AZ-900 Describe cloud concepts Practice Question
A company plans to migrate a line-of-business application to Azure. The application will run on a virtual machine (IaaS). The company wants to ensure that the operating system is kept up to date with security patches. According to the shared responsibility model, who is primarily responsible for applying these patches?
⚠ Common exam trap
Many candidates assume Microsoft handles all patching in Azure because of the 'as a service' nature, but in IaaS, the customer retains full control and responsibility for the guest OS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer, because the customer manages the guest operating system and is responsible for patching it.
In the shared responsibility model for IaaS, the customer retains control over the guest operating system, including applying security patches. Microsoft manages the physical host and hypervisor but does not patch the OS running inside the VM. Therefore, the customer is primarily responsible for keeping the OS up to date.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft, because they manage all operating system updates in Azure.
Why it's wrong here
Microsoft manages the physical infrastructure and the host OS (hypervisor) that run Azure VMs, but it does not patch the guest OS inside a customer's VM. When a customer deploys an IaaS VM, they are responsible for that OS, and Azure does not automatically apply guest-level updates unless the customer configures a solution like Azure Update Manager or Azure Automation Update Management. Saying Microsoft manages 'all' OS updates incorrectly conflates the host-level maintenance (which Microsoft performs) with guest-level patching (which is the customer's job).
When this WOULD be correct
If the question specified a PaaS service like Azure App Service or Azure SQL Database, where Microsoft manages the underlying OS and applies patches automatically, then Microsoft would be primarily responsible.
- ✓
The customer, because the customer manages the guest operating system and is responsible for patching it.
Why this is correct
In Azure IaaS, the customer creates and manages the virtual machine, including its guest operating system. Microsoft provides the physical datacenter, host servers, and hypervisor, but does not automatically patch the guest OS. The customer has full administrative access to the VM and is solely responsible for installing security updates, patches, and configuration of the operating system. This is a fundamental tenet of the shared responsibility model for IaaS.
- ✗
Both Microsoft and the customer share responsibility equally for operating system patching.
Why it's wrong here
The shared responsibility model does not mean an equal 50/50 split of duties; it means each party is responsible for specific layers of the stack. In IaaS, Microsoft secures and patches the physical host and hypervisor, while the customer exclusively handles the guest OS, including its patches and updates. There is no joint or cooperative patching of the guest OS—the customer operates and maintains that layer independently. Therefore, 'equally' is a mischaracterization of a clearly delineated division of responsibility.
When this WOULD be correct
This option would be correct in a scenario where the question specifies a PaaS service, such as Azure App Service, where Microsoft manages the underlying OS and applies patches, but the customer is still responsible for application-level patching, making it a shared responsibility.
- ✗
The cloud service provider, as a general rule for all services in Azure.
Why it's wrong here
There is no general rule that the cloud service provider always patches the operating system across all Azure services; responsibility varies by service model. In IaaS, the customer patches the guest OS; in PaaS offerings like Azure App Service or Azure SQL Database, Microsoft patches the underlying OS; in SaaS, Microsoft patches everything. Also, the phrase 'cloud service provider' is vague and does not clarify which party is accountable for what is inside a customer-deployed virtual machine, which is the crux of this IaaS scenario.
When this WOULD be correct
For a PaaS service like Azure App Service or Azure SQL Database, where Microsoft manages the underlying OS and applies security patches automatically, the cloud service provider is primarily responsible.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓The customer, because the customer manages the guest operating system and is responsible for patching it.Correct answer▾
Why this is correct
In Azure IaaS, the customer creates and manages the virtual machine, including its guest operating system. Microsoft provides the physical datacenter, host servers, and hypervisor, but does not automatically patch the guest OS. The customer has full administrative access to the VM and is solely responsible for installing security updates, patches, and configuration of the operating system. This is a fundamental tenet of the shared responsibility model for IaaS.
✗Microsoft, because they manage all operating system updates in Azure.Wrong answer — click to see why▾
Why this is wrong here
In an IaaS virtual machine, the customer retains responsibility for the guest OS, including security patches. Microsoft only manages the underlying hypervisor and physical infrastructure, not the OS updates.
★ When this WOULD be the correct answer
If the question specified a PaaS service like Azure App Service or Azure SQL Database, where Microsoft manages the underlying OS and applies patches automatically, then Microsoft would be primarily responsible.
Why candidates choose this
Candidates may mistakenly believe that Microsoft handles all OS updates in Azure, confusing IaaS with PaaS or SaaS, or assume that cloud providers always manage security patching.
✗Both Microsoft and the customer share responsibility equally for operating system patching.Wrong answer — click to see why▾
Why this is wrong here
For an IaaS virtual machine, the customer retains responsibility for the guest OS, including security patches. Microsoft manages the host OS and infrastructure but not the guest OS, so responsibility is not shared equally.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the question specifies a PaaS service, such as Azure App Service, where Microsoft manages the underlying OS and applies patches, but the customer is still responsible for application-level patching, making it a shared responsibility.
Why candidates choose this
Candidates may mistakenly believe that cloud providers handle all patching in IaaS, or they recall the shared responsibility model but incorrectly assume it applies equally to all layers, including the guest OS in IaaS.
✗The cloud service provider, as a general rule for all services in Azure.Wrong answer — click to see why▾
Why this is wrong here
In this specific scenario, the application runs on an IaaS virtual machine, where the customer manages the guest OS. Microsoft is responsible for the physical host and hypervisor, not the guest OS patching.
★ When this WOULD be the correct answer
For a PaaS service like Azure App Service or Azure SQL Database, where Microsoft manages the underlying OS and applies security patches automatically, the cloud service provider is primarily responsible.
Why candidates choose this
Candidates may overgeneralize the shared responsibility model, assuming that because Azure is a cloud platform, Microsoft handles all security updates, ignoring the distinction between IaaS and PaaS.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
The Shared Responsibility Model
Key term
Shared responsibility model
The shared responsibility model is a framework that defines which security and compliance tasks are handled by the cloud provider and which are handled by the customer.
Key term
IaaS
IaaS stands for Infrastructure as a Service, which means renting virtual computing resources like servers, storage, and networking from a cloud provider instead of buying and managing physical hardware yourself.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.