Courseiva
Describe cloud conceptsmediumMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

Which of the following best describes the 'shared responsibility' for operating system updates under the IaaS model?

⚠ Common exam trap

It's easy for candidates to assume the cloud provider handles all security updates, confusing IaaS with PaaS or SaaS where the provider does manage the OS, leading them to incorrectly select option A or D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The customer is responsible for patching the guest OS in IaaS VMs

Under the Infrastructure as a Service (IaaS) model, the cloud provider is responsible for the physical infrastructure and the hypervisor, but the customer retains control over the guest operating system running inside the virtual machine. Therefore, the customer is responsible for patching and updating the guest OS, including applying security updates and managing configuration. This aligns with the shared responsibility model where the customer manages anything they deploy on top of the abstracted infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The cloud provider is responsible for patching the OS in IaaS VMs

    Why it's wrong here

    Under the shared responsibility model for IaaS, the cloud provider's security obligations stop at the virtualization boundary. Azure manages the hypervisor, hardware, and network infrastructure, but does not patch the guest OS running inside a customer's VM. Therefore, claiming the provider handles OS patching for IaaS mistakenly transfers an obligation that remains firmly with the customer.

  • The customer is responsible for patching the guest OS in IaaS VMs

    Why this is correct

    When deploying an IaaS VM, Azure provides the virtual machine with a preconfigured operating system, but the customer takes on administration duties, including patch management. The customer must regularly update the guest OS with security patches and hotfixes to protect applications and data. Azure's responsibility extends only to the physical host and hypervisor, not to the operating system inside the VM.

  • Both customer and provider share equal responsibility for OS patches in IaaS

    Why it's wrong here

    In the shared responsibility model, Azure's responsibilities are limited to the physical datacenter, network, and hypervisor. The customer, however, retains full control over the guest OS, making OS patching entirely their obligation, not a 50/50 arrangement. Any suggestion of equal shared patching conflates IaaS with PaaS or SaaS, where the platform provider handles more of the stack.

  • OS patching is not required in cloud environments as Azure handles this automatically

    Why it's wrong here

    This statement falsely implies patches are unnecessary because Azure automatically secures all cloud workloads. In reality, Azure only applies automatic OS updates to platform-managed services like PaaS or SaaS offerings. For IaaS VMs, the customer is fully accountable for evaluating, approving, and applying guest OS patches, so patching remains mandatory.

About these practice questions

This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.