Courseiva
Describe cloud conceptshardMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

A company wants to understand who is responsible for securing the operating system on an Azure virtual machine. According to the shared responsibility model, who is responsible?

⚠ Common exam trap

Many exam-takers assume Microsoft handles all OS security for Azure VMs because of the 'as a service' branding, but in IaaS, the customer retains full responsibility for the guest OS and applications, unlike PaaS or SaaS where Microsoft manages more layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft is responsible for the physical host and network, while the customer is responsible for the guest OS and applications.

Under the shared responsibility model for IaaS like Azure VMs, Microsoft secures the physical datacenter, host OS, and network infrastructure, while the customer is responsible for securing the guest OS (e.g., applying patches, configuring firewalls) and any applications running on the VM. This division is explicit in Azure's documentation, where the customer retains control over the OS and software stack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft is responsible for all security.

    Why it's wrong here

    Microsoft is not responsible for all security because in an IaaS environment the customer manages the guest OS, runtime, middleware, and applications, which are outside Microsoft's control. While Microsoft secures the physical host, hypervisor, and network, the customer must apply OS patches, configure firewalls, and protect application-level credentials. Even in PaaS and SaaS, the customer remains responsible for their data, access policies, and identity configurations, so security is never solely the provider's obligation.

    When this WOULD be correct

    For a fully managed PaaS service like Azure SQL Database, Microsoft is responsible for securing the underlying OS and platform, while the customer manages data and access. A question asking about PaaS security would make this correct.

  • The customer is responsible for all security.

    Why it's wrong here

    This is incorrect because Microsoft retains physical and environmental security, including the datacenter facilities, power, cooling, and network infrastructure, even in an IaaS model. However, the customer is still responsible for the guest OS, applications, and data they install and configure, so the customer does not own every security control; their responsibilities begin where Microsoft's infrastructure responsibilities end.

    When this WOULD be correct

    This option would be correct if the question specified a scenario where the customer uses an on-premises server or a fully customer-managed environment, such as a physical server in their own data center, where the customer is responsible for all security layers.

  • Microsoft is responsible for the physical host and network, while the customer is responsible for the guest OS and applications.

    Why this is correct

    In an IaaS deployment, Microsoft protects the physical datacenter, server hardware, the hypervisor layer, and the physical network, while the customer must secure the guest OS, including patching, hardening, and configuration, along with its applications and data. This distinction precisely defines the shared responsibility model: the cloud provider manages the infrastructure up to the virtualization layer, and the customer manages everything deployed on top of it.

  • Responsibility is split 50/50.

    Why it's wrong here

    The shared responsibility model is not a literal 50/50 split based on percentage of effort or controls; it is a layered division based on the service model. For IaaS, customers handle the majority of security controls—guest OS, apps, data—while Microsoft handles the underlying hardware and network, so the split is uneven and varies by workload. In PaaS or SaaS, the balance shifts significantly toward Microsoft, further disproving any fixed 50/50 division.

    When this WOULD be correct

    In a scenario where a question asks about a shared responsibility model for a service like Azure SQL Database (PaaS), where Microsoft manages the OS and platform, and the customer manages data and access, the responsibility might be described as roughly 50/50 in terms of management effort, though not an exact split.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft is responsible for the physical host and network, while the customer is responsible for the guest OS and applications.Correct answer

Why this is correct

In an IaaS deployment, Microsoft protects the physical datacenter, server hardware, the hypervisor layer, and the physical network, while the customer must secure the guest OS, including patching, hardening, and configuration, along with its applications and data. This distinction precisely defines the shared responsibility model: the cloud provider manages the infrastructure up to the virtualization layer, and the customer manages everything deployed on top of it.

Microsoft is responsible for all security.Wrong answer — click to see why

Why this is wrong here

In Azure IaaS, Microsoft secures the physical infrastructure, but customers are responsible for securing their own guest OS, applications, and data. Option A incorrectly assigns full security responsibility to Microsoft.

★ When this WOULD be the correct answer

For a fully managed PaaS service like Azure SQL Database, Microsoft is responsible for securing the underlying OS and platform, while the customer manages data and access. A question asking about PaaS security would make this correct.

Why candidates choose this

Candidates may assume that because Azure is a cloud platform, Microsoft handles all security, overlooking the shared responsibility model where customers retain control over their own workloads.

The customer is responsible for all security.Wrong answer — click to see why

Why this is wrong here

In the shared responsibility model, Microsoft secures the physical infrastructure, but the customer is responsible for securing the guest OS and applications on an Azure VM. Option B incorrectly assigns all security to the customer, ignoring Microsoft's responsibilities.

★ When this WOULD be the correct answer

This option would be correct if the question specified a scenario where the customer uses an on-premises server or a fully customer-managed environment, such as a physical server in their own data center, where the customer is responsible for all security layers.

Why candidates choose this

Candidates may think that because the customer manages the VM's OS and applications, they are responsible for everything, overlooking that Microsoft secures the underlying physical host and network.

Responsibility is split 50/50.Wrong answer — click to see why

Why this is wrong here

The shared responsibility model does not split responsibility evenly; Microsoft secures the physical infrastructure, while the customer secures the guest OS, applications, and data. A 50/50 split misrepresents the actual division of responsibilities.

★ When this WOULD be the correct answer

In a scenario where a question asks about a shared responsibility model for a service like Azure SQL Database (PaaS), where Microsoft manages the OS and platform, and the customer manages data and access, the responsibility might be described as roughly 50/50 in terms of management effort, though not an exact split.

Why candidates choose this

Candidates may think of responsibility as a simple 50/50 split due to a misunderstanding of the shared responsibility model, or they may confuse it with other frameworks that use equal splits.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.