AZ-900 Describe cloud concepts Practice Question
A company subscribes to a SaaS-based customer relationship management (CRM) application hosted in the cloud. The CRM provider manages the application, runtime, and infrastructure. The company's employees access the CRM via a web browser. According to the shared responsibility model, which security responsibility belongs solely to the company?
⚠ Common exam trap
Many exam-takers confuse 'managing network access controls' (Option B) as solely the customer's responsibility, but in SaaS, the provider manages the underlying network infrastructure, and the customer only controls application-level access policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safeguarding the company's customer data and user identities.
In a SaaS model, the provider manages the application, runtime, and infrastructure, including patching the OS and physical security. The customer retains responsibility for what they bring into the cloud: their data and user identities. Option C is correct because safeguarding customer data and managing user identities (e.g., via Azure AD) is solely the company's responsibility under the shared responsibility model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patching the underlying operating system of the CRM servers.
Why it's wrong here
Patching the underlying operating system of the CRM servers is a provider responsibility in the SaaS model. The customer never has direct access or administrative control over the virtual machines or hosts that run the CRM application, so they cannot apply OS-level patches. The cloud provider automatically updates and secures the operating system and related infrastructure components as part of the managed service. Therefore, this is not a customer obligation.
When this WOULD be correct
In an IaaS scenario where the customer manages virtual machines, patching the guest OS is the customer's responsibility.
- ✗
Managing network access controls to the CRM application.
Why it's wrong here
Managing network access controls to the CRM application at the infrastructure level, such as firewalls, network segmentation, and DDoS protection, is handled by the SaaS provider. The customer may configure application-specific access policies like user roles or IP allowlists within the CRM interface, but they do not manage the underlying network layer. The provider secures the network fabric that delivers the application, making this a provider responsibility rather than a customer one.
When this WOULD be correct
In an IaaS scenario where the company manages virtual networks, such as deploying a virtual machine in Azure and needing to configure network security groups (NSGs) to control inbound/outbound traffic. The question would specify that the company is responsible for network configuration.
- ✓
Safeguarding the company's customer data and user identities.
Why this is correct
The customer is always responsible for their own data, including data classification, encryption, and access management. In SaaS, the provider does not have insight into which users should have access; the customer must manage identities and protect data.
- ✗
Ensuring physical security of the data centers hosting the CRM.
Why it's wrong here
Ensuring physical security of the data centers hosting the CRM is exclusively the cloud provider's responsibility in every service model. This includes guarding the facilities, controlling physical entry, monitoring environmental conditions, and managing hardware lifecycle. A SaaS customer never has physical access to the data center and cannot influence or manage those controls. Thus, it is definitively not a customer task.
When this WOULD be correct
In an IaaS scenario where the customer manages the virtual machines and data center access, ensuring physical security of the data centers would be the customer's responsibility if they operate their own on-premises infrastructure or have colocation arrangements.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Safeguarding the company's customer data and user identities.Correct answer▾
Why this is correct
The customer is always responsible for their own data, including data classification, encryption, and access management. In SaaS, the provider does not have insight into which users should have access; the customer must manage identities and protect data.
✗Patching the underlying operating system of the CRM servers.Wrong answer — click to see why▾
Why this is wrong here
In a SaaS model, the provider is responsible for patching the underlying OS; the customer has no access or control over the server OS.
★ When this WOULD be the correct answer
In an IaaS scenario where the customer manages virtual machines, patching the guest OS is the customer's responsibility.
Why candidates choose this
Candidates may confuse SaaS with IaaS or PaaS, assuming OS patching is always a customer task.
✗Managing network access controls to the CRM application.Wrong answer — click to see why▾
Why this is wrong here
In a SaaS model, the provider manages network access controls to the application, including firewalls and network security groups. The company's responsibility is limited to user access and data security, not network-level controls.
★ When this WOULD be the correct answer
In an IaaS scenario where the company manages virtual networks, such as deploying a virtual machine in Azure and needing to configure network security groups (NSGs) to control inbound/outbound traffic. The question would specify that the company is responsible for network configuration.
Why candidates choose this
Candidates may confuse network access controls with user access controls, or assume that since employees access the CRM via a browser, the company must manage network security. They overlook that in SaaS, the provider handles the underlying network infrastructure.
✗Ensuring physical security of the data centers hosting the CRM.Wrong answer — click to see why▾
Why this is wrong here
In a SaaS model, the provider is responsible for physical security of data centers, not the customer. The shared responsibility model assigns physical security to the cloud provider.
★ When this WOULD be the correct answer
In an IaaS scenario where the customer manages the virtual machines and data center access, ensuring physical security of the data centers would be the customer's responsibility if they operate their own on-premises infrastructure or have colocation arrangements.
Why candidates choose this
Candidates may confuse the shared responsibility model across different service models (IaaS, PaaS, SaaS) and incorrectly assume the customer is always responsible for physical security, or they may overestimate the customer's responsibilities in SaaS.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
What is Cloud Computing?
Key term
Shared responsibility model
The shared responsibility model is a framework that defines which security and compliance tasks are handled by the cloud provider and which are handled by the customer.
Key term
SaaS
Software as a Service (SaaS) is a cloud computing model where you use software over the internet without installing it on your own computer.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.