Courseiva
Describe cloud conceptsmediumMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

A company is migrating a custom line-of-business application to Azure. The application handles sensitive customer data. The IT team is evaluating whether to deploy the application on Azure Virtual Machines (IaaS) or Azure App Service (PaaS). They want to understand the division of security responsibilities between Microsoft and the customer under the shared responsibility model. Which responsibility remains the customer's obligation regardless of whether they choose IaaS, PaaS, or SaaS?

⚠ Common exam trap

A common mix-up: candidates assume OS patching (Option A) is always the customer's job, but in PaaS and SaaS the cloud provider handles the OS, making data access and classification the only truly universal customer responsibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Managing user access to the application data and ensuring data classification policies are enforced

Under the shared responsibility model, the customer is always responsible for managing access to data and enforcing data classification policies, regardless of whether the workload runs on IaaS, PaaS, or SaaS. This is because data ownership and the associated governance obligations (such as who can read, write, or modify sensitive customer data) remain with the customer. Microsoft secures the underlying infrastructure, but the customer must control who accesses the application data and how it is classified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Applying operating system security patches and updates to virtual machines

    Why it's wrong here

    Incorrect. OS patching is the customer's responsibility only in IaaS. In PaaS (e.g., Azure App Service), the cloud provider manages the underlying OS. In SaaS, the provider handles all patching. Therefore, this is not a responsibility that remains constant across all models.

    When this WOULD be correct

    A question that asks: 'A company is deploying a custom application on Azure Virtual Machines (IaaS). Which security responsibility does the customer retain?' In that specific IaaS scenario, applying OS patches is indeed the customer's obligation.

  • Managing the physical server hardware, network switches, and datacenter cooling

    Why it's wrong here

    In the shared responsibility model, Microsoft Azure always manages the physical datacenter components—servers, storage, networking hardware, power, and cooling—regardless of whether the service is IaaS, PaaS, or SaaS. This is a provider-controlled layer that customers never touch, even in IaaS where they control the VM OS and applications. Therefore, this is not a responsibility that persists across all cloud models, because it is never a customer responsibility in any Azure service.

    When this WOULD be correct

    This option would be correct if the question asked: 'Which responsibility is always the customer's obligation in an on-premises datacenter?' or 'Which task is the customer responsible for when using Azure IaaS?'

  • Configuring and maintaining the application-level network load balancer for high availability

    Why it's wrong here

    Incorrect. While a customer can configure load balancers in IaaS, in PaaS (like Azure App Service) the platform provides built-in load balancing managed by the provider. In SaaS, load balancing is entirely provided by the vendor. Thus, this responsibility varies by model.

    When this WOULD be correct

    In a question asking which responsibility is the customer's when using IaaS specifically (e.g., 'A company deploys VMs in Azure. Which task is the customer responsible for?'), configuring the load balancer for high availability would be correct.

  • Managing user access to the application data and ensuring data classification policies are enforced

    Why this is correct

    Correct. The customer always owns their data and identities, regardless of the service model. Data classification, access control, and identity management are perpetual customer responsibilities. Even in SaaS, the customer must manage who has access to the application and what data they can see.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

Managing user access to the application data and ensuring data classification policies are enforcedCorrect answer

Why this is correct

Correct. The customer always owns their data and identities, regardless of the service model. Data classification, access control, and identity management are perpetual customer responsibilities. Even in SaaS, the customer must manage who has access to the application and what data they can see.

Applying operating system security patches and updates to virtual machinesWrong answer — click to see why

Why this is wrong here

In the shared responsibility model, applying OS security patches is the customer's responsibility for IaaS (VMs), but for PaaS (App Service), Microsoft manages the OS and underlying infrastructure, including patching. The question asks for a responsibility that remains the customer's obligation regardless of IaaS, PaaS, or SaaS, and OS patching is not always the customer's responsibility.

★ When this WOULD be the correct answer

A question that asks: 'A company is deploying a custom application on Azure Virtual Machines (IaaS). Which security responsibility does the customer retain?' In that specific IaaS scenario, applying OS patches is indeed the customer's obligation.

Why candidates choose this

Candidates may confuse the shared responsibility model across service models, assuming OS patching is always the customer's job, or they may not realize that PaaS and SaaS shift that responsibility to Microsoft.

Managing the physical server hardware, network switches, and datacenter coolingWrong answer — click to see why

Why this is wrong here

In the shared responsibility model, managing physical hardware, network switches, and datacenter cooling is always Microsoft's responsibility, regardless of whether the customer uses IaaS, PaaS, or SaaS.

★ When this WOULD be the correct answer

This option would be correct if the question asked: 'Which responsibility is always the customer's obligation in an on-premises datacenter?' or 'Which task is the customer responsible for when using Azure IaaS?'

Why candidates choose this

Candidates may confuse the shared responsibility model with on-premises management, or mistakenly think that physical infrastructure is always the customer's burden.

Configuring and maintaining the application-level network load balancer for high availabilityWrong answer — click to see why

Why this is wrong here

Configuring and maintaining an application-level network load balancer is a customer responsibility in IaaS, but in PaaS (Azure App Service), the platform manages load balancing automatically, making this not a universal customer obligation across all service models.

★ When this WOULD be the correct answer

In a question asking which responsibility is the customer's when using IaaS specifically (e.g., 'A company deploys VMs in Azure. Which task is the customer responsible for?'), configuring the load balancer for high availability would be correct.

Why candidates choose this

Candidates may confuse load balancing as always a customer task, not realizing that PaaS abstracts this away, and they may overgeneralize from on-premises or IaaS experience.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.