AZ-900 Describe cloud concepts Practice Question
A company migrates its on-premises servers to Azure virtual machines (IaaS model). The security team is planning the patching strategy and asks who is responsible for installing security updates on the guest operating system of the Azure VMs. According to the shared responsibility model, which statement is correct?
⚠ Common exam trap
Candidates often confuse IaaS with PaaS or SaaS, where Microsoft does manage the guest OS (e.g., Azure App Service or SQL Database), leading them to incorrectly assume Microsoft handles patching for Azure VMs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer is responsible for maintaining and patching the guest operating system on Azure virtual machines.
In the shared responsibility model for IaaS, the customer retains control over the guest operating system, applications, and data. Microsoft manages the physical host, hypervisor, and underlying Azure infrastructure, but the customer must install and maintain security updates on the guest OS of their Azure VMs. This is because the customer has full administrative access to the VM and is responsible for its configuration and patch management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft is responsible for maintaining and patching the guest operating system on Azure virtual machines.
Why it's wrong here
For Azure Virtual Machines, the guest operating system is intentionally not controlled or patched by Microsoft. Azure's responsibility is limited to the physical datacenter, the server hardware, and the hypervisor that hosts the VM; the guest OS and everything within it are managed by the customer. Even when Azure services like `Azure Update Manager` are used to schedule OS patches, the customer retains accountability for verifying and applying the updates because the OS itself is their managed resource.
When this WOULD be correct
This option would be correct for a PaaS service like Azure App Service, where Microsoft manages the underlying OS and runtime, including security updates.
- ✓
The customer is responsible for maintaining and patching the guest operating system on Azure virtual machines.
Why this is correct
For Azure VMs (IaaS), the customer maintains full administrative control over the guest operating system, including installing updates, patches, and security configurations. Microsoft's responsibility ends at the physical host, hypervisor, and Azure-managed infrastructure, so the customer must patch the guest OS to keep the VM secure and compliant. This is a core tenet of the shared responsibility model: the customer owns everything inside the VM, while Azure provides the underlying infrastructure.
- ✗
Microsoft is responsible for patching any application software that runs on Azure virtual machines.
Why it's wrong here
Microsoft does not patch application software that customers install and run on Azure virtual machines. In IaaS, the customer is responsible for managing, securing, and patching the application layer, including binaries, configuration files, and dependencies. Microsoft's patching responsibilities apply only to the Azure platform itself (for example, the hypervisor, host OS, and network infrastructure) and to platform-as-a-service offerings, not to software deployed and customized by the customer on a VM.
When this WOULD be correct
This option would be correct in a PaaS scenario, such as Azure App Service, where Microsoft manages the underlying OS and runtime, and the customer only deploys code. In that case, Microsoft patches the platform including application dependencies.
- ✗
The customer is responsible for the physical security of the Azure datacenter where the virtual machines are hosted.
Why it's wrong here
Physical security of Azure datacenters—including access controls, biometric scanning, surveillance, and environmental protections—is exclusively Microsoft's responsibility under the shared responsibility model, regardless of the workload type. The customer cannot be responsible for securing facilities they never physically access; their obligations are limited to protecting their own identity credentials, data, and logical controls such as network security groups and Azure Policy. This separation is fundamental to how cloud providers guarantee the security of the underlying infrastructure.
When this WOULD be correct
This option would be correct in a question about on-premises infrastructure, where the customer owns and manages the physical datacenter and is responsible for physical security.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓The customer is responsible for maintaining and patching the guest operating system on Azure virtual machines.Correct answer▾
Why this is correct
For Azure VMs (IaaS), the customer maintains full administrative control over the guest operating system, including installing updates, patches, and security configurations. Microsoft's responsibility ends at the physical host, hypervisor, and Azure-managed infrastructure, so the customer must patch the guest OS to keep the VM secure and compliant. This is a core tenet of the shared responsibility model: the customer owns everything inside the VM, while Azure provides the underlying infrastructure.
✗Microsoft is responsible for maintaining and patching the guest operating system on Azure virtual machines.Wrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model for IaaS, Microsoft manages the physical host and hypervisor, but the customer is responsible for the guest OS, including patching.
★ When this WOULD be the correct answer
This option would be correct for a PaaS service like Azure App Service, where Microsoft manages the underlying OS and runtime, including security updates.
Why candidates choose this
Candidates may assume that since Microsoft manages the cloud infrastructure, they also handle guest OS patching, not realizing the division of responsibility in IaaS.
✗Microsoft is responsible for patching any application software that runs on Azure virtual machines.Wrong answer — click to see why▾
Why this is wrong here
In the IaaS model, Microsoft manages the hypervisor and physical infrastructure, but the customer is responsible for patching the guest OS and application software. Option C incorrectly assigns application patching to Microsoft.
★ When this WOULD be the correct answer
This option would be correct in a PaaS scenario, such as Azure App Service, where Microsoft manages the underlying OS and runtime, and the customer only deploys code. In that case, Microsoft patches the platform including application dependencies.
Why candidates choose this
Candidates may confuse IaaS with PaaS or assume Microsoft handles all software patching because they manage the infrastructure, overlooking the shared responsibility model's division of duties.
✗The customer is responsible for the physical security of the Azure datacenter where the virtual machines are hosted.Wrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, the customer is responsible for physical security of on-premises datacenters, not Azure datacenters. Microsoft is responsible for the physical security of Azure datacenters.
★ When this WOULD be the correct answer
This option would be correct in a question about on-premises infrastructure, where the customer owns and manages the physical datacenter and is responsible for physical security.
Why candidates choose this
Candidates may confuse the shared responsibility model and think that since they are using Azure, they are responsible for all security aspects, including physical security of Microsoft's datacenters.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
The Shared Responsibility Model
Key term
Shared responsibility model
The shared responsibility model is a framework that defines which security and compliance tasks are handled by the cloud provider and which are handled by the customer.
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.