MS-900 Describe cloud concepts Practice Question
A company migrates its database to Azure SQL Database (PaaS). According to the shared responsibility model, which of the following is the customer's responsibility?
⚠ Common exam trap
Watch out — candidates often assume patching or infrastructure maintenance is shared in PaaS, but Microsoft fully manages the OS and physical layers, while the customer's responsibility is strictly limited to data, access, and application-level security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing user access and authentication
In the shared responsibility model for Azure SQL Database (PaaS), the customer is responsible for managing user access and authentication because the customer controls who can connect to the database and what permissions they have. Microsoft manages the underlying infrastructure, including the operating system, physical hardware, and virtualization layer, while the customer must secure data access through Microsoft Entra ID or SQL authentication, configure firewall rules, and manage logins and users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Managing user access and authentication
Why this is correct
In Azure SQL Database, a PaaS offering, the customer remains responsible for data plane security, specifically controlling who can authenticate and what privileges they hold. You manage SQL logins, contained database users, Microsoft Entra ID identities, and database/role permissions, while Microsoft never takes on that access governance. This includes configuring firewalls for client IPs only as part of network access control, but authentication and authorization decisions are exclusively the customer's duty. Therefore, managing user access and authentication is a customer-controlled function within the shared responsibility model.
- ✗
Patching the operating system of the database server
Why it's wrong here
Patching the operating system that hosts the Azure SQL Database is entirely automated by Microsoft. The underlying Windows Server operating system receives security and maintenance updates from the Azure platform team, with no customer action or scheduled maintenance window required. In fact, the customer never gets access to the OS nor has any visibility into its patch state because SQL Database is a fully managed platform service. Thus, any expectation that the customer must patch the database server's OS is incorrect under the PaaS shared responsibility model.
- ✗
Maintaining the physical infrastructure
Why it's wrong here
Maintaining the physical infrastructure, such as rack-mounted servers, storage hardware, and network cables, is carried out by Microsoft datacenter operations staff, not by the customer. In a PaaS model, the hardware is abstracted away: you only provision and connect to a logical database, and your capacity resides in multi-tenant racks that Microsoft monitors and maintains. Because there is no customer access to the datacenter hardware, any obligation for hardware maintenance or replacement is entirely the provider's. Therefore, this is not a customer responsibility in Azure SQL Database.
- ✗
Managing the virtualization layer
Why it's wrong here
The virtualization layer, which isolates the Azure SQL Database instances and manages the underlying compute resources, is the provider's domain. Microsoft's Azure fabric controls the hypervisor, VM scheduling, and tenant isolation that run each managed database, and customers have no interaction with this layer. You connect only to the database endpoint, never to the underlying virtual machines or container hosts. Consequently, managing the virtualization layer is a Microsoft responsibility, making this option incorrect for the customer.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID (Azure AD) in M365
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.