AZ-900 Describe cloud concepts Practice Question
A hospital stores patient health records in the cloud. They are responsible for encrypting the data before storing it, while the cloud provider is responsible for securing the physical datacenter. Which cloud model is being described?
⚠ Common exam trap
Many exam-takers confuse the shared responsibility model with deployment models (private, public, hybrid, community) because the question mentions both a customer and a provider, leading them to pick a deployment model instead of recognizing the security duty split.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shared responsibility model
The scenario describes a division of security responsibilities: the hospital encrypts data (customer responsibility) and the cloud provider secures the physical datacenter (provider responsibility). This is the core definition of the shared responsibility model, where security obligations are split based on the cloud service model (IaaS, PaaS, SaaS) and the customer's control over the data and configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Shared responsibility model
Why this is correct
The shared responsibility model is the correct framework because it explicitly divides security duties between the cloud provider and the customer. Under this model, the provider maintains the security of the physical infrastructure, network, and hypervisor, while the customer is accountable for data, identities, access management, and—depending on the service model—configuration, patching, and encryption. For patient health records, this division is critical to understand for compliance (e.g., HIPAA) since the hospital, as the customer, retains responsibility for protecting the data itself regardless of where it is stored.
- ✗
Community cloud
Why it's wrong here
Community cloud is a multi-tenant deployment model tailored to organizations that share regulatory, compliance, or governance requirements, such as multiple hospitals in a region. It offers a shared infrastructure with similar access and policy controls, but it is not a security responsibility framework. Even in a community cloud, the provider and each tenant must still apply the shared responsibility model to determine who handles security tasks like identity management and data encryption.
When this WOULD be correct
A question that asks: 'Several hospitals in a region collaborate to build a cloud environment to share patient data while meeting regulatory requirements. Which cloud model is this?' would make community cloud correct.
- ✗
Hybrid cloud
Why it's wrong here
Hybrid cloud is a deployment architecture that connects a public cloud environment to a private cloud or on-premises infrastructure, often via VPN or dedicated circuits. It describes where workloads run, not which party is accountable for securing them. While a hospital could use hybrid cloud for PHI workloads, doing so does not change the fact that security responsibility is allocated by the shared responsibility model, making this option incorrect.
When this WOULD be correct
A question asks: 'A company uses a mix of on-premises servers and a public cloud provider to run its applications, with data synchronized between both. Which cloud model is this?' The correct answer would be hybrid cloud.
- ✗
Private cloud
Why it's wrong here
Private cloud is a single-tenant environment dedicated to one organization, either on-premises or hosted by a third-party provider. While this gives the hospital more control over physical and logical security, it is not a description of how security responsibilities are divided. In fact, even a private cloud has a separation of duties—for instance, the underlying data-center security is the provider's responsibility unless the hospital owns the facility, but the patient records themselves are always the customer's responsibility.
When this WOULD be correct
A question that asks: 'A company wants a cloud environment dedicated solely to its use, with no sharing of infrastructure with other organizations. Which cloud model should they choose?' would make private cloud the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Shared responsibility modelCorrect answer▾
Why this is correct
The shared responsibility model is the correct framework because it explicitly divides security duties between the cloud provider and the customer. Under this model, the provider maintains the security of the physical infrastructure, network, and hypervisor, while the customer is accountable for data, identities, access management, and—depending on the service model—configuration, patching, and encryption. For patient health records, this division is critical to understand for compliance (e.g., HIPAA) since the hospital, as the customer, retains responsibility for protecting the data itself regardless of where it is stored.
✗Community cloudWrong answer — click to see why▾
Why this is wrong here
The question describes a division of security responsibilities between the hospital and the cloud provider, which is the core concept of the shared responsibility model, not a community cloud. Community cloud refers to a cloud infrastructure shared by several organizations with common concerns, not to responsibility allocation.
★ When this WOULD be the correct answer
A question that asks: 'Several hospitals in a region collaborate to build a cloud environment to share patient data while meeting regulatory requirements. Which cloud model is this?' would make community cloud correct.
Why candidates choose this
Candidates may confuse 'shared' in shared responsibility with 'community' as both involve multiple parties, leading them to incorrectly select community cloud.
✗Hybrid cloudWrong answer — click to see why▾
Why this is wrong here
The hybrid cloud model combines public and private clouds, but the question describes a shared responsibility for security, not a deployment model. The scenario focuses on security responsibilities, not cloud deployment types.
★ When this WOULD be the correct answer
A question asks: 'A company uses a mix of on-premises servers and a public cloud provider to run its applications, with data synchronized between both. Which cloud model is this?' The correct answer would be hybrid cloud.
Why candidates choose this
Candidates may confuse 'shared responsibility' with 'hybrid' because both involve multiple parties or environments, leading them to incorrectly select hybrid cloud when the question is about security roles.
✗Private cloudWrong answer — click to see why▾
Why this is wrong here
The question describes a division of security responsibilities between the hospital and the cloud provider, which is the shared responsibility model. Private cloud refers to a cloud infrastructure used exclusively by a single organization, not a specific security responsibility model.
★ When this WOULD be the correct answer
A question that asks: 'A company wants a cloud environment dedicated solely to its use, with no sharing of infrastructure with other organizations. Which cloud model should they choose?' would make private cloud the correct answer.
Why candidates choose this
Candidates may confuse 'private cloud' with 'private responsibility' or think that a private cloud implies the customer handles all security, but the shared responsibility model applies to all cloud deployment models.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
What is Cloud Computing?
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
Key term
Shared responsibility model
The shared responsibility model is a framework that defines which security and compliance tasks are handled by the cloud provider and which are handled by the customer.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.