Courseiva
Describe cloud conceptsmediumMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

A hospital stores patient data in the cloud. They are concerned about physical security at the datacenter. Which aspect of the shared responsibility model describes the cloud provider's obligation to secure the physical infrastructure?

⚠ Common exam trap

Many exam-takers confuse 'security of the network infrastructure' (which is partially shared) with 'physical security of the datacenter' (which is solely the provider's responsibility), leading them to incorrectly select Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security of physical hardware

In the shared responsibility model, the cloud provider is always responsible for the physical security of the datacenter, including the physical hardware, environmental controls (power, cooling), and physical access controls. This is a foundational principle of the model: the provider secures the physical layer, while the customer secures what they deploy on top of it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Security of the network infrastructure

    Why it's wrong here

    Security of the network infrastructure is partially a provider obligation, but it is a logical and physical hybrid, not solely physical hardware. The provider handles the physical network fabric, DDoS protections, and edge routing, but customers must secure network-level configurations such as Network Security Groups, user-defined routes, firewalls, and VPN gateways. Since the hospital's specific concern is physical hardware, this option misses the stricter physical-layer boundary that the provider exclusively controls. Thus it is an incorrect answer because the network infrastructure is broader than just physical hardware.

    When this WOULD be correct

    In a scenario where the question asks about the cloud provider's responsibility for securing the network layer (e.g., 'Which aspect of the shared responsibility model covers protection against DDoS attacks on the provider's backbone?'), then 'Security of the network infrastructure' would be correct.

  • Security of physical hardware

    Why this is correct

    In the shared responsibility model, the cloud provider owns and secures the entire physical infrastructure stack: datacenter buildings, servers, storage devices, network switches, power systems, and hardware firmware. This includes physical access controls (badge/biometric gates), video surveillance, security guards, and secure disposal/decommissioning processes. Customers have no physical access to or management control over these assets, so any concern about physical hardware security falls entirely on the provider, especially in IaaS and PaaS scenarios.

  • Security of customer data

    Why it's wrong here

    Security of customer data is the customer's responsibility across all cloud services, even though the provider supplies the underlying platform. The customer must classify data, apply encryption in transit and at rest (often using customer-managed keys), and enforce identity-based access via Azure Active Directory and role-based access control. In PaaS or SaaS, the provider may offer tools like Azure Information Protection, but the customer must configure and govern them. This option is wrong because it addresses logical data security, not the physical hardware the hospital is worried about.

    When this WOULD be correct

    This option would be correct if the question asked: 'Which aspect of the shared responsibility model describes the customer's obligation to protect their own information stored in the cloud?'

  • Security of operating systems

    Why it's wrong here

    The security of operating systems is not a single-sided responsibility; it depends on the service model. Under IaaS, customers must patch, harden, and monitor the OS on their VMs, while in PaaS the provider patches the underlying OS, and in SaaS customers manage only data and access. Physical hardware security, however, is always the provider's duty, irrespective of the OS layer. This option is wrong because OS security can involve the customer, whereas physical hardware is unequivocally provider-managed, so it cannot be the correct answer.

    When this WOULD be correct

    This option would be correct in a question asking: 'Who is responsible for patching and securing the operating system on a virtual machine deployed in IaaS?' In that scenario, the customer manages the OS security.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

Security of physical hardwareCorrect answer

Why this is correct

In the shared responsibility model, the cloud provider owns and secures the entire physical infrastructure stack: datacenter buildings, servers, storage devices, network switches, power systems, and hardware firmware. This includes physical access controls (badge/biometric gates), video surveillance, security guards, and secure disposal/decommissioning processes. Customers have no physical access to or management control over these assets, so any concern about physical hardware security falls entirely on the provider, especially in IaaS and PaaS scenarios.

Security of the network infrastructureWrong answer — click to see why

Why this is wrong here

The question specifically asks about physical security at the datacenter, which includes hardware, facilities, and environmental controls. Network infrastructure security is a logical component that may be shared or customer-managed, but it is not the primary focus of physical datacenter security.

★ When this WOULD be the correct answer

In a scenario where the question asks about the cloud provider's responsibility for securing the network layer (e.g., 'Which aspect of the shared responsibility model covers protection against DDoS attacks on the provider's backbone?'), then 'Security of the network infrastructure' would be correct.

Why candidates choose this

Candidates may confuse 'physical security' with 'network security' because both are foundational to cloud security, and they might think the provider secures all infrastructure, including networks, without distinguishing between physical and logical layers.

Security of customer dataWrong answer — click to see why

Why this is wrong here

In the shared responsibility model, the cloud provider is responsible for the security 'of' the cloud, including physical hardware, while the customer is responsible for security 'in' the cloud, such as customer data. Thus, securing customer data is the customer's obligation, not the provider's.

★ When this WOULD be the correct answer

This option would be correct if the question asked: 'Which aspect of the shared responsibility model describes the customer's obligation to protect their own information stored in the cloud?'

Why candidates choose this

Candidates may confuse the provider's responsibility for physical infrastructure with data protection, mistakenly thinking the provider secures all data, including customer-managed content.

Security of operating systemsWrong answer — click to see why

Why this is wrong here

In the shared responsibility model, the customer is responsible for securing the operating systems they deploy, not the cloud provider. The question specifically asks about physical infrastructure security, which is the provider's obligation.

★ When this WOULD be the correct answer

This option would be correct in a question asking: 'Who is responsible for patching and securing the operating system on a virtual machine deployed in IaaS?' In that scenario, the customer manages the OS security.

Why candidates choose this

Candidates may confuse the provider's responsibility for the physical datacenter with the provider's responsibility for the underlying OS, or they may think the provider secures all layers including the OS.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.