Courseiva
Describe cloud conceptsmediumMultiple ChoiceObjective-mapped

AZ-900 Describe cloud concepts Practice Question

A company is migrating its customer relationship management (CRM) system to a Software as a Service (SaaS) provider. The provider manages the application, runtime, middleware, and infrastructure. The company's IT security team is concerned about who is responsible for protecting the company's data and managing user access. Based on the shared responsibility model for cloud computing, which statement is correct?

⚠ Common exam trap

Watch out — candidates often assume the SaaS provider handles all security aspects, including data and access, because the provider manages the application, but the shared responsibility model clearly assigns data and access management to the customer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The company is responsible for managing user access and protecting their own data within the SaaS application.

In the shared responsibility model for SaaS, the provider manages the application, runtime, middleware, and infrastructure, but the customer retains responsibility for securing their own data and managing user access. This includes tasks such as data classification, identity and access management (IAM), and ensuring compliance with internal policies. Option C correctly identifies that the company must handle user access and data protection within the SaaS application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The SaaS provider is responsible for everything, including data classification and user access control.

    Why it's wrong here

    The SaaS provider does not assume responsibility for everything. In the shared responsibility model for SaaS, the customer continuously owns its data, including data classification based on sensitivity, and controls user identities and access rights. The provider only supplies the application and underlying infrastructure, offering tools (like identity providers or role management) that the customer must configure to enforce its own access policies. Therefore, saying the provider is responsible for data classification and access control misplaces the boundary of security ownership.

    When this WOULD be correct

    This option would be correct in a scenario where the question specifies a fully managed service with no customer control, such as a consumer-facing SaaS where the provider handles all aspects including user accounts and data classification, and the customer has no administrative access.

  • The company is responsible for the security of the application itself, including patching vulnerabilities in the CRM software.

    Why it's wrong here

    This option inverts the SaaS responsibility boundary. Patches, security updates, and vulnerability fixes to the CRM application are applied by the SaaS provider as part of the managed service; the customer receives these changes without needing to intervene. The customer does not have access to the application's source code, runtime, or administrative environment to perform such patches, nor would they be permitted to alter the provider's software. Thus, the customer cannot be responsible for securing the application itself because that responsibility stays with the vendor offering the SaaS solution.

    When this WOULD be correct

    This option would be correct in an IaaS (Infrastructure as a Service) scenario where the company manages the operating system and applications, including patching vulnerabilities in the software they install.

  • The company is responsible for managing user access and protecting their own data within the SaaS application.

    Why this is correct

    This is correct. Under the shared responsibility model for SaaS, the customer manages user identities, data classification, and access control. The provider secures the platform and infrastructure, but the customer must ensure only authorized users access the data and that data is handled appropriately.

  • The SaaS provider is responsible for physical security of data centers, and the company is responsible for patching the operating system of the servers hosting the CRM.

    Why it's wrong here

    This option misallocates OS patching in a SaaS deployment. While it correctly assigns physical data center security to the provider, it incorrectly places operating system patching on the company. In SaaS, the provider is responsible for the entire compute stack, including hypervisors, host OSes, and guest OSes; the customer only uses the CRM application through a browser or API. The customer has no login or administrative rights to the servers hosting the CRM, so OS patching is exclusively the provider's operational duty.

    When this WOULD be correct

    This option would be correct for an IaaS (Infrastructure as a Service) scenario, where the cloud provider is responsible for physical security of data centers, and the customer is responsible for patching the operating system of their virtual machines.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

The company is responsible for managing user access and protecting their own data within the SaaS application.Correct answer

Why this is correct

This is correct. Under the shared responsibility model for SaaS, the customer manages user identities, data classification, and access control. The provider secures the platform and infrastructure, but the customer must ensure only authorized users access the data and that data is handled appropriately.

The SaaS provider is responsible for everything, including data classification and user access control.Wrong answer — click to see why

Why this is wrong here

In the shared responsibility model, the SaaS provider manages the application, runtime, middleware, and infrastructure, but the customer retains responsibility for data classification, user access, and protecting their own data. Option A incorrectly assigns full responsibility to the provider.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the question specifies a fully managed service with no customer control, such as a consumer-facing SaaS where the provider handles all aspects including user accounts and data classification, and the customer has no administrative access.

Why candidates choose this

Candidates may think that since the provider manages the entire stack, they also handle data security and access, overlooking the customer's ongoing responsibilities for data and identity management in the shared responsibility model.

The company is responsible for the security of the application itself, including patching vulnerabilities in the CRM software.Wrong answer — click to see why

Why this is wrong here

In a SaaS model, the provider manages the application, runtime, middleware, and infrastructure, including patching the CRM software. The company is not responsible for security of the application itself.

★ When this WOULD be the correct answer

This option would be correct in an IaaS (Infrastructure as a Service) scenario where the company manages the operating system and applications, including patching vulnerabilities in the software they install.

Why candidates choose this

Candidates may confuse SaaS with IaaS or PaaS, assuming the customer retains responsibility for application security and patching, which is not the case in SaaS.

The SaaS provider is responsible for physical security of data centers, and the company is responsible for patching the operating system of the servers hosting the CRM.Wrong answer — click to see why

Why this is wrong here

In the shared responsibility model for SaaS, the provider manages the operating system and infrastructure, so the company is not responsible for patching the OS. The company's responsibilities are limited to data, user access, and endpoints.

★ When this WOULD be the correct answer

This option would be correct for an IaaS (Infrastructure as a Service) scenario, where the cloud provider is responsible for physical security of data centers, and the customer is responsible for patching the operating system of their virtual machines.

Why candidates choose this

Candidates may confuse the shared responsibility model across different service models (IaaS, PaaS, SaaS) and incorrectly assume that in SaaS the customer still handles OS patching, or they may overgeneralize the provider's physical security responsibility to include OS patching.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.