. Microsoft operates and secures the Fabric Controller, and it is not exposed to customers in any API or portal. Under the shared responsibility model, maintenance and security of this component belong entirely to Microsoft, since the customer never has access to it.

    When this WOULD be correct

    This option would be correct in a question asking which security task is the responsibility of Microsoft (the cloud provider) under the shared responsibility model for IaaS. For example: 'Which of the following is the sole responsibility of Microsoft when using Azure virtual machines?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

Configuring the network security group (NSG) rules to restrict inbound traffic to the virtual machine.Correct answer

Why this is correct

Configuring NSG rules is a customer-managed security control in Azure IaaS. NSGs filter inbound and outbound traffic to a VM's network interface, and the customer defines the allow/deny rules. Because the VM resides in the customer's subscription, the customer owns network-level access control, while Microsoft only provides the networking infrastructure. This responsibility holds even for Azure Marketplace images, where the customer must lock down exposed ports.

Protecting the physical servers in the Azure datacenter with video surveillance and access controls.Wrong answer — click to see why

Why this is wrong here

Physical security of Azure datacenters, including video surveillance and access controls, is the responsibility of Microsoft, not the customer, under the shared responsibility model.

★ When this WOULD be the correct answer

If the question asked 'Which security task is the sole responsibility of Microsoft?' or 'Which task is part of Microsoft's responsibility for physical security?', then this option would be correct.

Why candidates choose this

Candidates may mistakenly think that all security tasks are shared or customer-owned, overlooking the clear division where physical infrastructure is managed by the cloud provider.

Ensuring the hypervisor that isolates virtual machines is free from vulnerabilities.Wrong answer — click to see why

Why this is wrong here

In the shared responsibility model, ensuring the hypervisor is free from vulnerabilities is the responsibility of Microsoft (the cloud provider), not the customer. The customer is responsible for securing their own data and applications, not the underlying virtualization layer.

★ When this WOULD be the correct answer

This option would be correct in a question asking about responsibilities under a model where the customer manages the entire stack, such as on-premises deployment or IaaS with a self-managed hypervisor (e.g., running Hyper-V on Azure BareMetal).

Why candidates choose this

Candidates may confuse the hypervisor's role in isolation with customer-managed security controls, or they may think that since the VM is customer-deployed, all related security is customer-owned.

Maintaining the security of the Azure Fabric Controller that manages the host servers.Wrong answer — click to see why

Why this is wrong here

In the shared responsibility model, maintaining the security of the Azure Fabric Controller is the responsibility of Microsoft, not the customer. The customer is responsible for securing their own applications and data, not the underlying infrastructure.

★ When this WOULD be the correct answer

This option would be correct in a question asking which security task is the responsibility of Microsoft (the cloud provider) under the shared responsibility model for IaaS. For example: 'Which of the following is the sole responsibility of Microsoft when using Azure virtual machines?'

Why candidates choose this

Candidates may confuse the boundaries of the shared responsibility model, thinking that because they manage the VM, they also manage the host infrastructure. The term 'Fabric Controller' sounds like something the customer might need to configure, leading to this error.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.