AZ-900 Describe cloud concepts Practice Question
A hospital stores sensitive patient data in the cloud. They want to ensure that data remains secure and that the cloud provider has implemented strict physical security controls, such as biometric access and 24/7 surveillance at datacenters. Which aspect of the shared responsibility model does this describe?
⚠ Common exam trap
Test-takers frequently confuse 'physical security' with 'network security' or 'IAM,' assuming the customer must manage all security layers, but the shared responsibility model explicitly assigns physical controls to the provider.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Responsibility of the cloud provider for physical security
The shared responsibility model delineates that the cloud provider is responsible for the security 'of' the cloud, which includes physical infrastructure controls like biometric access and 24/7 surveillance at datacenters. This question specifically asks about physical security controls, which fall under the provider's domain regardless of the deployment model (IaaS, PaaS, or SaaS). Therefore, option B is correct because the provider must secure the physical premises housing the servers and storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Responsibility of the customer for network security
Why it's wrong here
Network security typically falls on the customer in the form of creating network security groups, configuring firewalls, and managing virtual networks, while the provider secures the underlying network infrastructure. The customer's responsibility here addresses logical traffic flow and filtering, not the physical perimeter of the datacenter. Physical security is a separate, provider-controlled domain that prevents unauthorized individuals from physically accessing networking hardware. Therefore, asking the customer to be responsible for network security does not extend to the building's access controls or environmental protections.
When this WOULD be correct
A question that asks: 'A company wants to ensure that its virtual network in the cloud is protected from unauthorized access. Which aspect of the shared responsibility model does this describe?' In that case, network security is a customer responsibility for virtual networks, making option A correct.
- ✓
Responsibility of the cloud provider for physical security
Why this is correct
In the shared responsibility model, the cloud provider is solely responsible for the physical security of its datacenters, including perimeter fencing, biometric access controls, surveillance cameras, and environmental systems like power and cooling. This responsibility holds regardless of the service model (IaaS, PaaS, or SaaS) because the customer cannot physically access or control the underlying infrastructure. For a hospital storing sensitive patient data, this ensures that the building-level safeguards are handled by the provider, so the customer does not need to worry about physical break-ins or hardware tampering.
- ✗
Responsibility of the customer for data classification
Why it's wrong here
Data classification is a customer responsibility because the hospital must determine which of its data is sensitive (e.g., PHI under HIPAA) and apply appropriate labels and access rules. However, this is an administrative and governance task that operates at the data level, not the physical layer. The provider's physical security would exist even without any customer classification, since it protects all datacenter assets. So while classification is necessary for compliance, it has no bearing on who secures the building and hardware.
When this WOULD be correct
A question asks: 'Who is responsible for labeling patient data as confidential and ensuring appropriate access policies are applied?' In that context, data classification is the customer's responsibility.
- ✗
Responsibility of the customer for identity and access management
Why it's wrong here
Identity and access management (IAM) involves the customer controlling which users and applications can authenticate and authorize access to cloud resources, such as using Azure Active Directory and role-based access control. This is a logical access control mechanism that the customer configures for their own tenant and subscriptions. Physical security, conversely, is about who is allowed into the datacenter itself, which is entirely managed by the provider. For a hospital, IAM remains critical for protecting patient data in the application, but it is distinct from the physical protection of the server racks and network equipment.
When this WOULD be correct
This option would be correct in a scenario where the question asks about who is responsible for managing user identities, enforcing multi-factor authentication, or controlling access to cloud resources, such as 'A company wants to ensure only authorized employees can access its cloud storage. Which responsibility falls on the customer?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Responsibility of the cloud provider for physical securityCorrect answer▾
Why this is correct
In the shared responsibility model, the cloud provider is solely responsible for the physical security of its datacenters, including perimeter fencing, biometric access controls, surveillance cameras, and environmental systems like power and cooling. This responsibility holds regardless of the service model (IaaS, PaaS, or SaaS) because the customer cannot physically access or control the underlying infrastructure. For a hospital storing sensitive patient data, this ensures that the building-level safeguards are handled by the provider, so the customer does not need to worry about physical break-ins or hardware tampering.
✗Responsibility of the customer for network securityWrong answer — click to see why▾
Why this is wrong here
The question specifically asks about physical security controls at datacenters, which are the responsibility of the cloud provider under the shared responsibility model. Network security is a broader category that includes virtual network controls, which may be shared or customer-managed, but physical security is always provider-managed.
★ When this WOULD be the correct answer
A question that asks: 'A company wants to ensure that its virtual network in the cloud is protected from unauthorized access. Which aspect of the shared responsibility model does this describe?' In that case, network security is a customer responsibility for virtual networks, making option A correct.
Why candidates choose this
Candidates may confuse network security with physical security, thinking that the cloud provider handles all security, or they may not distinguish between the layers of the shared responsibility model, leading them to select a provider responsibility for a customer-managed area.
✗Responsibility of the customer for data classificationWrong answer — click to see why▾
Why this is wrong here
Data classification is the customer's responsibility to categorize data based on sensitivity, not the cloud provider's physical security controls like biometric access and surveillance.
★ When this WOULD be the correct answer
A question asks: 'Who is responsible for labeling patient data as confidential and ensuring appropriate access policies are applied?' In that context, data classification is the customer's responsibility.
Why candidates choose this
Candidates may confuse data classification with data security, thinking that classifying data involves implementing security controls, but classification is about labeling, not physical protection.
✗Responsibility of the customer for identity and access managementWrong answer — click to see why▾
Why this is wrong here
The question specifically asks about physical security controls like biometric access and surveillance, which are the cloud provider's responsibility under the shared responsibility model, not the customer's identity and access management.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the question asks about who is responsible for managing user identities, enforcing multi-factor authentication, or controlling access to cloud resources, such as 'A company wants to ensure only authorized employees can access its cloud storage. Which responsibility falls on the customer?'
Why candidates choose this
Candidates may confuse identity and access management with physical security, thinking both involve access control, or they may assume the customer is responsible for all security aspects due to a misunderstanding of the shared responsibility model.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
What is Cloud Computing?
Key term
SaaS
Software as a Service (SaaS) is a cloud computing model where you use software over the internet without installing it on your own computer.
Key term
Shared responsibility model
The shared responsibility model is a framework that defines which security and compliance tasks are handled by the cloud provider and which are handled by the customer.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.