AZ-900 Describe Azure management and governance Practice Question
Which Azure service allows customers to extend Azure management and governance to non-Azure resources, including on-premises servers and other cloud providers?
⚠ Common exam trap
Many exam-takers confuse Azure Arc with Azure Stack Hub, assuming both are for on-premises Azure services, but Arc is about managing existing non-Azure resources while Stack Hub is about running Azure services locally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Arc
Azure Arc is the correct answer because it is specifically designed to extend Azure's management plane and governance policies (such as Azure Policy and Azure RBAC) to resources outside of Azure, including on-premises servers, Kubernetes clusters, and other cloud providers like AWS or GCP. It does this by installing the Azure Connected Machine agent on non-Azure machines, which registers them as Azure resources and enables consistent management through the Azure portal, CLI, and APIs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Stack Hub
Why it's wrong here
Azure Stack Hub is a fully integrated Azure environment that runs on certified, dedicated hardware in your own datacenter, essentially creating a separate Azure endpoint. While it works in disconnected scenarios, it does not manage already-existing external resources; you must deploy workloads on it. Azure Arc requires no special hardware or separate deployment, because a lightweight agent simply connects any existing on-premises or multi-cloud machine to Azure's standard management plane.
- ✓
Azure Arc
Why this is correct
Azure Arc projects non-Azure resources, such as Windows and Linux servers, into Azure Resource Manager by installing the Connected Machine agent, which registers each machine as an Azure resource. Once registered, these resources appear in the Azure portal, can be controlled with Azure Policy, assigned RBAC permissions, and have guest configuration audited from Azure. This enables consistent governance and monitoring across on-premises, multi-cloud, and edge environments without moving workloads or requiring a separate Azure deployment.
- ✗
Azure ExpressRoute
Why it's wrong here
Azure ExpressRoute is a private network connectivity service that links your on-premises network to Microsoft's cloud over a dedicated, high-bandwidth circuit. It provides only Layer 2/Layer 3 data connectivity; it cannot install agents, report resource configuration, or enable Azure management features on non-Azure machines. While ExpressRoute might be used to connect a network physically, Azure Arc is the technology that extends Azure's management plane to resources outside of Azure.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway establishes encrypted network tunnels between on-premises networks and Azure virtual networks, but it is purely a data-path connectivity service. It does not project external servers into Azure Resource Manager, so it cannot provide Azure Policy, RBAC, or centralized inventory for non-Azure resources. Arc, by contrast, installs an agent to register those resources with the Azure control plane.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
Key term
Azure Policy
Azure Policy is a service in Microsoft Azure that lets you create, assign, and manage rules to ensure your resources stay compliant with your company standards and service-level agreements.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.