Courseiva
Describe cloud conceptsmediumMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

A retail company is planning to migrate its e-commerce application to Azure. The application will run on an Azure virtual machine that the company will manage. The IT manager wants to ensure that security patches are applied promptly. According to the shared responsibility model, who is responsible for applying security updates to the guest operating system of the Azure virtual machine?

⚠ Common exam trap

Test-takers frequently confuse the hypervisor (managed by Microsoft) with the guest OS (managed by the customer), leading them to incorrectly select option A or C, assuming Microsoft handles all security updates for VMs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The customer, because the guest operating system is under the customer's control.

In the shared responsibility model, the customer is responsible for securing and patching the guest operating system (OS) of an Azure virtual machine because the customer retains control over the OS, applications, and data. Microsoft manages the underlying hypervisor and physical infrastructure but does not have access to the guest OS. Therefore, the customer must apply security updates to the guest OS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft, because they manage the hypervisor under the virtual machine.

    Why it's wrong here

    Microsoft is responsible for the physical and virtual hosting infrastructure (including the hypervisor), but the guest operating system running inside the virtual machine is the customer's domain. Patching the guest OS is not a Microsoft responsibility.

    When this WOULD be correct

    If the question asked about applying security updates to the hypervisor or the physical host, then Microsoft would be responsible, as they manage the underlying infrastructure.

  • The customer, because the guest operating system is under the customer's control.

    Why this is correct

    In the shared responsibility model, the customer manages the guest OS, applications, and data. Even though the VM runs on Microsoft infrastructure, the customer has full administrative access and must apply updates to the guest OS.

  • Both Microsoft and the customer share responsibility equally for patching the guest operating system.

    Why it's wrong here

    This statement misrepresents the shared responsibility model. While both parties have security obligations in the cloud, they are not equal or overlapping for a specific resource. For an IaaS virtual machine, Microsoft's responsibility ends at the physical host, network, and hypervisor. Once the guest OS is deployed, its configuration, patching, and maintenance are entirely the customer's duty, not a 50/50 split. Azure offers tools like Update Management to assist with patch orchestration, but assistance does not transfer or share accountability for applying patches.

    When this WOULD be correct

    This option would be correct if the question asked about a PaaS service like Azure App Service, where Microsoft manages the underlying OS and the customer is responsible only for their application code, making patching a shared responsibility.

  • The customer, but only if they have configured Azure Policy to enforce patch compliance.

    Why it's wrong here

    Azure Policy can help enforce compliance rules, such as requiring specific patch levels, but it does not change who is responsible for applying the patches. The customer must still perform or schedule the patching regardless of Azure Policy.

    When this WOULD be correct

    In a scenario where the question asks who is responsible for ensuring that patch compliance policies are enforced (e.g., 'Who is responsible for configuring Azure Policy to enforce patch compliance?'), the customer would be correct because they configure Azure Policy.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

The customer, because the guest operating system is under the customer's control.Correct answer

Why this is correct

In the shared responsibility model, the customer manages the guest OS, applications, and data. Even though the VM runs on Microsoft infrastructure, the customer has full administrative access and must apply updates to the guest OS.

Microsoft, because they manage the hypervisor under the virtual machine.Wrong answer — click to see why

Why this is wrong here

In the shared responsibility model, Microsoft is responsible for the hypervisor, not the guest OS. The customer retains responsibility for patching the guest OS because they control it.

★ When this WOULD be the correct answer

If the question asked about applying security updates to the hypervisor or the physical host, then Microsoft would be responsible, as they manage the underlying infrastructure.

Why candidates choose this

Candidates may confuse the hypervisor with the guest OS, assuming that since Microsoft manages the virtual machine platform, they also handle OS patches.

Both Microsoft and the customer share responsibility equally for patching the guest operating system.Wrong answer — click to see why

Why this is wrong here

In the shared responsibility model, the customer is solely responsible for the guest OS, including patching, while Microsoft manages the hypervisor. Shared responsibility for patching the guest OS does not apply; it is not equally shared.

★ When this WOULD be the correct answer

This option would be correct if the question asked about a PaaS service like Azure App Service, where Microsoft manages the underlying OS and the customer is responsible only for their application code, making patching a shared responsibility.

Why candidates choose this

Candidates may think that since Microsoft manages the infrastructure, they share responsibility for all security updates, but the model clearly assigns guest OS patching to the customer for IaaS VMs.

The customer, but only if they have configured Azure Policy to enforce patch compliance.Wrong answer — click to see why

Why this is wrong here

Azure Policy enforces compliance rules but does not apply security patches; patching the guest OS is the customer's responsibility regardless of Azure Policy configuration.

★ When this WOULD be the correct answer

In a scenario where the question asks who is responsible for ensuring that patch compliance policies are enforced (e.g., 'Who is responsible for configuring Azure Policy to enforce patch compliance?'), the customer would be correct because they configure Azure Policy.

Why candidates choose this

Candidates may think that using Azure Policy automates patching, confusing policy enforcement with actual patch application, or believe that Microsoft handles patching if policies are in place.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.