Courseiva
Question 665 of 981
Describe cloud conceptseasyMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

What is the role of a cloud provider's physical datacenter security in the shared responsibility model?

⚠ Common exam trap

The trap here is that candidates mistakenly think physical security is shared or customer-managed in IaaS, confusing the customer's responsibility for virtual infrastructure (e.g., VMs, OS) with the provider's responsibility for the physical datacenter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Physical security is entirely the cloud provider's responsibility

In the shared responsibility model, physical security of the datacenter—including access controls, surveillance, and environmental controls—is always the sole responsibility of the cloud provider (e.g., Microsoft Azure). The customer never manages or is responsible for the physical infrastructure, regardless of the service model (IaaS, PaaS, SaaS). This is because the customer has no physical access to the datacenter and cannot implement or control physical security measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Both the cloud provider and customer share responsibility for physical security

    Why it's wrong here

    This option incorrectly suggests that physical security is part of the shared responsibility model's split between provider and customer. In actuality, physical security controls—such as building perimeter defenses, server room access, surveillance, and hardware disposition—are exclusively managed by the cloud provider, and customers are never granted physical access to the infrastructure. The customer's shared duties begin at the virtualization layer (for IaaS) or higher, never extending down to the datacenter's physical environment.

  • Physical security is entirely the cloud provider's responsibility

    Why this is correct

    Across every cloud service model—IaaS, PaaS, and SaaS—the cloud provider is solely responsible for physical security of the data center. This includes protecting the facilities with biometric access controls, multi-factor authentication for entry, continuous video monitoring, and physically securing server racks and hardware. Customers interact only with logical resources through the cloud interface, never with the physical hardware or facilities, so responsibility for physical security cannot be transferred or shared.

  • Customers are responsible for physical security when using IaaS

    Why it's wrong here

    While IaaS customers are responsible for securing the operating system, applications, and network configurations they deploy, this does not extend to the physical data center or hardware. The provider retains custody and control of the physical server farm—including maintenance, power, cooling, and physical access controls—even when a customer manages a virtual machine down to the OS level. Therefore, IaaS customers must secure the guest OS and application layer, but physical security remains a provider-side function that the customer cannot alter or assume.

  • Physical security responsibility depends on the customer's support plan level

    Why it's wrong here

    Support plans, like Basic, Developer, Standard, or Premier, determine the level of technical support, response times, and operational guidance a customer receives, but they have zero impact on security responsibility allocation. Physical security of cloud data centers is a provider-controlled obligation that remains constant under any support tier or contract agreement. Choosing a higher support plan yields better support services and service-level response guarantees, but it does not grant customers any physical access or obligation to manage provider facilities.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.