AZ-900 Describe cloud concepts Practice Question
A company is migrating its on-premises SQL Server databases to Azure SQL Database, which is a Platform as a Service (PaaS) offering. The on-premises IT team is accustomed to manually applying monthly security patches to the SQL Server software. After the migration, the team wants to understand their responsibilities for securing the database. According to the shared responsibility model, which party is responsible for applying security patches to the SQL Server database engine in Azure SQL Database?
⚠ Common exam trap
The trap here is that candidates mistakenly apply on-premises patching habits to PaaS, assuming the customer retains full control over the database engine, when in fact Microsoft manages the underlying platform and engine updates under the shared responsibility model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft, because Azure SQL Database is a PaaS service where Microsoft manages the database engine.
Azure SQL Database is a Platform as a Service (PaaS) offering where Microsoft manages the underlying infrastructure, including the operating system and the SQL Server database engine. Under the shared responsibility model, Microsoft is responsible for applying security patches to the database engine, while the customer is responsible for securing their data, access controls, and database-level configurations. This frees the customer from manual patching tasks they performed on-premises.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The customer, because the database engine is a customer-managed application.
Why it's wrong here
The database engine in Azure SQL Database is not a customer-managed application; it is a component of a managed PaaS service. Unlike a SQL Server installed on an IaaS VM, Azure SQL provides no direct access to the engine's operating system or files, so the customer cannot apply patches to it. The customer's duties are limited to logical aspects such as database design, data integrity, and user permissions, while Microsoft handles the engine maintenance.
When this WOULD be correct
This option would be correct if the question were about an IaaS scenario, such as a customer deploying SQL Server on a virtual machine in Azure, where the customer is responsible for managing and patching the SQL Server software.
- ✓
Microsoft, because Azure SQL Database is a PaaS service where Microsoft manages the database engine.
Why this is correct
Azure SQL Database is a fully managed Platform-as-a-Service (PaaS) offering, so Microsoft owns the entire operational stack, including the database engine and its security updates. The customer has no access to the underlying OS or service binaries, so patching the engine is entirely Microsoft's responsibility. Customers remain responsible for their data, schemas, and identity/access management, not for the platform components.
- ✗
Both the customer and Microsoft share equal responsibility for patching the database engine.
Why it's wrong here
The shared responsibility model does not split engine patching equally; Microsoft holds the complete and exclusive obligation to patch the Azure SQL Database engine. Customers are responsible for controlling access to their data and configuring security features, but they have no operational role in applying OS or engine updates. Therefore, the statement regarding equal sharing is inaccurate because platform patching is entirely owned by Microsoft under PaaS.
When this WOULD be correct
This option would be correct for a hybrid scenario where the customer manages the operating system or database engine (e.g., SQL Server on Azure Virtual Machine), and Microsoft manages the underlying infrastructure, leading to shared patching responsibilities.
- ✗
The customer, but only if the Azure SQL Database is configured with the serverless compute tier.
Why it's wrong here
This is incorrect. The serverless compute tier in Azure SQL Database is a scaling option for compute resources, but it does not change the shared responsibility model. Microsoft remains responsible for patching the database engine regardless of the compute tier.
When this WOULD be correct
This option would be correct if the question asked about a customer-managed SQL Server on an Azure Virtual Machine (IaaS), where the customer is responsible for patching the database engine, and the serverless tier is an additional configuration that does not change responsibility.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft, because Azure SQL Database is a PaaS service where Microsoft manages the database engine.Correct answer▾
Why this is correct
Azure SQL Database is a fully managed Platform-as-a-Service (PaaS) offering, so Microsoft owns the entire operational stack, including the database engine and its security updates. The customer has no access to the underlying OS or service binaries, so patching the engine is entirely Microsoft's responsibility. Customers remain responsible for their data, schemas, and identity/access management, not for the platform components.
✗The customer, because the database engine is a customer-managed application.Wrong answer — click to see why▾
Why this is wrong here
Azure SQL Database is a PaaS service where Microsoft manages the database engine, including applying security patches. The customer does not have access to the underlying OS or database engine to apply patches themselves.
★ When this WOULD be the correct answer
This option would be correct if the question were about an IaaS scenario, such as a customer deploying SQL Server on a virtual machine in Azure, where the customer is responsible for managing and patching the SQL Server software.
Why candidates choose this
Candidates may confuse PaaS with IaaS, or assume that since they manage the database content, they also manage the database engine patching, not realizing that in PaaS the provider handles the platform layer.
✗Both the customer and Microsoft share equal responsibility for patching the database engine.Wrong answer — click to see why▾
Why this is wrong here
In Azure SQL Database (PaaS), Microsoft manages the database engine, including patching. The shared responsibility model assigns full responsibility for patching the PaaS database engine to Microsoft, not shared.
★ When this WOULD be the correct answer
This option would be correct for a hybrid scenario where the customer manages the operating system or database engine (e.g., SQL Server on Azure Virtual Machine), and Microsoft manages the underlying infrastructure, leading to shared patching responsibilities.
Why candidates choose this
Candidates may mistakenly think that security responsibilities are always shared equally, not realizing that PaaS shifts patching of the platform to the provider.
✗The customer, but only if the Azure SQL Database is configured with the serverless compute tier.Wrong answer — click to see why▾
Why this is wrong here
In Azure SQL Database (PaaS), Microsoft manages the database engine, including security patching, regardless of the compute tier. The serverless compute tier only affects scaling and billing, not patching responsibilities.
★ When this WOULD be the correct answer
This option would be correct if the question asked about a customer-managed SQL Server on an Azure Virtual Machine (IaaS), where the customer is responsible for patching the database engine, and the serverless tier is an additional configuration that does not change responsibility.
Why candidates choose this
Candidates may confuse the serverless compute tier with shared responsibility, thinking that serverless implies more customer control or that it alters the patching model, when in fact PaaS always means Microsoft handles patching.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
The Shared Responsibility Model
Key term
Azure SQL Database
Azure SQL Database is a fully managed relational database-as-a-service (DBaaS) in Microsoft Azure, based on the SQL Server engine, that handles scaling, backups, patching, and high availability automatically.
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.