AZ-900 Describe cloud concepts Practice Question
A company is migrating a custom line-of-business application to Azure. The application handles sensitive customer data. The IT team is evaluating whether to deploy the application on Azure Virtual Machines (IaaS) or Azure App Service (PaaS). They want to understand the division of security responsibilities between Microsoft and the customer under the shared responsibility model. Which responsibility remains the customer's obligation regardless of whether they choose IaaS, PaaS, or SaaS?
⚠ Common exam trap
A common mix-up: candidates assume OS patching (Option A) is always the customer's job, but in PaaS and SaaS the cloud provider handles the OS, making data access and classification the only truly universal customer responsibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing user access to the application data and ensuring data classification policies are enforced
Under the shared responsibility model, the customer is always responsible for managing access to data and enforcing data classification policies, regardless of whether the workload runs on IaaS, PaaS, or SaaS. This is because data ownership and the associated governance obligations (such as who can read, write, or modify sensitive customer data) remain with the customer. Microsoft secures the underlying infrastructure, but the customer must control who accesses the application data and how it is classified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Applying operating system security patches and updates to virtual machines
Why it's wrong here
Incorrect. OS patching is the customer's responsibility only in IaaS. In PaaS (e.g., Azure App Service), the cloud provider manages the underlying OS. In SaaS, the provider handles all patching. Therefore, this is not a responsibility that remains constant across all models.
When this WOULD be correct
A question that asks: 'A company is deploying a custom application on Azure Virtual Machines (IaaS). Which security responsibility does the customer retain?' In that specific IaaS scenario, applying OS patches is indeed the customer's obligation.
- ✗
Managing the physical server hardware, network switches, and datacenter cooling
Why it's wrong here
In the shared responsibility model, Microsoft Azure always manages the physical datacenter components—servers, storage, networking hardware, power, and cooling—regardless of whether the service is IaaS, PaaS, or SaaS. This is a provider-controlled layer that customers never touch, even in IaaS where they control the VM OS and applications. Therefore, this is not a responsibility that persists across all cloud models, because it is never a customer responsibility in any Azure service.
When this WOULD be correct
This option would be correct if the question asked: 'Which responsibility is always the customer's obligation in an on-premises datacenter?' or 'Which task is the customer responsible for when using Azure IaaS?'
- ✗
Configuring and maintaining the application-level network load balancer for high availability
Why it's wrong here
Incorrect. While a customer can configure load balancers in IaaS, in PaaS (like Azure App Service) the platform provides built-in load balancing managed by the provider. In SaaS, load balancing is entirely provided by the vendor. Thus, this responsibility varies by model.
When this WOULD be correct
In a question asking which responsibility is the customer's when using IaaS specifically (e.g., 'A company deploys VMs in Azure. Which task is the customer responsible for?'), configuring the load balancer for high availability would be correct.
- ✓
Managing user access to the application data and ensuring data classification policies are enforced
Why this is correct
Correct. The customer always owns their data and identities, regardless of the service model. Data classification, access control, and identity management are perpetual customer responsibilities. Even in SaaS, the customer must manage who has access to the application and what data they can see.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Managing user access to the application data and ensuring data classification policies are enforcedCorrect answer▾
Why this is correct
Correct. The customer always owns their data and identities, regardless of the service model. Data classification, access control, and identity management are perpetual customer responsibilities. Even in SaaS, the customer must manage who has access to the application and what data they can see.
✗Applying operating system security patches and updates to virtual machinesWrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, applying OS security patches is the customer's responsibility for IaaS (VMs), but for PaaS (App Service), Microsoft manages the OS and underlying infrastructure, including patching. The question asks for a responsibility that remains the customer's obligation regardless of IaaS, PaaS, or SaaS, and OS patching is not always the customer's responsibility.
★ When this WOULD be the correct answer
A question that asks: 'A company is deploying a custom application on Azure Virtual Machines (IaaS). Which security responsibility does the customer retain?' In that specific IaaS scenario, applying OS patches is indeed the customer's obligation.
Why candidates choose this
Candidates may confuse the shared responsibility model across service models, assuming OS patching is always the customer's job, or they may not realize that PaaS and SaaS shift that responsibility to Microsoft.
✗Managing the physical server hardware, network switches, and datacenter coolingWrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, managing physical hardware, network switches, and datacenter cooling is always Microsoft's responsibility, regardless of whether the customer uses IaaS, PaaS, or SaaS.
★ When this WOULD be the correct answer
This option would be correct if the question asked: 'Which responsibility is always the customer's obligation in an on-premises datacenter?' or 'Which task is the customer responsible for when using Azure IaaS?'
Why candidates choose this
Candidates may confuse the shared responsibility model with on-premises management, or mistakenly think that physical infrastructure is always the customer's burden.
✗Configuring and maintaining the application-level network load balancer for high availabilityWrong answer — click to see why▾
Why this is wrong here
Configuring and maintaining an application-level network load balancer is a customer responsibility in IaaS, but in PaaS (Azure App Service), the platform manages load balancing automatically, making this not a universal customer obligation across all service models.
★ When this WOULD be the correct answer
In a question asking which responsibility is the customer's when using IaaS specifically (e.g., 'A company deploys VMs in Azure. Which task is the customer responsible for?'), configuring the load balancer for high availability would be correct.
Why candidates choose this
Candidates may confuse load balancing as always a customer task, not realizing that PaaS abstracts this away, and they may overgeneralize from on-premises or IaaS experience.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
The Shared Responsibility Model
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.