Question 665 of 981
AZ-900 Describe cloud concepts Practice Question
What is the role of a cloud provider's physical datacenter security in the shared responsibility model?
⚠ Common exam trap
The trap here is that candidates mistakenly think physical security is shared or customer-managed in IaaS, confusing the customer's responsibility for virtual infrastructure (e.g., VMs, OS) with the provider's responsibility for the physical datacenter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Physical security is entirely the cloud provider's responsibility
In the shared responsibility model, physical security of the datacenter—including access controls, surveillance, and environmental controls—is always the sole responsibility of the cloud provider (e.g., Microsoft Azure). The customer never manages or is responsible for the physical infrastructure, regardless of the service model (IaaS, PaaS, SaaS). This is because the customer has no physical access to the datacenter and cannot implement or control physical security measures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Both the cloud provider and customer share responsibility for physical security
Why it's wrong here
This option incorrectly suggests that physical security is part of the shared responsibility model's split between provider and customer. In actuality, physical security controls—such as building perimeter defenses, server room access, surveillance, and hardware disposition—are exclusively managed by the cloud provider, and customers are never granted physical access to the infrastructure. The customer's shared duties begin at the virtualization layer (for IaaS) or higher, never extending down to the datacenter's physical environment.
- ✓
Physical security is entirely the cloud provider's responsibility
Why this is correct
Across every cloud service model—IaaS, PaaS, and SaaS—the cloud provider is solely responsible for physical security of the data center. This includes protecting the facilities with biometric access controls, multi-factor authentication for entry, continuous video monitoring, and physically securing server racks and hardware. Customers interact only with logical resources through the cloud interface, never with the physical hardware or facilities, so responsibility for physical security cannot be transferred or shared.
- ✗
Customers are responsible for physical security when using IaaS
Why it's wrong here
While IaaS customers are responsible for securing the operating system, applications, and network configurations they deploy, this does not extend to the physical data center or hardware. The provider retains custody and control of the physical server farm—including maintenance, power, cooling, and physical access controls—even when a customer manages a virtual machine down to the OS level. Therefore, IaaS customers must secure the guest OS and application layer, but physical security remains a provider-side function that the customer cannot alter or assume.
- ✗
Physical security responsibility depends on the customer's support plan level
Why it's wrong here
Support plans, like Basic, Developer, Standard, or Premier, determine the level of technical support, response times, and operational guidance a customer receives, but they have zero impact on security responsibility allocation. Physical security of cloud data centers is a provider-controlled obligation that remains constant under any support tier or contract agreement. Choosing a higher support plan yields better support services and service-level response guarantees, but it does not grant customers any physical access or obligation to manage provider facilities.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.