AZ-900 Describe cloud concepts Practice Question
A retail company is planning to migrate its e-commerce application to Azure. The application will run on an Azure virtual machine that the company will manage. The IT manager wants to ensure that security patches are applied promptly. According to the shared responsibility model, who is responsible for applying security updates to the guest operating system of the Azure virtual machine?
⚠ Common exam trap
Test-takers frequently confuse the hypervisor (managed by Microsoft) with the guest OS (managed by the customer), leading them to incorrectly select option A or C, assuming Microsoft handles all security updates for VMs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer, because the guest operating system is under the customer's control.
In the shared responsibility model, the customer is responsible for securing and patching the guest operating system (OS) of an Azure virtual machine because the customer retains control over the OS, applications, and data. Microsoft manages the underlying hypervisor and physical infrastructure but does not have access to the guest OS. Therefore, the customer must apply security updates to the guest OS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft, because they manage the hypervisor under the virtual machine.
Why it's wrong here
Microsoft is responsible for the physical and virtual hosting infrastructure (including the hypervisor), but the guest operating system running inside the virtual machine is the customer's domain. Patching the guest OS is not a Microsoft responsibility.
When this WOULD be correct
If the question asked about applying security updates to the hypervisor or the physical host, then Microsoft would be responsible, as they manage the underlying infrastructure.
- ✓
The customer, because the guest operating system is under the customer's control.
Why this is correct
In the shared responsibility model, the customer manages the guest OS, applications, and data. Even though the VM runs on Microsoft infrastructure, the customer has full administrative access and must apply updates to the guest OS.
- ✗
Both Microsoft and the customer share responsibility equally for patching the guest operating system.
Why it's wrong here
This statement misrepresents the shared responsibility model. While both parties have security obligations in the cloud, they are not equal or overlapping for a specific resource. For an IaaS virtual machine, Microsoft's responsibility ends at the physical host, network, and hypervisor. Once the guest OS is deployed, its configuration, patching, and maintenance are entirely the customer's duty, not a 50/50 split. Azure offers tools like Update Management to assist with patch orchestration, but assistance does not transfer or share accountability for applying patches.
When this WOULD be correct
This option would be correct if the question asked about a PaaS service like Azure App Service, where Microsoft manages the underlying OS and the customer is responsible only for their application code, making patching a shared responsibility.
- ✗
The customer, but only if they have configured Azure Policy to enforce patch compliance.
Why it's wrong here
Azure Policy can help enforce compliance rules, such as requiring specific patch levels, but it does not change who is responsible for applying the patches. The customer must still perform or schedule the patching regardless of Azure Policy.
When this WOULD be correct
In a scenario where the question asks who is responsible for ensuring that patch compliance policies are enforced (e.g., 'Who is responsible for configuring Azure Policy to enforce patch compliance?'), the customer would be correct because they configure Azure Policy.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓The customer, because the guest operating system is under the customer's control.Correct answer▾
Why this is correct
In the shared responsibility model, the customer manages the guest OS, applications, and data. Even though the VM runs on Microsoft infrastructure, the customer has full administrative access and must apply updates to the guest OS.
✗Microsoft, because they manage the hypervisor under the virtual machine.Wrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, Microsoft is responsible for the hypervisor, not the guest OS. The customer retains responsibility for patching the guest OS because they control it.
★ When this WOULD be the correct answer
If the question asked about applying security updates to the hypervisor or the physical host, then Microsoft would be responsible, as they manage the underlying infrastructure.
Why candidates choose this
Candidates may confuse the hypervisor with the guest OS, assuming that since Microsoft manages the virtual machine platform, they also handle OS patches.
✗Both Microsoft and the customer share responsibility equally for patching the guest operating system.Wrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, the customer is solely responsible for the guest OS, including patching, while Microsoft manages the hypervisor. Shared responsibility for patching the guest OS does not apply; it is not equally shared.
★ When this WOULD be the correct answer
This option would be correct if the question asked about a PaaS service like Azure App Service, where Microsoft manages the underlying OS and the customer is responsible only for their application code, making patching a shared responsibility.
Why candidates choose this
Candidates may think that since Microsoft manages the infrastructure, they share responsibility for all security updates, but the model clearly assigns guest OS patching to the customer for IaaS VMs.
✗The customer, but only if they have configured Azure Policy to enforce patch compliance.Wrong answer — click to see why▾
Why this is wrong here
Azure Policy enforces compliance rules but does not apply security patches; patching the guest OS is the customer's responsibility regardless of Azure Policy configuration.
★ When this WOULD be the correct answer
In a scenario where the question asks who is responsible for ensuring that patch compliance policies are enforced (e.g., 'Who is responsible for configuring Azure Policy to enforce patch compliance?'), the customer would be correct because they configure Azure Policy.
Why candidates choose this
Candidates may think that using Azure Policy automates patching, confusing policy enforcement with actual patch application, or believe that Microsoft handles patching if policies are in place.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
The Shared Responsibility Model
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Shared responsibility model
The shared responsibility model is a framework that defines which security and compliance tasks are handled by the cloud provider and which are handled by the customer.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.