Courseiva
Describe cloud conceptseasyMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

A hospital stores sensitive patient data in the cloud. They want to ensure that data remains secure and that the cloud provider has implemented strict physical security controls, such as biometric access and 24/7 surveillance at datacenters. Which aspect of the shared responsibility model does this describe?

⚠ Common exam trap

Test-takers frequently confuse 'physical security' with 'network security' or 'IAM,' assuming the customer must manage all security layers, but the shared responsibility model explicitly assigns physical controls to the provider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Responsibility of the cloud provider for physical security

The shared responsibility model delineates that the cloud provider is responsible for the security 'of' the cloud, which includes physical infrastructure controls like biometric access and 24/7 surveillance at datacenters. This question specifically asks about physical security controls, which fall under the provider's domain regardless of the deployment model (IaaS, PaaS, or SaaS). Therefore, option B is correct because the provider must secure the physical premises housing the servers and storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Responsibility of the customer for network security

    Why it's wrong here

    Network security typically falls on the customer in the form of creating network security groups, configuring firewalls, and managing virtual networks, while the provider secures the underlying network infrastructure. The customer's responsibility here addresses logical traffic flow and filtering, not the physical perimeter of the datacenter. Physical security is a separate, provider-controlled domain that prevents unauthorized individuals from physically accessing networking hardware. Therefore, asking the customer to be responsible for network security does not extend to the building's access controls or environmental protections.

    When this WOULD be correct

    A question that asks: 'A company wants to ensure that its virtual network in the cloud is protected from unauthorized access. Which aspect of the shared responsibility model does this describe?' In that case, network security is a customer responsibility for virtual networks, making option A correct.

  • Responsibility of the cloud provider for physical security

    Why this is correct

    In the shared responsibility model, the cloud provider is solely responsible for the physical security of its datacenters, including perimeter fencing, biometric access controls, surveillance cameras, and environmental systems like power and cooling. This responsibility holds regardless of the service model (IaaS, PaaS, or SaaS) because the customer cannot physically access or control the underlying infrastructure. For a hospital storing sensitive patient data, this ensures that the building-level safeguards are handled by the provider, so the customer does not need to worry about physical break-ins or hardware tampering.

  • Responsibility of the customer for data classification

    Why it's wrong here

    Data classification is a customer responsibility because the hospital must determine which of its data is sensitive (e.g., PHI under HIPAA) and apply appropriate labels and access rules. However, this is an administrative and governance task that operates at the data level, not the physical layer. The provider's physical security would exist even without any customer classification, since it protects all datacenter assets. So while classification is necessary for compliance, it has no bearing on who secures the building and hardware.

    When this WOULD be correct

    A question asks: 'Who is responsible for labeling patient data as confidential and ensuring appropriate access policies are applied?' In that context, data classification is the customer's responsibility.

  • Responsibility of the customer for identity and access management

    Why it's wrong here

    Identity and access management (IAM) involves the customer controlling which users and applications can authenticate and authorize access to cloud resources, such as using Azure Active Directory and role-based access control. This is a logical access control mechanism that the customer configures for their own tenant and subscriptions. Physical security, conversely, is about who is allowed into the datacenter itself, which is entirely managed by the provider. For a hospital, IAM remains critical for protecting patient data in the application, but it is distinct from the physical protection of the server racks and network equipment.

    When this WOULD be correct

    This option would be correct in a scenario where the question asks about who is responsible for managing user identities, enforcing multi-factor authentication, or controlling access to cloud resources, such as 'A company wants to ensure only authorized employees can access its cloud storage. Which responsibility falls on the customer?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

Responsibility of the cloud provider for physical securityCorrect answer

Why this is correct

In the shared responsibility model, the cloud provider is solely responsible for the physical security of its datacenters, including perimeter fencing, biometric access controls, surveillance cameras, and environmental systems like power and cooling. This responsibility holds regardless of the service model (IaaS, PaaS, or SaaS) because the customer cannot physically access or control the underlying infrastructure. For a hospital storing sensitive patient data, this ensures that the building-level safeguards are handled by the provider, so the customer does not need to worry about physical break-ins or hardware tampering.

Responsibility of the customer for network securityWrong answer — click to see why

Why this is wrong here

The question specifically asks about physical security controls at datacenters, which are the responsibility of the cloud provider under the shared responsibility model. Network security is a broader category that includes virtual network controls, which may be shared or customer-managed, but physical security is always provider-managed.

★ When this WOULD be the correct answer

A question that asks: 'A company wants to ensure that its virtual network in the cloud is protected from unauthorized access. Which aspect of the shared responsibility model does this describe?' In that case, network security is a customer responsibility for virtual networks, making option A correct.

Why candidates choose this

Candidates may confuse network security with physical security, thinking that the cloud provider handles all security, or they may not distinguish between the layers of the shared responsibility model, leading them to select a provider responsibility for a customer-managed area.

Responsibility of the customer for data classificationWrong answer — click to see why

Why this is wrong here

Data classification is the customer's responsibility to categorize data based on sensitivity, not the cloud provider's physical security controls like biometric access and surveillance.

★ When this WOULD be the correct answer

A question asks: 'Who is responsible for labeling patient data as confidential and ensuring appropriate access policies are applied?' In that context, data classification is the customer's responsibility.

Why candidates choose this

Candidates may confuse data classification with data security, thinking that classifying data involves implementing security controls, but classification is about labeling, not physical protection.

Responsibility of the customer for identity and access managementWrong answer — click to see why

Why this is wrong here

The question specifically asks about physical security controls like biometric access and surveillance, which are the cloud provider's responsibility under the shared responsibility model, not the customer's identity and access management.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the question asks about who is responsible for managing user identities, enforcing multi-factor authentication, or controlling access to cloud resources, such as 'A company wants to ensure only authorized employees can access its cloud storage. Which responsibility falls on the customer?'

Why candidates choose this

Candidates may confuse identity and access management with physical security, thinking both involve access control, or they may assume the customer is responsible for all security aspects due to a misunderstanding of the shared responsibility model.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.