AZ-900 Describe cloud concepts Practice Question
A financial services company is evaluating a public cloud provider. They are concerned about the shared responsibility model for security. The company must ensure that their customer data is encrypted at rest and in transit. Under the shared responsibility model, which security control is the cloud provider typically responsible for?
⚠ Common exam trap
Many exam-takers confuse 'encryption at rest' (which is a shared or customer responsibility depending on key management) with physical security, leading them to choose A, but the provider's inherent responsibility is always the physical infrastructure, not the customer's data encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Physical network security
Under the shared responsibility model, the cloud provider is responsible for the security OF the cloud, which includes physical network security such as protecting the data center perimeter, network infrastructure, and hardware. This is correct because physical security controls (e.g., access badges, surveillance, and network firewalls at the provider's edge) are entirely the provider's domain and cannot be delegated to the customer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypting customer data at rest
Why it's wrong here
Encrypting customer data at rest is the customer's responsibility to configure and manage, even though Azure provides encryption by default at the storage platform level. The customer must enable and control encryption options such as Azure Disk Encryption, customer-managed keys in Azure Key Vault, or adjust storage service encryption settings. Microsoft may offer platform-managed keys, but the customer is responsible for choosing, configuring, and managing the encryption approach and key lifecycle for their data.
When this WOULD be correct
In a scenario where the cloud provider offers a managed encryption service (e.g., Azure Storage Service Encryption) that automatically encrypts data at rest, and the question asks which security control the provider is responsible for when using that service, then encrypting customer data at rest could be correct.
- ✗
Patching virtual machines
Why it's wrong here
Patching virtual machines is the customer's responsibility in an IaaS deployment because the customer maintains the guest operating system and applications running inside the VM. Microsoft patches the physical host and hypervisor, but the customer must apply OS and application updates to the VM itself, unless they implement Azure Automation Update Management or similar. Therefore, patching VMs is not a provider-managed security control.
When this WOULD be correct
For a question about the cloud provider's responsibility in a Platform as a Service (PaaS) model, where the provider manages the underlying OS and runtime, patching VMs would be the provider's responsibility. Example: 'Which task is the cloud provider responsible for in a PaaS deployment?'
- ✓
Physical network security
Why this is correct
Physical network security is the provider's responsibility because the cloud provider operates and controls the physical data center infrastructure. This includes securing the facility, cabling, switches, routers, and firewalls against physical tampering, environmental threats, and unauthorized access. The customer has no visibility or control over these physical layers, so under the shared responsibility model this falls entirely on Microsoft.
- ✗
Managing customer access policies
Why it's wrong here
Managing customer access policies is the customer's responsibility because they own their identity and access management. The customer uses Azure AD and RBAC to define who can sign in, which roles they hold, and what resources they can access. Microsoft provides the identity platform but does not decide or enforce the customer's specific access rules, so this is a customer-side control.
When this WOULD be correct
This option would be correct in a question asking: 'Which security control is the customer responsible for under the shared responsibility model?' or 'Which of the following is a customer's responsibility to manage?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Physical network securityCorrect answer▾
Why this is correct
Physical network security is the provider's responsibility because the cloud provider operates and controls the physical data center infrastructure. This includes securing the facility, cabling, switches, routers, and firewalls against physical tampering, environmental threats, and unauthorized access. The customer has no visibility or control over these physical layers, so under the shared responsibility model this falls entirely on Microsoft.
✗Encrypting customer data at restWrong answer — click to see why▾
Why this is wrong here
Under the shared responsibility model, encrypting customer data at rest is typically the customer's responsibility, not the cloud provider's, because the customer controls the data and encryption keys.
★ When this WOULD be the correct answer
In a scenario where the cloud provider offers a managed encryption service (e.g., Azure Storage Service Encryption) that automatically encrypts data at rest, and the question asks which security control the provider is responsible for when using that service, then encrypting customer data at rest could be correct.
Why candidates choose this
Candidates often assume that since the cloud provider manages the infrastructure, they also handle all encryption, but the shared responsibility model clearly divides duties: the provider secures the physical layer, while the customer secures data and access.
✗Patching virtual machinesWrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, patching virtual machines is typically the customer's responsibility, not the cloud provider's. The provider secures the physical infrastructure, but customers must manage OS and application patches on their VMs.
★ When this WOULD be the correct answer
For a question about the cloud provider's responsibility in a Platform as a Service (PaaS) model, where the provider manages the underlying OS and runtime, patching VMs would be the provider's responsibility. Example: 'Which task is the cloud provider responsible for in a PaaS deployment?'
Why candidates choose this
Candidates may confuse the shared responsibility model, assuming the provider handles all security patches, or they may think of IaaS where patching is shared, but forget that VMs are customer-managed.
✗Managing customer access policiesWrong answer — click to see why▾
Why this is wrong here
Managing customer access policies is the customer's responsibility under the shared responsibility model, not the cloud provider's. The provider is responsible for the security of the cloud, while customers manage access to their own data and resources.
★ When this WOULD be the correct answer
This option would be correct in a question asking: 'Which security control is the customer responsible for under the shared responsibility model?' or 'Which of the following is a customer's responsibility to manage?'
Why candidates choose this
Candidates may confuse the division of responsibilities, assuming the provider handles all security controls including access policies, or they may misinterpret 'managing' as provider-level identity and access management infrastructure.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
What is Cloud Computing?
Key term
Public cloud
A public cloud is a computing model where third-party providers deliver IT resources like servers, storage, and applications over the internet to multiple customers on a pay-as-you-go basis.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.