AZ-900 Describe cloud concepts Practice Question
A hospital stores patient data in the cloud. They are concerned about physical security at the datacenter. Which aspect of the shared responsibility model describes the cloud provider's obligation to secure the physical infrastructure?
⚠ Common exam trap
Many exam-takers confuse 'security of the network infrastructure' (which is partially shared) with 'physical security of the datacenter' (which is solely the provider's responsibility), leading them to incorrectly select Option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security of physical hardware
In the shared responsibility model, the cloud provider is always responsible for the physical security of the datacenter, including the physical hardware, environmental controls (power, cooling), and physical access controls. This is a foundational principle of the model: the provider secures the physical layer, while the customer secures what they deploy on top of it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security of the network infrastructure
Why it's wrong here
Security of the network infrastructure is partially a provider obligation, but it is a logical and physical hybrid, not solely physical hardware. The provider handles the physical network fabric, DDoS protections, and edge routing, but customers must secure network-level configurations such as Network Security Groups, user-defined routes, firewalls, and VPN gateways. Since the hospital's specific concern is physical hardware, this option misses the stricter physical-layer boundary that the provider exclusively controls. Thus it is an incorrect answer because the network infrastructure is broader than just physical hardware.
When this WOULD be correct
In a scenario where the question asks about the cloud provider's responsibility for securing the network layer (e.g., 'Which aspect of the shared responsibility model covers protection against DDoS attacks on the provider's backbone?'), then 'Security of the network infrastructure' would be correct.
- ✓
Security of physical hardware
Why this is correct
In the shared responsibility model, the cloud provider owns and secures the entire physical infrastructure stack: datacenter buildings, servers, storage devices, network switches, power systems, and hardware firmware. This includes physical access controls (badge/biometric gates), video surveillance, security guards, and secure disposal/decommissioning processes. Customers have no physical access to or management control over these assets, so any concern about physical hardware security falls entirely on the provider, especially in IaaS and PaaS scenarios.
- ✗
Security of customer data
Why it's wrong here
Security of customer data is the customer's responsibility across all cloud services, even though the provider supplies the underlying platform. The customer must classify data, apply encryption in transit and at rest (often using customer-managed keys), and enforce identity-based access via Azure Active Directory and role-based access control. In PaaS or SaaS, the provider may offer tools like Azure Information Protection, but the customer must configure and govern them. This option is wrong because it addresses logical data security, not the physical hardware the hospital is worried about.
When this WOULD be correct
This option would be correct if the question asked: 'Which aspect of the shared responsibility model describes the customer's obligation to protect their own information stored in the cloud?'
- ✗
Security of operating systems
Why it's wrong here
The security of operating systems is not a single-sided responsibility; it depends on the service model. Under IaaS, customers must patch, harden, and monitor the OS on their VMs, while in PaaS the provider patches the underlying OS, and in SaaS customers manage only data and access. Physical hardware security, however, is always the provider's duty, irrespective of the OS layer. This option is wrong because OS security can involve the customer, whereas physical hardware is unequivocally provider-managed, so it cannot be the correct answer.
When this WOULD be correct
This option would be correct in a question asking: 'Who is responsible for patching and securing the operating system on a virtual machine deployed in IaaS?' In that scenario, the customer manages the OS security.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Security of physical hardwareCorrect answer▾
Why this is correct
In the shared responsibility model, the cloud provider owns and secures the entire physical infrastructure stack: datacenter buildings, servers, storage devices, network switches, power systems, and hardware firmware. This includes physical access controls (badge/biometric gates), video surveillance, security guards, and secure disposal/decommissioning processes. Customers have no physical access to or management control over these assets, so any concern about physical hardware security falls entirely on the provider, especially in IaaS and PaaS scenarios.
✗Security of the network infrastructureWrong answer — click to see why▾
Why this is wrong here
The question specifically asks about physical security at the datacenter, which includes hardware, facilities, and environmental controls. Network infrastructure security is a logical component that may be shared or customer-managed, but it is not the primary focus of physical datacenter security.
★ When this WOULD be the correct answer
In a scenario where the question asks about the cloud provider's responsibility for securing the network layer (e.g., 'Which aspect of the shared responsibility model covers protection against DDoS attacks on the provider's backbone?'), then 'Security of the network infrastructure' would be correct.
Why candidates choose this
Candidates may confuse 'physical security' with 'network security' because both are foundational to cloud security, and they might think the provider secures all infrastructure, including networks, without distinguishing between physical and logical layers.
✗Security of customer dataWrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, the cloud provider is responsible for the security 'of' the cloud, including physical hardware, while the customer is responsible for security 'in' the cloud, such as customer data. Thus, securing customer data is the customer's obligation, not the provider's.
★ When this WOULD be the correct answer
This option would be correct if the question asked: 'Which aspect of the shared responsibility model describes the customer's obligation to protect their own information stored in the cloud?'
Why candidates choose this
Candidates may confuse the provider's responsibility for physical infrastructure with data protection, mistakenly thinking the provider secures all data, including customer-managed content.
✗Security of operating systemsWrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, the customer is responsible for securing the operating systems they deploy, not the cloud provider. The question specifically asks about physical infrastructure security, which is the provider's obligation.
★ When this WOULD be the correct answer
This option would be correct in a question asking: 'Who is responsible for patching and securing the operating system on a virtual machine deployed in IaaS?' In that scenario, the customer manages the OS security.
Why candidates choose this
Candidates may confuse the provider's responsibility for the physical datacenter with the provider's responsibility for the underlying OS, or they may think the provider secures all layers including the OS.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
What is Cloud Computing?
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.