Courseiva

CCNA Describe cloud concepts Questions

68 of 143 questions · Page 2/2 · Describe cloud concepts · Answers revealed

76
MCQeasy

An e-commerce website hosted on a cloud provider automatically adds more virtual machines to handle increased traffic during Black Friday and removes them after the event. Which cloud characteristic does this illustrate?

A.Rapid elasticity
B.On-demand self-service
C.Resource pooling
D.Measured service
AnswerA

Rapid elasticity is the correct NIST characteristic because it enables the cloud to automatically provision and release compute resources—such as VMs—in response to fluctuating demand. In this scenario, the e-commerce site's traffic spikes trigger an immediate increase in VM instances, and when traffic subsides, those instances are automatically deprovisioned, making the resource pool appear infinite and highly responsive.

Why this answer

Rapid elasticity is the cloud characteristic that enables resources to scale out (add VMs) automatically in response to demand spikes like Black Friday traffic, and scale in (remove VMs) when demand subsides. This is distinct from manual scaling because it happens automatically and dynamically, often using autoscaling policies tied to metrics such as CPU utilization or request count.

Exam trap

The trap here is that candidates confuse 'rapid elasticity' with 'on-demand self-service' because both involve automation, but elasticity specifically refers to automatic scaling in response to load, not just the ability to provision resources on demand.

How to eliminate wrong answers

Option B (On-demand self-service) is wrong because it refers to a user provisioning resources without human intervention, not the automatic scaling of resources in response to load. Option C (Resource pooling) is wrong because it describes the provider's multi-tenant model where physical and virtual resources are shared across customers, not the ability to scale up/down. Option D (Measured service) is wrong because it involves metering resource usage for billing and optimization, not the dynamic adjustment of capacity.

77
MCQeasy

A company uses a cloud service that provides virtual machines. The company manages the operating system, middleware, and applications, while the cloud provider manages the physical hardware, networking, and data center security. Which cloud service model does this represent?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Desktop as a Service (DaaS)
AnswerA

IaaS (Infrastructure as a Service) delivers virtualized compute resources as ready-to-use VMs, and the customer retains full control over the guest operating system, runtime, and application stack. The cloud provider is responsible for the physical hosts, the hypervisor, and the data-center networking, while the customer patches, configures, and secures the OS. In this scenario, the company is using a cloud service that provides virtual machines, which directly matches the IaaS delivery model.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer manages the operating system, middleware, and applications, while the cloud provider is responsible for the physical hardware, networking, and data center security. In IaaS, the provider delivers virtualized computing resources over the internet, and the customer retains control over the guest OS, storage, and deployed applications, which matches the division of responsibilities given.

Exam trap

The trap here is that candidates confuse IaaS with PaaS because both involve virtual machines, but PaaS abstracts the OS and middleware, so the key differentiator is who manages the operating system and middleware—if the customer manages them, it is IaaS.

How to eliminate wrong answers

Option B (PaaS) is wrong because in Platform as a Service, the provider manages the operating system, middleware, and runtime environment, leaving the customer to only deploy and manage their own applications and data, not the OS or middleware. Option C (SaaS) is wrong because in Software as a Service, the provider manages the entire application stack, including the operating system, middleware, and applications, and the customer only uses the software via a web browser or client, with no management of the underlying infrastructure. Option D (DaaS) is wrong because Desktop as a Service delivers virtual desktops to end users, where the provider manages the desktop OS and underlying infrastructure, and the customer typically does not manage the OS or middleware as described.

78
MCQeasy

While preparing a Microsoft 365 adoption plan, a consultant is asked to avoid buying servers upfront and pay monthly based on usage. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Data Loss Prevention (DLP)
C.Operational expenditure (OpEx) model
D.Microsoft Planner
AnswerC

The OpEx model satisfies the requirement to avoid upfront server purchases by shifting costs to monthly, usage-based payments. Unlike capital expenditure, which demands significant initial hardware investment, OpEx aligns spending with consumption, directly matching the consultant's mandate to eliminate upfront infrastructure costs while maintaining Microsoft 365 services.

Why this answer

The operational expenditure (OpEx) model is correct because it aligns with the requirement to avoid upfront capital investment (CapEx) and instead pay monthly based on usage. In Microsoft 365, this is delivered through subscription-based licensing (e.g., per-user per-month plans), which shifts costs from large upfront server purchases to predictable monthly payments that scale with consumption.

Exam trap

The trap here is that candidates may confuse 'operational expenditure' with a specific tool or feature (like Planner or DLP) because they focus on the word 'plan' in the question, rather than recognizing that OpEx is a fundamental cloud financial model distinct from any product or security feature.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data (e.g., encrypt emails or mark documents as confidential), not a financial or deployment model. Option B is wrong because Data Loss Prevention (DLP) is a policy-based security feature that detects and prevents accidental sharing of sensitive information (e.g., credit card numbers), not a cost or procurement model. Option D is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365 (part of the Power Platform and Teams), not a cloud concept or benefit related to payment or infrastructure.

79
MCQeasy

A company uses a cloud provider that hosts multiple customers on the same physical servers. Each customer's data and applications are isolated, but customers have no knowledge or control over the exact physical location of their resources. Which cloud characteristic does this describe?

A.Resource pooling
B.Rapid elasticity
C.On-demand self-service
D.Measured service
AnswerA

Resource pooling is the cloud characteristic that lets a provider serve many customers, or tenants, from shared physical infrastructure—servers, storage, and network—while isolating each tenant's data and workloads through virtualization and access controls. In Microsoft 365, this means compute and storage capacity are pooled across customers but logically segmented per tenant. This directly matches the scenario's wording, so it is the correct answer.

Why this answer

Resource pooling is the correct answer because the scenario describes a multi-tenant model where the cloud provider's physical and virtual resources are pooled to serve multiple customers, with isolation between tenants. Customers have no knowledge or control over the exact physical location of their resources, which is a defining characteristic of resource pooling as defined by NIST SP 800-145.

Exam trap

The trap here is that candidates often confuse resource pooling with rapid elasticity because both involve shared infrastructure, but resource pooling specifically focuses on multi-tenancy and location transparency, not dynamic scaling.

How to eliminate wrong answers

Option B (Rapid elasticity) is wrong because it refers to the ability to quickly scale resources up or down based on demand, not to multi-tenant isolation or location transparency. Option C (On-demand self-service) is wrong because it describes the capability for a user to provision computing capabilities automatically without requiring human interaction with the provider, not the pooling of resources across customers. Option D (Measured service) is wrong because it involves metering and billing based on usage (e.g., pay-per-use), not the sharing of physical infrastructure among multiple tenants.

80
MCQmedium

A company subscribes to a cloud service where they can provision virtual machines, choose the operating system, install any software, and manage all applications. The cloud provider is responsible for the underlying physical hardware and network infrastructure. Which cloud service model is being used?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises
AnswerA

IaaS is correct because the provider supplies virtualized compute, storage, and networking on physical servers it owns and operates, while customers provision these resources as virtual machines and install their own operating systems, runtime environments, and applications. This gives customers the same administrative control over the OS and application stack as they would have on physical servers, without needing to manage datacenter hardware, cooling, or power. The ability to define the OS version, configure its settings, and deploy arbitrary software exactly matches the scenario's description of controlling both OS and applications.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer provisions virtual machines, chooses the operating system, installs software, and manages applications, while the cloud provider is responsible for the underlying physical hardware and network infrastructure. In IaaS, the provider delivers virtualized computing resources over the internet, and the customer retains control over the OS, storage, and deployed applications, which matches the description exactly.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve virtual machines, but PaaS abstracts the OS and runtime, whereas IaaS gives the customer full control over the OS and software installation, as explicitly stated in the question.

How to eliminate wrong answers

Option B (PaaS) is wrong because PaaS provides a managed platform where the provider handles the OS, runtime, and middleware, and the customer only deploys and manages applications—not the OS or full software stack. Option C (SaaS) is wrong because SaaS delivers fully managed applications accessed via a browser or client, with no customer control over the underlying infrastructure, OS, or software installation. Option D (On-premises) is wrong because on-premises deployment means the customer owns and manages all hardware, software, and networking within their own data center, contradicting the cloud provider's responsibility for physical infrastructure.

81
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to reduce maintenance of power, cooling, and server replacement. Cloud concept or benefit best matches this requirement?

A.Reduced data center management
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

In Microsoft 365, Microsoft owns and operates the physical data centers, hardware, networking, and virtualization layers, so organizations eliminate the need to procure, rack, patch, and maintain physical servers. This also includes handling capacity planning, hardware failure replacement, and infrastructure-level security updates, all backed by Microsoft's SLAs. As a result, IT staff can focus on application-level configuration and business value instead of data center operations.

Why this answer

Reduced data center management is the correct answer because the requirement to reduce maintenance of power, cooling, and server replacement directly maps to the cloud benefit of offloading physical infrastructure responsibilities to the cloud provider. In Microsoft 365, this is realized through the shared responsibility model where Microsoft manages the underlying hardware, facilities, and environmental controls, allowing the organization to focus on application and data management rather than data center operations.

Exam trap

The trap here is that candidates may confuse operational benefits (like reduced maintenance) with productivity tools (Planner) or security features (DLP, sensitivity labels), rather than recognizing that the question is testing the foundational cloud concept of offloading infrastructure management to the provider.

How to eliminate wrong answers

Option B (Microsoft Planner) is wrong because it is a task management and planning tool within Microsoft 365, not a cloud concept or benefit related to reducing physical infrastructure maintenance. Option C (Data Loss Prevention or DLP) is wrong because it is a security feature that helps prevent accidental sharing of sensitive data, not a cloud concept that reduces power, cooling, or server replacement efforts. Option D (Sensitivity labels) is wrong because they are classification and protection mechanisms for data governance, not a cloud benefit addressing data center operational overhead.

82
MCQmedium

A company is migrating its on-premises workloads to Microsoft 365. The IT team wants to minimize latency for users in Europe while ensuring data residency requirements are met. Which cloud concept should the team consider?

A.Geography
B.Hybrid deployment
C.Redundancy
D.Multi-tenancy
AnswerA

Geography, in Microsoft 365/Azure, refers to the distinct regional boundary containing datacenters where your tenant data is stored at rest. During a migration, selecting the correct geography ensures data resides in the region that minimizes network latency for your users and satisfies data-residency compliance, such as staying within an EU or US boundary. Without this deliberate choice, your workloads may land in a distant region, causing slower access and regulatory exposure.

Why this answer

Geography in Microsoft 365 refers to a defined geographic boundary (e.g., Europe) that contains one or more Azure regions where data is stored and processed at rest. By selecting a Geography, the IT team ensures that user data remains within European borders to meet data residency requirements, while the proximity of the data centers to users in Europe minimizes network latency. This concept directly addresses both performance and compliance needs without requiring complex hybrid configurations.

Exam trap

The trap here is that candidates often confuse 'Geography' with 'Region' or think that 'Hybrid deployment' can solve latency and residency issues, but Geography is the specific Microsoft 365 concept that ties data residency to a fixed set of data centers within a geographic boundary.

How to eliminate wrong answers

Option B (Hybrid deployment) is wrong because it describes a mix of on-premises and cloud services, not a mechanism to control data location or latency for a specific geographic region. Option C (Redundancy) is wrong because it focuses on data replication and high availability across multiple sites, not on minimizing latency or enforcing data residency boundaries. Option D (Multi-tenancy) is wrong because it refers to sharing infrastructure among multiple customers, which does not influence where data is stored or how close it is to users.

83
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to use Microsoft 365 and another public cloud provider for different workloads. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Sensitivity labels
C.Multi-cloud
D.Data Loss Prevention (DLP)
AnswerC

Multi-cloud describes using two or more public cloud providers for different workloads, exactly matching the requirement to combine Microsoft 365 with another public cloud provider. It is a deployment model, not a licensing or cost benefit.

Why this answer

Multi-cloud is the correct answer because the requirement explicitly involves using Microsoft 365 alongside another public cloud provider for different workloads. Multi-cloud refers to the strategy of leveraging services from multiple cloud providers (e.g., Microsoft Azure and AWS) to avoid vendor lock-in, optimize costs, or meet compliance needs. This directly matches the scenario of using Microsoft 365 and another public cloud provider together.

Exam trap

The trap here is that candidates may confuse 'multi-cloud' with 'hybrid cloud' (which combines public and private cloud) or mistakenly think a specific Microsoft 365 feature like DLP or Sensitivity labels is the answer, when the question is about the overarching cloud concept of using multiple public providers.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and planning tool within Microsoft 365, not a cloud concept or benefit that addresses multi-provider workload distribution. Option B is wrong because Sensitivity labels are a Microsoft Information Protection feature used to classify and protect data based on sensitivity, not a cloud deployment model or strategy for using multiple providers. Option D is wrong because Data Loss Prevention (DLP) is a security policy mechanism to prevent accidental sharing of sensitive data, not a cloud concept describing the use of multiple cloud providers.

84
MCQeasy

A company uses a cloud storage service that automatically increases its storage capacity without any manual intervention as new files are added. This behavior is an example of which cloud computing characteristic?

A.On-demand self-service
B.Broad network access
C.Resource pooling
D.Rapid elasticity
AnswerD

Rapid elasticity is the NIST essential characteristic that allows a cloud service to provision and release resources automatically, scaling out and in quickly and in line with real-time demand. A storage service that automatically increases or decreases its capacity based on usage is a textbook example of this behavior, because the customer perceives the scaling as seamless and often without pre-planning. This precisely matches the scenario, so it is the correct answer.

Why this answer

The scenario describes storage capacity automatically increasing as new files are added, which is the essence of rapid elasticity. This cloud characteristic allows resources to scale out and in automatically, often to the point where the user perceives unlimited capacity, without requiring manual provisioning or intervention.

Exam trap

The trap here is that candidates often confuse 'resource pooling' (the multi-tenant sharing of resources) with 'rapid elasticity' (the ability to scale resources up/down automatically), because both involve dynamic allocation, but pooling is about sharing among tenants while elasticity is about scaling for a single tenant's demand.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision computing resources (e.g., spinning up a VM) through a web portal or API without human interaction with the provider, not the automatic scaling of capacity. Option B is wrong because broad network access describes the ability to access cloud services over standard network protocols (e.g., HTTPS, SSH) from a wide variety of devices (laptops, phones, tablets), not the dynamic adjustment of storage. Option C is wrong because resource pooling means the provider's computing resources are pooled to serve multiple customers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to demand; it does not describe the automatic increase in capacity for a single customer's storage.

85
MCQeasy

Refer to the exhibit. A Contoso user tries to send an email containing a credit card number to an external recipient. What will happen?

A.The email is blocked and the user receives a notification.
B.The credit card number is removed and the email is sent.
C.The email is sent and an alert is generated for admin.
D.The email is delivered to the external recipient but placed in quarantine.
AnswerA

This is correct because the DLP policy is set to enforce mode with a block action. When the credit card number is detected as a sensitive info type, Outlook or Outlook on the web displays a policy tip to the sender, and the message is not delivered. The notification informs the user that the content violates policy and that the send is prevented.

Why this answer

The DLP policy enforces blocking of credit card numbers. Option B is wrong because the policy is enforced, not just audit. Option C is wrong because it blocks, not removes.

Option D is wrong because it blocks, not quarantines.

86
MCQeasy

While preparing a Microsoft 365 adoption plan, a consultant is asked to add and remove capacity quickly when demand changes. Cloud concept or benefit best matches this requirement?

A.Rapid elasticity
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Rapid elasticity is a fundamental cloud characteristic defined by NIST, allowing resources such as compute, storage, and network capacity to scale out and in automatically or near-instantly to match fluctuating demand. In a Microsoft 365 adoption plan, this ensures services like Exchange Online and Teams can handle traffic spikes without manual provisioning or over-purchasing hardware, directly reducing cost and improving responsiveness.

Why this answer

Rapid elasticity is a core cloud computing concept defined by NIST (SP 800-145) that allows resources to be provisioned and released elastically, often automatically, to scale rapidly outward and inward commensurate with demand. In Microsoft 365, this means the consultant can quickly add or remove user licenses, storage, or service capacity via the admin center or PowerShell without manual hardware provisioning, directly matching the requirement to adjust capacity on demand.

Exam trap

The trap here is that candidates confuse a specific Microsoft 365 tool (like Planner) with a fundamental cloud characteristic (rapid elasticity), because the question asks for a 'cloud concept or benefit' but lists product names as distractors, testing whether you can distinguish between abstract cloud attributes and concrete service features.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management and planning tool within Microsoft 365, not a cloud concept or benefit related to scaling capacity. Option C is wrong because Data Loss Prevention (DLP) is a security feature that helps protect sensitive data from being shared inappropriately, not a mechanism for adding or removing capacity. Option D is wrong because sensitivity labels are classification and protection controls for data (e.g., encrypting or marking documents), unrelated to the elastic scaling of cloud resources.

87
MCQmedium

A financial services company uses a public cloud provider for its development and testing environments, but keeps its production data and applications on-premises due to strict regulatory requirements. Which cloud deployment model is the company using?

A.Hybrid cloud
B.Public cloud
C.Private cloud
D.Community cloud
AnswerA

Hybrid cloud describes an environment that integrates a public cloud provider with on-premises infrastructure, and here the company uses public cloud for dev/test while keeping production on-premises for regulatory data residency. This mixed deployment lets the organization balance scalability and cost efficiency with strict compliance requirements, which is the defining characteristic of hybrid cloud. It is not purely public or private because both resource locations are actively used.

Why this answer

The company uses a hybrid cloud model because it combines on-premises infrastructure (private cloud) for production workloads with a public cloud provider for development and testing. This allows the organization to meet strict regulatory requirements for data residency and security while leveraging the scalability and cost benefits of the public cloud for non-sensitive workloads.

Exam trap

The trap here is that candidates may confuse 'hybrid cloud' with 'public cloud' because the company uses a public provider, but the key distinction is the combination of on-premises and public resources, not exclusive use of one.

How to eliminate wrong answers

Option B (Public cloud) is wrong because the company keeps production data and applications on-premises, not entirely in the public cloud; a pure public cloud model would have all workloads hosted by a third-party provider. Option C (Private cloud) is wrong because the company uses a public cloud provider for development and testing, which is not part of a solely private cloud deployment. Option D (Community cloud) is wrong because the infrastructure is not shared among multiple organizations with common concerns (e.g., regulatory compliance); instead, it is a mix of private and public resources tailored to a single organization.

88
MCQeasy

A marketing manager can access the company's cloud resources from her laptop at home, her tablet while traveling, and her smartphone. Which essential characteristic of cloud computing does this describe?

A.Resource pooling
B.Scalability
C.Broad network access
D.Measured service
AnswerC

Broad network access is the cloud characteristic that makes capabilities available over the network and accessible through standard protocols from heterogeneous client platforms, including laptops, tablets, and smartphones. The marketing manager's ability to reach company cloud resources from multiple devices directly exemplifies this capability, because the same service is usable regardless of device type or location. This is why broad network access is the correct answer.

Why this answer

Broad network access means cloud resources can be accessed over standard network protocols (e.g., HTTPS, TLS) from a wide range of client devices, such as laptops, tablets, and smartphones. The scenario explicitly describes access from multiple device types and locations, which is the defining characteristic of broad network access as per NIST SP 800-145.

Exam trap

The trap here is that candidates confuse 'broad network access' with 'resource pooling' because both involve multiple users or devices, but resource pooling is about the provider's shared infrastructure, not the consumer's ability to use different device types.

How to eliminate wrong answers

Option A is wrong because resource pooling refers to the provider's multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to consumer demand, not to the ability to access resources from various devices. Option B is wrong because scalability (or rapid elasticity) is the capability to automatically scale resources up or down based on demand, not the cross-device access described. Option D is wrong because measured service involves metering and billing for resource usage (e.g., pay-per-use), not the device-agnostic access pattern.

89
MCQeasy

A company wants to use a cloud service that provides ready-to-use business applications such as email, collaboration, and customer relationship management without managing the underlying infrastructure. Which cloud service model is this?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Private cloud
AnswerC

SaaS is a complete, cloud-hosted application delivered over the internet, where the provider manages the entire stack—from infrastructure and middleware to security patches and version updates. Subscribers access the ready-to-use business functionality via a browser or mobile app, needing no installation or development, as exemplified by Exchange Online and Dynamics 365. This model aligns directly with the requirement of using a cloud service that provides ready-to-use business applications.

Why this answer

(SaaS) is correct because Software as a Service delivers ready-to-use business applications like Microsoft 365 (Exchange Online for email, Teams for collaboration, Dynamics 365 for CRM) over the internet, with the provider managing all underlying infrastructure, including servers, storage, and networking. The customer simply accesses the software via a web browser or client app without any responsibility for patching, scaling, or hardware maintenance.

Exam trap

The trap here is that candidates often confuse PaaS with SaaS because both abstract infrastructure, but PaaS requires the customer to develop and manage the application code, whereas SaaS provides fully functional, ready-to-use applications—a distinction Microsoft emphasizes in the MS-900 by focusing on the 'what you manage' vs. 'what the provider manages' model.

How to eliminate wrong answers

Option A (IaaS) is wrong because it provides virtualized computing resources (e.g., virtual machines, storage, networks) but requires the customer to deploy and manage their own operating systems, middleware, and applications—not ready-to-use business apps. Option B (PaaS) is wrong because it offers a platform for developing, testing, and deploying custom applications (e.g., Azure App Services) but does not include pre-built business applications like email or CRM; the customer still writes and manages the application code. Option D (Private cloud) is wrong because it refers to a deployment model where cloud resources are used exclusively by a single organization, either on-premises or hosted, and does not inherently provide ready-to-use business applications; it still requires the organization to manage or procure the software layer.

90
MCQmedium

A company needs a dedicated, private network connection between its on-premises data center and Microsoft's cloud infrastructure to support a hybrid deployment with low latency and high reliability. The connection must not traverse the public internet. Which service should they use?

A.Azure ExpressRoute
B.Azure VPN Gateway
C.Azure Virtual WAN
D.Microsoft Entra ID Application Proxy
AnswerA

Azure ExpressRoute provisions a dedicated, private Layer 2 or Layer 3 circuit through an MPLS or network service provider, extending an on-premises infrastructure directly into Azure at Microsoft edge locations without traversing the public internet. This private connectivity offers lower and more consistent latency, higher security, bandwidth up to 100 Gbps, and a 99.95% availability SLA when redundant circuits are configured. For a company that specifically requires a dedicated private network connection for hybrid workloads, ExpressRoute is the Azure service built exactly for that scenario.

Why this answer

Azure ExpressRoute is the correct choice because it provides a dedicated, private network connection from an on-premises data center directly into Microsoft's cloud infrastructure, bypassing the public internet entirely. This ensures low latency, high reliability, and consistent performance for hybrid deployments, as the traffic traverses a private MPLS or Ethernet link rather than the unpredictable internet.

Exam trap

The trap here is that candidates often confuse Azure VPN Gateway with a private connection because it uses encryption, but the key differentiator is that VPN traffic still traverses the public internet, whereas ExpressRoute bypasses it entirely for a truly private, dedicated link.

How to eliminate wrong answers

Option B (Azure VPN Gateway) is wrong because it creates an encrypted tunnel over the public internet, which means traffic traverses the internet and cannot guarantee the low latency, high reliability, or complete privacy required by the scenario. Option C (Azure Virtual WAN) is wrong because it is a networking service that aggregates branch connectivity and can use ExpressRoute or VPN, but by itself it does not provide a dedicated private connection; it is a management and routing overlay, not a direct private link. Option D (Microsoft Entra ID Application Proxy) is wrong because it is an identity and access proxy for publishing on-premises web applications to external users via the internet, not a private network connection between data centers and Azure.

91
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to use a dedicated environment controlled by one organization. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Private cloud
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerB

Private cloud is a deployment model in which computing resources are dedicated exclusively to one organization, whether hosted on-premises or by a provider. It gives the service owner isolated tenancy, custom control over networking and compliance, and predictable capacity, directly matching the scenario's cloud model or benefit. In Microsoft's portfolio, this maps to offerings like Azure Stack rather than shared Microsoft 365 services.

Why this answer

A private cloud is a dedicated environment controlled by a single organization, providing exclusive access and management over resources. This matches the requirement for a dedicated environment, as opposed to public cloud or hybrid models where control is shared or distributed.

Exam trap

The trap here is that candidates confuse Microsoft 365 service features (like Planner, DLP, or sensitivity labels) with cloud deployment models, failing to recognize that 'dedicated environment controlled by one organization' is the textbook definition of a private cloud.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool within Microsoft 365, not a cloud deployment model or concept. Option C is wrong because Data Loss Prevention (DLP) is a security policy feature that helps prevent data leaks, not a cloud environment type. Option D is wrong because sensitivity labels are classification tools for data protection, not a cloud concept describing dedicated infrastructure control.

92
Multi-Selecthard

Which THREE are key characteristics of cloud computing as defined by NIST?

Select 3 answers
A.High availability
B.Broad network access
C.Resource pooling
D.On-demand self-service
E.Reserved capacity
AnswersB, C, D

Broad network access is a NIST essential characteristic: capabilities are available over the network through standard mechanisms, accessible from heterogeneous client platforms such as laptops, tablets, and phones. This satisfies the stem's request for a NIST-defined cloud characteristic.

Why this answer

The NIST SP 800-145 definition of cloud computing lists five essential characteristics, and three of them appear here: Broad network access (B), Resource pooling (C), and On-demand self-service (D). Broad network access (B) is correct because cloud capabilities must be available over the network through standard mechanisms that promote use by heterogeneous thin or thick client platforms such as mobile phones, laptops, and PDAs. Resource pooling (C) is correct because the provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to demand.

On-demand self-service (D) is correct because a consumer can unilaterally provision computing capabilities, such as server time and network storage, automatically without requiring human interaction with each service provider. The other two NIST characteristics not listed among the options are rapid elasticity and measured service. High availability (A) is a desirable quality attribute but is not one of the five NIST essential characteristics, and reserved capacity (E) describes a purchasing or pricing model rather than a defining characteristic of cloud computing.

Exam trap

MS-900 often tests the NIST essential characteristics, and candidates may include high availability or reserved capacity because they are common cloud features, but they are not part of the NIST definition.

93
MCQmedium

A company runs a critical application on-premises but wants to extend capacity to the cloud during peak demand without purchasing additional hardware. Which cloud deployment model best describes this strategy?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Multi-cloud
AnswerC

Hybrid cloud is correct because it explicitly combines an on-premises environment with one or more public cloud services, connected through a secure, dedicated network (e.g., VPN gateway, Azure ExpressRoute) and often unified identity for consistent management. This architecture allows a critical application to remain running on-premises while 'bursting' into the public cloud during peak load—scaling out additional instances or offloading batch processing to the cloud. The company's stated goal directly matches the hybrid cloud value proposition of preserving existing investments while gaining elastic capacity and resilience.

Why this answer

A hybrid cloud model combines on-premises infrastructure (private cloud) with public cloud resources, enabling a company to 'burst' into the public cloud during peak demand without purchasing additional hardware. This strategy, often called cloud bursting, allows the critical application to run locally under normal conditions and seamlessly extend capacity to a public cloud provider like Azure during spikes.

Exam trap

The trap here is that candidates confuse 'hybrid cloud' with 'multi-cloud,' but hybrid cloud specifically involves a mix of on-premises and public cloud, while multi-cloud involves multiple public clouds without any on-premises component.

How to eliminate wrong answers

Option A is wrong because a pure public cloud model would require migrating the entire critical application off-premises, which contradicts the requirement to keep it on-premises and only extend capacity during peak demand. Option B is wrong because a private cloud is entirely on-premises and would still require purchasing additional hardware to handle peak loads, defeating the goal of avoiding hardware purchases. Option D is wrong because multi-cloud refers to using multiple public cloud providers (e.g., AWS and Azure) simultaneously, not extending an on-premises environment to the cloud.

94
MCQeasy

A company wants to run a workload that requires the highest level of physical security and control over hardware. They have the budget to purchase and maintain their own data center. Which cloud deployment model should they choose?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerB

A private cloud places infrastructure on hardware the organisation owns and controls, delivering the highest physical security and hardware control the workload demands. Because the company has budget to purchase and maintain its own data centre, this deployment model directly satisfies both constraints.

Why this answer

A private cloud deployment model is correct because it provides dedicated infrastructure for a single organization, offering the highest level of physical security and full control over hardware. This model allows the company to purchase, own, and manage its own data center, ensuring compliance with stringent security requirements and complete hardware isolation.

Exam trap

The trap here is that candidates often confuse 'hybrid cloud' with 'best of both worlds' and overlook that the question explicitly demands the highest physical security and hardware control, which only a private cloud with dedicated on-premises hardware can provide.

How to eliminate wrong answers

Option A is wrong because the public cloud model shares physical hardware among multiple tenants via hypervisors, which reduces direct control over hardware and cannot guarantee the highest level of physical security. Option C is wrong because the hybrid cloud model combines public and private clouds, but the public cloud component inherently lacks the dedicated hardware control required, and the model does not mandate exclusive hardware ownership. Option D is wrong because the community cloud model shares infrastructure among several organizations with common concerns, which still involves shared hardware and does not provide the exclusive physical control and security of a single-tenant private cloud.

95
MCQmedium

A healthcare organization must keep sensitive patient data on-premises due to regulatory compliance, but wants to use cloud services for other applications like customer relationship management and collaboration. Which cloud deployment model best meets this requirement?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerC

A hybrid cloud combines an organization's on-premises infrastructure, such as an Azure Stack edge device or local datacenter, with public cloud services via a secure connection like VPN or ExpressRoute. This allows sensitive patient data to remain resident in the on-premises environment while compute and storage for non-sensitive workloads scale into the public cloud, directly satisfying the stated requirement.

Why this answer

The hybrid cloud model is correct because it allows the healthcare organization to keep sensitive patient data on-premises (private cloud) for regulatory compliance (e.g., HIPAA), while leveraging public cloud services for customer relationship management and collaboration tools like Microsoft Dynamics 365 and Microsoft 365. This deployment model provides a unified environment where workloads can be distributed across on-premises and cloud infrastructure, ensuring data sovereignty and compliance without sacrificing scalability or cost efficiency.

Exam trap

The trap here is that candidates often confuse 'private cloud' as the only compliant option for sensitive data, overlooking that hybrid cloud allows the organization to meet compliance for specific workloads while still benefiting from public cloud economics for others.

How to eliminate wrong answers

Option A is wrong because a public cloud model would require all workloads, including sensitive patient data, to run on shared infrastructure managed by a third-party provider, which violates regulatory compliance requirements for data residency and control. Option B is wrong because a private cloud model, while secure and compliant, would force the organization to host all applications—including CRM and collaboration tools—on-premises, negating the cost and scalability benefits of cloud services for non-sensitive workloads. Option D is wrong because a community cloud is designed for organizations with shared compliance concerns (e.g., multiple healthcare entities), but it still requires all participants to adhere to a common regulatory framework and does not inherently allow selective placement of sensitive data on-premises while using public cloud for other apps.

96
MCQeasy

Which cloud computing characteristic allows users to provision resources such as virtual machines and storage without requiring human interaction with the service provider?

A.Measured service
B.On-demand self-service
C.Resource pooling
D.Rapid elasticity
AnswerB

On-demand self-service lets consumers provision compute and storage capabilities automatically, without human interaction with the provider. This directly satisfies the stem's constraint: resources are obtained unilaterally through self-service portals or APIs, with no manual request or approval from Microsoft. Elasticity and measured service address scaling and billing, not autonomous provisioning.

Why this answer

On-demand self-service is the cloud characteristic that lets consumers provision computing capabilities such as VMs and storage automatically, without requiring human interaction with the service provider. This is one of the five essential characteristics defined by NIST SP 800-145. It directly matches the scenario of unilaterally provisioning resources via a portal or API.

Exam trap

The trap is confusing the five NIST characteristics—candidates often pick rapid elasticity because provisioning sounds like scaling, but the key phrase is 'without human interaction with the service provider,' which defines self-service.

How to eliminate wrong answers

Option A is wrong because measured service refers to automatic metering and billing of resource usage, not the ability to self-provision. Option C is wrong because resource pooling describes the provider's multi-tenant model where resources are pooled to serve multiple consumers, not the user's ability to provision independently. Option D is wrong because rapid elasticity is about scaling resources up or down quickly to match demand, not the initial self-service provisioning action.

97
MCQmedium

A company uses Infrastructure-as-a-Service (IaaS) from a cloud provider. They have deployed virtual machines running a custom application. The cloud provider supplies the physical hardware, networking, and storage. Who is responsible for patching the operating system of the virtual machines?

A.The cloud provider
B.The customer
C.Both the provider and the customer share equally
D.A third-party managed security service provider
AnswerB

The customer is the correct answer because IaaS delivers raw compute, storage, and networking, leaving the customer in full control of the guest OS, middleware, runtime, data, and applications. This means the customer must apply OS patches, configure firewalls, harden the system, manage user access, and protect workloads against malware and vulnerabilities. Under the shared responsibility model, this is a firm, non-transferable obligation for the IaaS consumer, even if some tasks are automated or delegated.

Why this answer

In an IaaS model, the cloud provider is responsible for the physical infrastructure (hardware, networking, storage), but the customer retains responsibility for the guest OS and application stack. Patching the operating system of virtual machines is a customer task because the customer controls the OS image and has full administrative access to the VM. This follows the shared responsibility model where the provider secures the hypervisor and physical layer, while the customer secures the OS and applications.

Exam trap

The trap here is that candidates confuse IaaS with PaaS or SaaS, assuming the cloud provider patches everything, but in IaaS the customer is explicitly responsible for the guest OS and applications.

How to eliminate wrong answers

Option A is wrong because the cloud provider patches only the hypervisor and physical infrastructure, not the guest OS inside the VM; the customer manages the OS. Option C is wrong because responsibility is not shared equally for OS patching—the provider handles the underlying platform, and the customer handles the OS and applications. Option D is wrong because a third-party MSSP is an optional service the customer could contract, but it is not the default responsibility assignment in the IaaS shared responsibility model.

98
MCQmedium

A department head asks which Microsoft 365 option should be used to review uptime commitments for Microsoft cloud services. Cloud concept or benefit best matches this requirement?

A.Data Loss Prevention (DLP)
B.Microsoft Planner
C.Sensitivity labels
D.Service Level Agreement (SLA)
AnswerD

A Service Level Agreement formally documents Microsoft's uptime commitments for cloud services, giving the department head the guaranteed availability percentages and remedies. This matches the requirement to review uptime commitments rather than general reliability guidance.

Why this answer

The Service Level Agreement (SLA) is the correct choice because it is the formal document published by Microsoft that defines the uptime commitments, availability guarantees, and financial remedies for Microsoft cloud services. The department head needs to review uptime commitments, which is exactly what the SLA covers, not a security or project management feature.

Exam trap

The trap here is that candidates often confuse operational features (like DLP or sensitivity labels) with contractual documents, assuming any Microsoft 365 tool that 'protects' or 'manages' something could cover uptime, when only the SLA provides legally binding availability commitments.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is a security policy that prevents sensitive information from being shared or leaked, not a document that defines uptime commitments. Option B is wrong because Microsoft Planner is a task management and project planning tool within Microsoft 365, not a source of service availability guarantees. Option C is wrong because sensitivity labels are used to classify and protect data based on its sensitivity level, not to provide uptime or service-level commitments.

99
MCQmedium

A company wants to run a critical application that requires dedicated hardware to comply with regulatory isolation requirements. However, they want to avoid the upfront cost of building their own data center. Which cloud deployment model meets these needs?

A.Private cloud
B.Public cloud
C.Hybrid cloud
D.Community cloud
AnswerA

A private cloud delivers a single-tenant environment on dedicated physical hardware, giving the organization exclusive access to compute, storage, and networking. This fully satisfies the requirement for dedicated hardware while still providing cloud-like self-service and scalability. If hosted by a third-party, it also eliminates capital expenditure and can be tailored to meet regulatory or compliance constraints.

Why this answer

A private cloud is the correct deployment model because it provides dedicated hardware and infrastructure for a single organization, ensuring regulatory isolation without requiring the company to build and maintain its own on-premises data center. In Azure, a private cloud can be implemented via Azure Stack Hub or Azure VMware Solution, which run in the customer's own environment or a dedicated hosted environment, meeting compliance needs while avoiding upfront capital expenditure.

Exam trap

The trap here is that candidates often confuse 'private cloud' with 'on-premises only,' forgetting that a private cloud can be hosted by a third-party provider like Azure Stack Hub, which offers dedicated hardware without the upfront cost of building a data center.

How to eliminate wrong answers

Option B (Public cloud) is wrong because it uses shared multi-tenant infrastructure that cannot guarantee the dedicated hardware isolation required for strict regulatory compliance. Option C (Hybrid cloud) is wrong because it combines public and private clouds but does not inherently provide dedicated hardware; the public cloud portion still lacks isolation. Option D (Community cloud) is wrong because it is shared among several organizations with common concerns, not dedicated to a single company, and thus cannot meet the requirement for exclusive hardware isolation.

100
MCQeasy

A business stakeholder asks how Microsoft 365 can help them create a short-term test environment and delete it after the pilot. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Agility
C.Data Loss Prevention (DLP)
D.Microsoft Planner
AnswerB

Cloud agility lets the business provision a short-term test environment on demand and tear it down once the pilot ends, paying only for what is used. This directly satisfies the stem's requirement to create and delete a temporary pilot environment quickly without long procurement cycles.

Why this answer

Agility is the correct answer because it refers to the ability to rapidly provision and deprovision resources, such as creating a short-term test environment and deleting it after a pilot. Microsoft 365's cloud-based infrastructure enables on-demand scaling and resource lifecycle management, allowing organizations to spin up environments quickly and tear them down without long-term commitments or hardware procurement delays.

Exam trap

The trap here is that candidates confuse agility with data protection features (sensitivity labels or DLP) or productivity tools (Planner), because the question mentions 'test environment' and 'delete' which superficially sounds like data management or task tracking, but the core cloud concept is rapid provisioning and deprovisioning.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data based on sensitivity (e.g., confidential or restricted), not to manage temporary environments. Option C is wrong because Data Loss Prevention (DLP) policies prevent unauthorized sharing or leakage of sensitive data, not environment lifecycle management. Option D is wrong because Microsoft Planner is a task management and collaboration tool for organizing work, not for provisioning or deleting cloud test environments.

101
MCQeasy

A business stakeholder asks how Microsoft 365 can help them use hosted email without managing mail servers. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Community cloud
C.Software as a Service (SaaS)
D.Infrastructure as a Service (IaaS)
AnswerC

Software as a Service (SaaS) is a cloud service model where the provider operates the complete application, including the underlying infrastructure, platform, and application code, and delivers it to users over the internet. Microsoft 365 exemplifies SaaS with services such as Exchange Online, Microsoft Teams, and Word Web App, which Microsoft patches and updates centrally. This matches the stakeholder's goal of using business tools immediately without managing servers or software installations, making it the correct answer.

Why this answer

Microsoft 365 delivers hosted email (Exchange Online) as a Software as a Service (SaaS) offering, where Microsoft manages the mail servers, patches, and infrastructure. The stakeholder simply uses the service via a web browser or client without any server administration. This aligns with the SaaS model, which provides ready-to-use applications over the internet.

Exam trap

The trap here is that candidates confuse PaaS with SaaS because both involve managed services, but PaaS still requires the customer to deploy and manage the application code (e.g., a custom email server), whereas SaaS delivers the fully functional application itself.

How to eliminate wrong answers

Option A is wrong because PaaS provides a platform (runtime, database, middleware) for developers to build and deploy custom applications, not a ready-to-use hosted email service. Option B is wrong because a community cloud is a deployment model shared by several organizations with common concerns (e.g., compliance), not a service model that delivers hosted email without server management. Option D is wrong because IaaS provides virtualized computing resources (VMs, storage, networking) that still require the customer to manage operating systems and mail server software, contradicting the requirement to avoid managing mail servers.

102
MCQeasy

A company runs a virtual machine in Azure that hosts a web application. The company is responsible for configuring the operating system, installing web server software, and managing application updates. The cloud provider is responsible for the physical hardware, networking, and data center security. Which cloud service model does this represent?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerC

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, where the cloud provider supplies the physical hardware, virtualization, networking, and storage, but you are responsible for installing and managing the guest OS, middleware, and applications. For a VM hosting a web app, IaaS matches because you manage the OS, apply patches, configure the web server, and maintain the app itself. Azure Virtual Machines is a classic IaaS offering that gives you full administrative control.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer manages the operating system, web server software, and application updates, while the cloud provider handles the physical hardware, networking, and data center security. In IaaS, the provider offers virtualized computing resources over the internet, and the customer retains control over the guest OS and installed software, which matches the responsibilities outlined.

Exam trap

The trap here is that candidates confuse PaaS with IaaS because both involve deploying applications, but the key differentiator is whether the customer manages the OS and installed software—PaaS abstracts the OS, while IaaS does not.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) would have the provider manage the entire application stack, including the OS and software, leaving the customer only to use the application—here the customer configures the OS and installs web server software. Option B is wrong because Platform as a Service (PaaS) abstracts the OS and runtime, with the provider managing the underlying OS and middleware, but the customer is responsible for configuring the OS and installing web server software, which is not typical for PaaS. Option D is wrong because Function as a Service (FaaS) is a serverless compute model where the provider manages all infrastructure and the customer only deploys individual functions, not a full VM with OS and web server management.

103
MCQmedium

A tenant administrator is advising a department that wants to keep services available during a hardware failure. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.High availability
D.Sensitivity labels
AnswerC

High availability keeps services reachable during hardware failure by using redundancy such as multiple nodes, load balancing, and failover, so no single component outage causes downtime. This matches the department's requirement to maintain continuous service availability.

Why this answer

High availability (C) is the correct answer because it directly addresses the requirement to keep services available during a hardware failure. High availability refers to a system's ability to remain operational and accessible despite component failures, typically achieved through redundancy, failover clustering, and load balancing. In Microsoft 365, this is implemented via redundant infrastructure across multiple datacenters and automatic failover mechanisms, ensuring service continuity without manual intervention.

Exam trap

The trap here is that candidates confuse high availability with disaster recovery or data protection features like DLP, but high availability specifically focuses on minimizing downtime during failures, not on preventing data loss or classifying data.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management application, not a cloud concept or benefit; it does not provide infrastructure-level availability during hardware failures. Option B is wrong because Data Loss Prevention (DLP) is a security feature that helps prevent sensitive information from being shared inappropriately, but it has no role in maintaining service availability during hardware outages. Option D is wrong because sensitivity labels are used for data classification and protection (e.g., encryption, marking), not for ensuring uptime or resilience against hardware failures.

104
MCQeasy

A colleague says, 'The public cloud is cheaper because you only pay for the resources you use, like compute hours or storage space.' Which cloud computing characteristic directly supports this pay-as-you-go model?

A.Rapid elasticity
B.Broad network access
C.Measured service
D.On-demand self-service
AnswerC

Measured service is the cloud feature that automates the metering of resource usage, such as CPU time, storage GBs, and network bandwidth, at a granular level. It is this metering capability that enables the pay-as-you-go model, where customers are billed only for the actual consumption, and it allows providers to offer variable pricing that can be lower for sporadic workloads compared to on-premises fixed capacity. This direct linkage between usage and billing is why measured service, not elasticity or self-service, is the correct answer.

Why this answer

Measured service is the cloud computing characteristic that enables a pay-as-you-go model by metering resource usage (e.g., compute hours, storage GB-months, outbound data transfer) and providing transparent billing based on actual consumption. This allows providers like Azure to charge only for what is used, directly supporting the colleague's statement that the public cloud is cheaper because you pay only for resources consumed.

Exam trap

The trap here is that candidates often confuse on-demand self-service (the ability to provision resources without waiting) with the billing model, but on-demand self-service does not inherently include usage metering or pay-as-you-go pricing.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to automatically scale resources up or down quickly based on demand, not to the metering or billing mechanism that supports pay-as-you-go. Option B is wrong because broad network access describes the ability to access cloud services over the network via standard protocols (e.g., HTTPS, SSH), which enables connectivity but does not involve usage tracking or cost allocation. Option D is wrong because on-demand self-service allows users to provision resources without human interaction (e.g., via the Azure portal or CLI), but it does not inherently include the metering or billing logic that makes pay-as-you-go possible.

105
MCQhard

A multinational corporation needs to design a cloud strategy that allows them to keep sensitive financial data on-premises while using public cloud for customer-facing apps. Which deployment model should they adopt?

A.Hybrid cloud
B.Private cloud
C.Public cloud
D.Multi-cloud
AnswerA

Hybrid cloud combines on-premises infrastructure with public cloud services, letting the corporation retain sensitive financial data in its own datacentre while hosting customer-facing apps in the public cloud. This directly satisfies the stem's split requirement, unlike pure public or private models. Microsoft Entra ID can broker identity across both environments.

Why this answer

A hybrid cloud combines on-premises infrastructure with public cloud services, connected so workloads and data can span both environments. Keeping sensitive financial data on-premises for compliance while running customer-facing apps in the public cloud is the textbook hybrid scenario, since it preserves data residency and control where required while gaining public cloud elasticity elsewhere.

Exam trap

MS-900 often tests the confusion between hybrid and multi-cloud — candidates pick multi-cloud because it sounds more flexible, forgetting that multi-cloud means multiple public providers, not on-prem plus public.

How to eliminate wrong answers

Option B is wrong because a private cloud is dedicated solely to one organization and does not include public cloud for customer-facing apps — it addresses control but not the requirement to use public cloud. Option C is wrong because a pure public cloud cannot keep sensitive financial data on-premises, violating the stated data residency requirement. Option D is wrong because multi-cloud means using two or more public cloud providers (e.g., Azure and AWS) and says nothing about on-premises integration, so it does not satisfy the on-prem data requirement.

106
MCQmedium

Your company is moving to Microsoft 365 and wants to reduce capital expenditure (CapEx) on hardware and software licenses. Which cloud benefit is most directly related to this goal?

A.Scalability
B.Consumption-based pricing
C.Agility
D.Security
AnswerB

Consumption-based pricing converts upfront hardware and licence purchases into operating expenditure, billed only for resources actually used. This directly satisfies the stem's CapEx reduction goal, since Microsoft 365 subscriptions remove large initial capital outlays and shift spending to predictable monthly operational costs.

Why this answer

Consumption-based pricing (also called pay-as-you-go) directly reduces capital expenditure because organizations no longer purchase hardware or perpetual software licenses upfront; instead they pay only for the resources and licenses they consume. This shifts spending from CapEx to OpEx, which is the core financial benefit the company is seeking. Scalability, agility, and security are cloud benefits but do not directly address the CapEx reduction goal.

Exam trap

MS-900 often tests the CapEx vs. OpEx distinction, and candidates may confuse 'scalability' or 'agility' with the financial benefit — the key is recognizing that consumption-based pricing is the specific cloud characteristic that eliminates upfront capital spending.

How to eliminate wrong answers

Option A is wrong because scalability refers to the ability to grow or shrink resources on demand; while valuable, it does not by itself eliminate upfront hardware or license purchases. Option C is wrong because agility describes the speed at which an organization can deploy and adapt services, not the financial model that reduces CapEx. Option D is wrong because security is a cloud benefit related to protection and compliance, not to the capital-expenditure reduction the company wants.

107
Multi-Selecteasy

A business wants to use a cloud solution where they can scale computing resources up or down automatically based on demand and only pay for what they use. The cloud provider manages the underlying hardware. Which two cloud characteristics are being described? (Choose two.)

Select 2 answers
A.Elasticity
B.Measured service
C.Scalability
D.High availability
AnswersA, B

Elasticity is the cloud computing characteristic that allows resources to be automatically scaled up or down in response to real-time demand. In the scenario, the business can dynamically adjust resource consumption without manual intervention, ensuring they only provision what is needed. This automatic provisioning and deprovisioning directly aligns with the definition of elasticity, which is distinct from mere scalability because it responds to fluctuations in workload instantaneously.

Why this answer

Elasticity is correct because it describes the ability to automatically scale computing resources up or down based on demand, which is a key characteristic of cloud computing. The scenario explicitly states that resources scale automatically, which aligns with elasticity rather than just the ability to scale (scalability). Measured service is correct because the business pays only for what they use, which is the pay-per-use billing model enabled by metering resource consumption.

Exam trap

The trap here is that candidates confuse scalability (the ability to scale) with elasticity (automatic scaling based on demand), and they overlook measured service as a distinct characteristic because they focus only on the scaling aspect rather than the pay-per-use billing model explicitly stated in the question.

108
MCQeasy

A help desk lead is documenting the correct Microsoft 365 approach to use hosted email without managing mail servers. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Community cloud
C.Software as a Service (SaaS)
D.Infrastructure as a Service (IaaS)
AnswerC

SaaS delivers fully hosted applications where the provider manages servers, patching and availability. Microsoft 365 email is consumed directly, so the help desk needs no mail server administration. This matches the requirement of hosted email without managing infrastructure.

Why this answer

Microsoft 365's Exchange Online delivers hosted email as a Software as a Service (SaaS) offering. This means Microsoft manages the mail servers, software updates, and infrastructure, while the help desk lead simply configures user mailboxes and policies via the admin center. SaaS is the cloud model where the provider hosts and manages the entire application, aligning perfectly with the requirement to avoid managing mail servers.

Exam trap

The trap here is that candidates confuse PaaS with SaaS because both involve managed services, but PaaS requires you to manage the application code and runtime, whereas SaaS delivers a fully finished application like Exchange Online, eliminating all server management tasks.

How to eliminate wrong answers

Option A is wrong because Platform as a Service (PaaS) provides a runtime environment for deploying custom applications, not a ready-to-use hosted email service; you would still need to build and manage the email application code. Option B is wrong because Community cloud is a deployment model where infrastructure is shared among several organizations with common concerns (e.g., compliance), not a service model that delivers hosted email without server management. Option D is wrong because Infrastructure as a Service (IaaS) provides virtualized servers, storage, and networking, requiring the customer to install, configure, and manage the email server software (e.g., Exchange Server) themselves, which contradicts the 'without managing mail servers' requirement.

109
Multi-Selecteasy

Which two statements correctly describe SaaS in a cloud computing model? (Choose 2.)

Select 2 answers
A.Users access a complete application provided by the cloud service provider.
B.The provider manages the underlying infrastructure and application platform.
C.Customers manage the operating system patching.
D.Customers deploy their own runtime environment.
AnswersA, B

In SaaS, the cloud service provider delivers a finished, functional application to end users over the internet, typically through a web browser or thin client. Users do not install, deploy, or host the software on their own devices or servers; they simply consume the hosted application and its features. This is the defining characteristic of the SaaS model, as the customer sees only the application interface and data, not the underlying stack.

Why this answer

In the SaaS model, users access a complete application—such as Microsoft 365—that is hosted and managed entirely by the cloud service provider. The provider handles all aspects of the application, including availability, performance, and security, while the user simply consumes the software via a web browser or client. This aligns with the NIST definition of SaaS, where the consumer does not manage or control the underlying cloud infrastructure or even individual application capabilities.

Exam trap

The trap here is that candidates confuse SaaS with PaaS or IaaS, mistakenly thinking customers are responsible for OS patching (Option C) or deploying their own runtime (Option D), when in fact SaaS abstracts all underlying layers away from the consumer.

110
MCQeasy

A cloud provider allows customers to provision virtual machines, storage, and other resources through a web portal without requiring human interaction with the provider's staff. Which cloud computing characteristic does this best illustrate?

A.Rapid elasticity
B.Measured service
C.Resource pooling
D.On-demand self-service
AnswerD

On-demand self-service is the cloud characteristic that lets a consumer unilaterally provision computing capabilities—such as virtual machines, storage, and databases—automatically, using a self-service interface like a web portal, CLI, or REST API, with no human interaction with the cloud provider. In the question's scenario, the customer directly requests and configures a VM and receives it without waiting for an administrator, which is precisely the definition of this capability. It is a foundational trait that distinguishes cloud computing from traditional IT operations, where provisioning requires a service desk ticket and human approval.

Why this answer

The scenario describes a user provisioning resources through a web portal without any human interaction from the provider. This directly matches the NIST SP 800-145 definition of on-demand self-service, where a consumer can unilaterally provision computing capabilities as needed automatically without requiring human interaction with each service provider.

Exam trap

The trap here is that candidates confuse the 'self-service' aspect of provisioning with 'rapid elasticity' because both involve speed, but the question specifically highlights the lack of human interaction, which is the defining feature of on-demand self-service, not the scaling behavior.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to quickly scale resources up or down, often automatically, not the method of provisioning without human contact. Option B is wrong because measured service involves monitoring, controlling, and reporting resource usage for billing and optimization, not the self-provisioning capability. Option C is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned to serve multiple consumers, not the consumer's ability to provision without staff interaction.

111
MCQmedium

A company needs to ensure that their cloud data and applications remain available even if an entire Azure region experiences an outage. They also want to minimize latency by hosting resources in multiple geographic locations. Which cloud concept addresses these requirements?

A.Scalability
B.Geo-redundancy
C.Measured service
D.Resource pooling
AnswerB

Geo-redundancy stores synchronous or asynchronous copies of data in a secondary Azure region, commonly a paired region, and automatically fails over or permits customer-triggered failover when the primary region becomes unavailable. Azure Storage geo-redundant storage (GRS) and geo-zone-redundant storage (GZRS) maintain a second copy hundreds of miles away, while read-access geo-redundant storage (RA-GRS) additionally lets applications read from the secondary region, improving availability and lowering latency for nearby users.

Why this answer

Geo-redundancy (Option B) is correct because it specifically addresses the requirement for data and application availability during an entire Azure region outage by replicating resources across multiple geographically separated regions, such as Azure paired regions (e.g., East US and West US). This also minimizes latency by allowing traffic to be routed to the nearest available region, leveraging Azure Traffic Manager or Azure Front Door for global load balancing.

Exam trap

The trap here is that candidates often confuse geo-redundancy with high availability within a single region (e.g., Availability Zones) or mistakenly think scalability or resource pooling can provide region-level disaster recovery, but only geo-redundancy ensures data and app availability across entire regions.

How to eliminate wrong answers

Option A is wrong because scalability refers to the ability to increase or decrease resources (e.g., compute or storage) to handle demand, not to maintain availability during a region-wide outage or to reduce latency across geographic locations. Option C is wrong because measured service is a cloud characteristic where usage is metered and billed (e.g., pay-as-you-go), which does not address disaster recovery or geographic latency. Option D is wrong because resource pooling describes the multi-tenant model where provider resources are shared among customers (e.g., Azure's hypervisor isolation), not the replication of data across regions for high availability.

112
Multi-Selecteasy

A company uses a cloud service where they pay only for the compute hours their virtual machines run. They can increase or decrease the number of VMs instantly based on demand. Which two cloud computing characteristics are demonstrated? (Choose two.)

Select 2 answers
A.On-demand self-service
B.Rapid elasticity
C.Measured service
D.Resource pooling
AnswersB, C

Rapid elasticity is the cloud characteristic that enables resources to be provisioned and released elastically, often automatically, to scale outward and inward commensurate with demand. In this scenario, the company's ability to increase or decrease the number of virtual machines based on demand is a textbook example of rapid elasticity, as it directly addresses the agility and scalability of resource allocation. This elasticity is what allows the company to align its resource usage with actual workload, rather than over-provisioning for peak demand.

Why this answer

B is correct because rapid elasticity allows the company to instantly increase or decrease the number of virtual machines based on demand, scaling resources up or down automatically. C is correct because measured service ensures that the company pays only for the compute hours their VMs run, with usage metered and billed accordingly.

Exam trap

The trap here is that candidates often confuse 'on-demand self-service' with the ability to instantly scale resources, but on-demand self-service specifically refers to the user's ability to provision resources without provider intervention, not the elasticity of scaling.

113
MCQeasy

An administrator is reviewing a request from users who need to avoid buying servers upfront and pay monthly based on usage. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Data Loss Prevention (DLP)
C.Operational expenditure (OpEx) model
D.Microsoft Planner
AnswerC

The operational expenditure (OpEx) model charges for cloud solutions on a subscription or pay-as-you-go basis, so organizations pay a recurring fee for capacity instead of making a large upfront capital investment in hardware. Microsoft 365, for example, typically costs per user per month, covering licensing, maintenance, and infrastructure. This approach directly aligns with the users' need to avoid buying servers because it converts fixed capital expenditure into variable operating expenses that scale with actual usage.

Why this answer

The requirement to avoid upfront server purchases and pay monthly based on usage directly aligns with the operational expenditure (OpEx) model, a key cloud computing benefit. In cloud services, OpEx shifts costs from capital expenditure (CapEx) to a pay-as-you-go or subscription-based model, eliminating the need for large upfront hardware investments. This is a fundamental concept in Microsoft Azure and other cloud platforms, where resources like virtual machines are billed monthly based on actual consumption.

Exam trap

The trap here is that candidates often confuse OpEx with other cloud benefits like scalability or elasticity, but the question specifically tests the financial distinction between paying upfront (CapEx) versus paying monthly based on usage (OpEx).

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data based on sensitivity (e.g., confidential, public), not a financial or deployment model. Option B is wrong because Data Loss Prevention (DLP) is a security policy mechanism that detects and prevents unauthorized sharing of sensitive data, unrelated to cost models or server procurement. Option D is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, designed for organizing work, not for financial planning or infrastructure purchasing.

114
MCQmedium

A development team wants to build a custom web application. They choose a cloud service that provides the runtime environment, operating system, and middleware, but the team is responsible for writing and deploying their own code. The provider automatically applies patches to the underlying infrastructure. Which cloud service model best describes this approach?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Function as a Service (FaaS)
AnswerB

Platform as a Service (PaaS) is correct because it provides a fully managed hosting environment that includes the operating system, language runtime, web server, and middleware, along with built-in deployment and scaling features. In a service like Azure App Service, the development team simply deploys its custom code and configuration, and the platform handles patching, load balancing, and high availability. This allows the team to focus on building the application rather than maintaining the underlying infrastructure.

Why this answer

Platform as a Service (PaaS) provides the runtime environment, operating system, and middleware, allowing developers to focus on writing and deploying their own code while the cloud provider manages the underlying infrastructure, including automatic patching. This model abstracts the hardware and OS layer, giving the team full control over application code but not the platform stack.

Exam trap

The trap here is that candidates confuse IaaS with PaaS because both involve deploying custom code, but IaaS requires the team to manage the OS and middleware patching, whereas PaaS automates that responsibility.

How to eliminate wrong answers

Option A (IaaS) is wrong because it provides virtualized computing resources (e.g., VMs, storage, networking) where the team is responsible for managing the operating system, middleware, and runtime, including patching, which contradicts the automatic patching described. Option C (SaaS) is wrong because it delivers fully functional software applications over the internet, where the provider manages everything, and the team would not write or deploy their own code. Option D (FaaS) is wrong because it is a serverless compute model where code runs in response to events, and the provider manages the runtime environment, but it does not include middleware or a full runtime environment like a web server; it is a subset of PaaS focused on individual functions.

115
Multi-Selectmedium

An e-commerce company hosts its website on a public cloud IaaS platform. The site experiences varying traffic throughout the year. The cloud provider automatically adds more virtual servers during peak traffic and removes them when demand drops. The company only pays for the resources used during each period. Which two cloud characteristics are demonstrated? (Choose two.)

Select 2 answers
A.Rapid elasticity
B.Measured service
C.On-demand self-service
D.Resource pooling
AnswersA, B

Rapid elasticity is a core NIST characteristic of cloud computing where resources can be provisioned and released automatically, often in response to demand, to scale outward and inward rapidly. In this IaaS scenario, the automatic addition and removal of VMs based on traffic levels directly demonstrates this capability, making it the correct answer.

Why this answer

Rapid elasticity is demonstrated because the cloud provider automatically scales virtual servers up or down in response to varying traffic, which is a key characteristic of cloud computing where resources can be provisioned and released elastically to match demand. Measured service is demonstrated because the company only pays for the resources used during each period, meaning the provider meters resource usage (e.g., CPU hours, memory, bandwidth) and bills accordingly, which is a core attribute of cloud services.

Exam trap

The trap here is that candidates often confuse 'on-demand self-service' with automatic scaling, but on-demand self-service is about manual provisioning without provider interaction, not about the system's ability to scale automatically based on load.

116
MCQmedium

A healthcare company must keep patient records in a specific country and wants Microsoft to guarantee that data remains within that geography. The company also needs to know which Microsoft 365 services are available in that region. Which Microsoft 365 capability should the company review?

A.Microsoft 365 network connectivity principles
B.Microsoft 365 service health dashboard
C.Microsoft 365 data residency commitments
D.Microsoft 365 backup and restore
AnswerC

Microsoft 365 data residency commitments define where customer data at rest is stored for core workloads and which geographies support those workloads. Reviewing these commitments lets the healthcare company verify that patient records remain in the required country and understand service availability by region. This directly addresses the compliance and location requirements described in the scenario.

Why this answer

Data residency commitments specify the geographic locations where Microsoft stores customer data at rest and which services are available in each geography. The healthcare company needs that contractual and architectural assurance to keep patient records in the required country. Backup, network connectivity, and service health features address recovery, performance, and incidents, but none of them establish or document where data resides.

Exam trap

The trap here is assuming any Microsoft 365 operational or security feature automatically guarantees where customer data is stored.

117
MCQhard

A company runs a legacy application that requires a fixed amount of dedicated hardware resources for compliance reasons. However, they want to benefit from cloud-based backup and disaster recovery to reduce on-premises hardware costs. Which cloud deployment model best aligns with this requirement?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerC

Hybrid cloud combines a private or on-premises environment with public cloud services, typically over a secure VPN or dedicated connection like Azure ExpressRoute. This lets the legacy application continue running in a dedicated private space with fixed resources, while backup, disaster recovery, or scale-out workloads are offloaded to the public cloud, decreasing the on-premises footprint. The resulting reduction in physical infrastructure, energy, and maintenance directly lowers on-premises cost while preserving the application's required isolation.

Why this answer

Hybrid cloud is correct because it allows the company to keep the legacy application on dedicated on-premises hardware for compliance, while leveraging cloud-based backup and disaster recovery services (e.g., Azure Backup and Azure Site Recovery) to reduce on-premises hardware costs. This model combines private cloud (or on-premises infrastructure) with public cloud resources, enabling data replication and failover to the cloud without migrating the application itself.

Exam trap

The trap here is that candidates often confuse 'hybrid cloud' with 'private cloud' because both involve on-premises resources, but the key differentiator is the use of public cloud services for backup/DR to reduce hardware costs, which only hybrid cloud enables.

How to eliminate wrong answers

Option A is wrong because public cloud would require running the legacy application entirely on shared cloud infrastructure, which cannot guarantee the fixed amount of dedicated hardware resources needed for compliance. Option B is wrong because private cloud, while providing dedicated resources, does not inherently reduce on-premises hardware costs as it still requires maintaining all hardware on-site or in a dedicated data center. Option D is wrong because community cloud is designed for organizations with shared compliance concerns (e.g., government or healthcare), but it does not specifically address the need for dedicated hardware for a single company's legacy application while also reducing on-premises costs via cloud backup.

118
MCQmedium

During requirements gathering, an IT manager says the organization must keep services available during a hardware failure. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.High availability
D.Sensitivity labels
AnswerC

High availability is the cloud characteristic that keeps services operational and user-accessible even when specific components, such as servers, disks, or network paths, fail. It is implemented through redundant design, automatic failover, load balancing, and continuous health monitoring that routes traffic away from unhealthy nodes. Microsoft 365 contractually guarantees a monthly uptime percentage through its Service Level Agreement, which is typically expressed in 'nines' (e.g., 99.9%), directly matching an IT manager's expectation that 'this needs to be available no matter what.'

Why this answer

High availability (C) is the correct cloud concept because it directly addresses the requirement to keep services operational during hardware failure. In Microsoft 365, high availability is achieved through redundant infrastructure, such as multiple server instances across different Azure availability zones, and automatic failover mechanisms that ensure service continuity without manual intervention.

Exam trap

The trap here is that candidates may confuse high availability with disaster recovery, but the question specifically asks about keeping services available during a hardware failure, which is the definition of high availability, not the broader recovery from a major outage.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management application within Microsoft 365, not a cloud concept or benefit related to service availability during hardware failure. Option B is wrong because Data Loss Prevention (DLP) is a security feature that helps prevent sensitive information from being shared or leaked, focusing on data protection rather than infrastructure resilience. Option D is wrong because Sensitivity labels are classification and protection tools for data governance, used to apply encryption and access restrictions, not to maintain service uptime during hardware failures.

119
MCQmedium

Refer to the exhibit. A Microsoft 365 admin configures an update policy for Microsoft 365 Apps for enterprise. The channel is set to 'CurrentChannel'. What is the expected behavior for users?

A.Users receive feature updates monthly.
B.Users receive feature updates twice a year.
C.Users receive feature updates as soon as they are released.
D.Users receive updates only after the deadline.
AnswerC

CurrentChannel delivers feature updates as soon as Microsoft releases them, with no fixed deferral. Devices on this channel therefore receive new features immediately rather than after the scheduled delays applied to Monthly Enterprise Channel or Semi-Annual Channel.

Why this answer

The Current Channel in Microsoft 365 Apps for enterprise provides feature updates as soon as they are released, typically monthly, but the key is that users receive them as soon as they are available, without a fixed delay. This channel is designed for users who want the latest features immediately. The expected behavior is that users receive feature updates as soon as they are released, which aligns with option C.

Exam trap

The trap is confusing Current Channel with Monthly Enterprise Channel; both provide monthly updates, but Current Channel delivers features as soon as they are released, while Monthly Enterprise Channel follows a more predictable monthly schedule with a slight delay.

How to eliminate wrong answers

Option A is wrong because while Current Channel does receive monthly feature updates, the statement 'monthly' is not precise; the channel delivers updates as soon as they are released, which is typically monthly but can vary. Option B is wrong because twice-a-year feature updates correspond to the Semi-Annual Enterprise Channel, not Current Channel. Option D is wrong because updates are not held until a deadline; that behavior is associated with deadlines set for updates, but the channel itself does not delay updates until a deadline.

120
MCQeasy

A small accounting firm wants its staff to work from home using Microsoft 365. The partners want to avoid buying new servers and want predictable monthly costs instead of large upfront hardware purchases. Which cloud benefit does this describe?

A.CapEx to OpEx shift
B.High availability
C.Disaster recovery
D.Elasticity
AnswerA

Moving from on-premises servers to Microsoft 365 replaces large upfront capital expenditure on hardware with ongoing operational expenditure in the form of subscription fees. The firm avoids buying servers and gains predictable monthly costs, which is exactly the CapEx-to-OpEx benefit of cloud services. This matches the partners' stated financial goal.

Why this answer

Cloud services replace upfront capital purchases with subscription-based operating expenses, which is the CapEx-to-OpEx shift. The accounting firm avoids buying servers and pays predictable monthly fees, directly matching that benefit. High availability, elasticity, and disaster recovery are real cloud advantages, but they address uptime, scaling, and recovery rather than the financial model the partners want.

Exam trap

The trap here is confusing any cloud benefit with the specific financial benefit of replacing upfront hardware purchases with recurring subscription costs.

121
MCQeasy

A company uses a cloud provider that charges them based solely on the exact number of gigabytes of storage used and the number of virtual machine hours consumed. They can increase or decrease usage at any time without any upfront commitment. Which essential characteristic of cloud computing does this billing model demonstrate?

A.Measured service
B.Rapid elasticity
C.Resource pooling
D.On-demand self-service
AnswerA

Measured service is the cloud characteristic where a provider meters resource usage — such as compute hours, storage capacity, and network bandwidth — and bills customers based solely on that measured consumption. This pay-per-use model directly matches the scenario of being charged based on actual resource utilization, not on flat fees or other factors.

Why this answer

The billing model charges based on exact gigabytes of storage used and virtual machine hours consumed, which directly aligns with the 'measured service' characteristic of cloud computing. Measured service means cloud providers meter and bill customers precisely for the resources they consume, often using a pay-as-you-go model. This allows the company to pay only for what they use without upfront commitments, as described in the scenario.

Exam trap

The trap here is that candidates often confuse 'measured service' with 'on-demand self-service' because both involve user control and flexibility, but measured service specifically focuses on the metering and billing aspect, not the ability to provision resources without human interaction.

How to eliminate wrong answers

Option B (Rapid elasticity) is wrong because rapid elasticity refers to the ability to automatically scale resources up or down quickly in response to demand, not to the billing or metering of those resources. Option C (Resource pooling) is wrong because resource pooling describes how the provider's computing resources are pooled to serve multiple customers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to consumer demand; it does not directly relate to billing granularity. Option D (On-demand self-service) is wrong because on-demand self-service allows a consumer to provision computing capabilities automatically without requiring human interaction with each service provider; while the scenario mentions the ability to increase or decrease usage at any time, the key billing aspect of 'pay per exact usage' is specifically measured service, not the provisioning mechanism.

122
MCQmedium

During a Microsoft 365 planning workshop, explain why Microsoft 365 is cloud-based despite local Office apps. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Cloud-hosted service backend
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerB

The correct explanation is Microsoft 365's cloud-hosted service backend: Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, and Microsoft Entra ID run on Microsoft's multi-tenant cloud infrastructure, not on local servers. Local Office apps connect to these services through HTTPS and Microsoft Graph to deliver mail, files, identity, and policy, enabling centralized management, automatic updates, and global availability. This backend is the foundational reason M365 behaves as a cloud service.

Why this answer

Microsoft 365 is considered cloud-based because its core services—such as Exchange Online, SharePoint Online, and the Microsoft 365 admin portal—are hosted and managed in Microsoft's cloud datacenters. Even though local Office apps (e.g., Word, Excel) run on the client device, they rely on a cloud-hosted service backend for licensing validation, data synchronization, and feature updates. This backend enables centralized management, automatic updates, and seamless integration with cloud services like OneDrive and Teams, which is the defining characteristic of a cloud-based platform.

Exam trap

The trap here is that candidates mistakenly think local Office apps mean the solution is not cloud-based, but Microsoft 365 is defined by its cloud-hosted backend that manages licensing, data, and updates, not by where the application code executes.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a specific cloud-based task management application within Microsoft 365, not a general cloud concept or benefit that explains why the platform is cloud-based despite local apps. Option C is wrong because Data Loss Prevention (DLP) is a security feature that helps prevent sensitive data from being shared inappropriately, but it does not address the foundational cloud architecture or the reason local apps still qualify as cloud-based. Option D is wrong because sensitivity labels are classification and protection tools for data, not a cloud concept that describes the backend infrastructure enabling local apps to function as part of a cloud service.

123
MCQeasy

A startup wants to focus only on developing and deploying its application code without managing underlying servers or operating systems. Which cloud service model best fits this need?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises deployment
AnswerB

PaaS delivers a fully managed hosting environment that includes the operating system, language runtime, web server, and deployment tooling as part of the service. The startup only manages its application code and data, while the platform provider automatically handles patching, scaling, and infrastructure maintenance—exactly matching the requirement to focus purely on development and deployment.

Why this answer

Platform as a Service (PaaS) is the correct choice because it abstracts the underlying infrastructure, including servers, operating systems, and runtime environments, allowing the startup to focus solely on developing and deploying application code. With PaaS, the cloud provider manages the OS patching, hardware scaling, and middleware, while the customer only manages the application and data. This directly matches the requirement of not managing servers or operating systems.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS, mistakenly thinking that IaaS also abstracts the OS, but IaaS only abstracts the hardware while leaving OS management to the customer.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides virtualized servers, storage, and networking, but the customer is still responsible for managing the operating system, middleware, and runtime—contradicting the requirement to avoid managing servers or OS. Option C is wrong because Software as a Service (SaaS) delivers fully managed applications (e.g., Office 365, Salesforce) where the customer does not develop or deploy code, only consumes the software—this does not fit the need to develop and deploy custom application code. Option D is wrong because on-premises deployment requires the startup to own and manage all hardware, servers, and operating systems, which is the opposite of the stated goal of not managing underlying infrastructure.

124
MCQmedium

An e-commerce application runs in the cloud and automatically adjusts the number of virtual machines based on real-time traffic. When traffic spikes, more VMs are added; when traffic drops, VMs are removed. Which cloud computing characteristic does this behavior exemplify?

A.Rapid elasticity
B.Measured service
C.Resource pooling
D.On-demand self-service
AnswerA

Rapid elasticity is the cloud characteristic that lets an e-commerce application dynamically add or remove compute capacity—such as VM instances or containers—in near-real time as traffic spikes or falls. An autoscaling group monitors metrics like CPU utilization or request count and adjusts resources automatically, so the application always has enough capacity without manual intervention. This exactly matches the scenario's automatic scaling based on demand.

Why this answer

Rapid elasticity is the cloud characteristic that enables resources to scale out (add VMs) and scale in (remove VMs) automatically in response to real-time demand. In this e-commerce scenario, the application adjusts VM count based on traffic spikes and drops, which directly matches the definition of rapid elasticity as defined by NIST SP 800-145.

Exam trap

The trap here is that candidates confuse 'on-demand self-service' (manual provisioning by the user) with 'rapid elasticity' (automatic scaling), because both involve responding to demand, but only elasticity handles real-time, automated adjustments without user intervention.

How to eliminate wrong answers

Option B (Measured service) is wrong because measured service refers to the metering and billing of cloud resource usage (e.g., pay-per-hour or per-GB), not the automatic scaling of resources. Option C (Resource pooling) is wrong because resource pooling describes the multi-tenant model where physical and virtual resources are dynamically assigned to multiple customers, not the ability to scale out/in based on demand. Option D (On-demand self-service) is wrong because on-demand self-service allows a user to provision resources without human interaction, but it does not inherently include automatic scaling based on real-time traffic.

125
MCQeasy

A service owner is comparing Microsoft 365 capabilities and needs to meter compute and storage usage for consumption-based billing. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Measured service
AnswerD

Measured service tracks usage so customers can be charged according to consumption.

Why this answer

Measured service is a core cloud computing concept where resource usage (such as compute and storage) is metered, tracked, and billed based on actual consumption. This directly matches the service owner's requirement for consumption-based billing, as Microsoft 365 uses metering for services like Azure Active Directory and Exchange Online to enable pay-as-you-go models.

Exam trap

The trap here is that candidates confuse operational features (like DLP or sensitivity labels) with cloud service model characteristics, mistakenly thinking data protection tools are related to billing rather than recognizing measured service as a fundamental cloud attribute.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data based on sensitivity, not to meter compute or storage usage. Option B is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, not a billing or metering mechanism. Option C is wrong because Data Loss Prevention (DLP) is a security policy feature that prevents unauthorized sharing of sensitive data, not a consumption-based billing capability.

126
MCQeasy

A tenant administrator is advising a department that wants to stop maintaining local file servers by using managed cloud storage. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Reduced infrastructure maintenance
C.Microsoft Planner
D.Data Loss Prevention (DLP)
AnswerB

Reduced infrastructure maintenance is the correct benefit because moving file storage to Microsoft 365 transfers responsibility for server hardware, storage capacity, patching, backups, and physical security to Microsoft under the shared responsibility model. The tenant administrator no longer needs to provision, monitor, upgrade, or repair on-premises file servers, lowering operational overhead and hardware lifecycle costs. This is the primary infrastructure-related advantage when advising a department that wants to move away from maintaining its own storage servers.

Why this answer

Moving from on-premises file servers to managed cloud storage (e.g., Microsoft OneDrive, SharePoint Online, or Azure Files) eliminates the need for the department to handle hardware procurement, patching, backups, and physical maintenance. This directly aligns with the cloud benefit of reduced infrastructure maintenance, a core concept in the MS-900 exam's 'Describe cloud concepts' domain.

Exam trap

The trap here is that candidates confuse security or compliance features (like sensitivity labels or DLP) with cloud benefits, when the question specifically asks for the cloud concept or benefit that matches reducing local server maintenance.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data based on sensitivity, not a cloud concept or benefit for reducing infrastructure maintenance. Option C is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, unrelated to replacing local file servers or reducing maintenance overhead. Option D is wrong because Data Loss Prevention (DLP) is a security policy feature that helps prevent accidental sharing of sensitive data, not a cloud benefit that addresses the requirement of stopping local file server maintenance.

127
MCQeasy

Refer to the exhibit. An administrator is configuring a new Azure subscription with this ARM template snippet for Microsoft Defender for Cloud. What will be the immediate result?

A.All virtual machines will be automatically onboarded to Microsoft Defender for Endpoint
B.The subscription will be monitored for security issues and receive recommendations
C.The subscription will be protected by the highest security tier
D.No changes will occur until a security policy is manually created
AnswerB

When Microsoft Defender for Cloud is enabled on the subscription, it continuously assesses the environment against built-in security benchmarks and policy initiatives. The service surfaces misconfigurations, computes a secure score, and provides prioritized, actionable recommendations; this monitoring and guidance happen automatically after enabling Defender for Cloud, with no need for manual security policy creation to get basic CSPM value.

Why this answer

The ARM template snippet enables Microsoft Defender for Cloud at the subscription level. By default, this activates the foundational Cloud Security Posture Management (CSPM) capabilities, which continuously assess the subscription's resources against security baselines and generate actionable security recommendations. This does not automatically onboard VMs to Defender for Endpoint or apply the highest security tier; it simply enables monitoring and recommendations.

Exam trap

The trap here is that candidates confuse 'enabling Microsoft Defender for Cloud' with automatically activating premium features like Defender for Endpoint or the highest security tier, when in reality the default is only foundational CSPM with recommendations.

How to eliminate wrong answers

Option A is wrong because automatic onboarding to Microsoft Defender for Endpoint requires explicit integration via the Defender for Cloud 'Integrations' blade or a separate policy assignment, not just enabling the basic Defender for Cloud plan. Option C is wrong because the 'highest security tier' (e.g., Microsoft Defender for Servers Plan 2) is an optional paid add-on that must be explicitly selected; the default plan only provides foundational CSPM. Option D is wrong because enabling Defender for Cloud automatically applies the default security policy (built-in initiative) to the subscription, generating recommendations immediately without manual policy creation.

128
MCQhard

Your company is experiencing high costs for maintaining an on-premises email server and wants to reduce IT management overhead. Which Microsoft 365 service provides enterprise-grade email with minimal infrastructure management?

A.Microsoft Entra ID
B.SharePoint Online
C.Microsoft Intune
D.Exchange Online
AnswerD

Exchange Online is the Microsoft 365 cloud-hosted email service, providing user mailboxes, calendars, contacts, and tasks through the Exchange Online architecture. It accepts, stores, and routes email messages, and includes built-in protection with anti-malware, anti-spam, and data loss prevention policies. Administrators manage Exchange Online through the Exchange admin center, and it is the correct service for email-related tasks in the Microsoft 365 ecosystem.

Why this answer

Exchange Online is Microsoft's cloud-hosted email service that eliminates the need for on-premises Exchange servers, providing enterprise-grade email with minimal infrastructure management. It includes built-in security, compliance, and high availability, and is part of most Microsoft 365 subscriptions. By moving to Exchange Online, the company offloads server maintenance, patching, and scaling to Microsoft, reducing IT overhead and costs.

Exam trap

MS-900 often tests the confusion between Microsoft 365 services that sound similar, such as Exchange Online (email) versus SharePoint Online (document collaboration) or Entra ID (identity), so candidates must map each service to its primary function.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (formerly Azure AD) is an identity and access management service, not an email service; it handles authentication and authorization but does not provide mailboxes or email transport. Option B is wrong because SharePoint Online is a collaboration and document management platform, not an email service; it offers sites, libraries, and lists but no email hosting. Option C is wrong because Microsoft Intune is a mobile device and application management service, not an email service; it manages device compliance and app deployment but does not provide email functionality.

129
MCQeasy

A company uses a cloud service where administrators can add or remove virtual machine instances through a web portal without contacting the provider. The provider bills only for the exact resources consumed. Which cloud computing characteristic does this scenario best demonstrate?

A.Rapid elasticity
B.On-demand self-service
C.Measured service
D.Resource pooling
AnswerB

On-demand self-service is a cloud characteristic that allows consumers to provision and manage computing resources (e.g., VMs, storage) independently through a self-service portal or API, without requiring human interaction with the service provider. The scenario directly illustrates this: an administrator adds or removes VMs via a web portal, and the organization only pays for what they consume (consumption-based billing). This is the primary characteristic being demonstrated because the focus is on the user's ability to unilaterally change resources, not on the underlying metering or resource sharing.

Why this answer

On-demand self-service is the cloud characteristic where consumers can provision capabilities, such as VM instances, automatically through a web portal or API without requiring human interaction with the service provider. The scenario explicitly states administrators add or remove VMs via a web portal without contacting the provider, which is the textbook definition of on-demand self-service per NIST SP 800-145.

Exam trap

MS-900 often tests the confusion between on-demand self-service (provisioning without provider interaction) and measured service (paying only for what is consumed), since both appear in the same billing-related scenario.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to capabilities scaling outward and inward commensurate with demand, not the self-provisioning mechanism itself. Option C is wrong because measured service refers to the metering and billing of resource usage, which is a separate characteristic from the self-service provisioning action. Option D is wrong because resource pooling describes the provider's multi-tenant model where resources are pooled to serve multiple consumers, not the consumer's ability to self-provision.

130
Multi-Selectmedium

A retail company is evaluating Microsoft 365 for a new subsidiary. Management wants to understand which characteristics are fundamental to cloud computing as described by the National Institute of Standards and Technology (NIST). Which two characteristics should the company include? (Choose two.)

Select 2 answers
A.Mandatory multi-year contracts
B.On-demand self-service
C.Dedicated physical hardware per tenant
D.Broad network access
E.Unlimited storage at no cost
AnswersB, D

On-demand self-service means consumers can provision computing capabilities, such as services and storage, automatically without requiring human interaction with the provider. NIST lists this as an essential cloud characteristic. For the retail subsidiary, this means administrators can enable Microsoft 365 services themselves rather than waiting for manual provider provisioning, matching the NIST definition.

Why this answer

NIST defines five essential cloud characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. On-demand self-service and broad network access are both on that list. Dedicated hardware per tenant, unlimited free storage, and mandatory multi-year contracts are commercial or hosting concepts that are not part of the NIST definition, so they should not be included.

Exam trap

The trap here is mixing commercial licensing terms or hosting models into the NIST essential characteristics of cloud computing.

131
MCQmedium

During a Microsoft 365 planning workshop, understand which security tasks Microsoft handles and which remain with the customer. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.Sensitivity labels
D.Shared responsibility model
AnswerD

The shared responsibility model is the foundational cloud computing principle that describes how the service provider is responsible for the security of the cloud, while the customer is responsible for security in the cloud. For Microsoft 365 as a SaaS offering, Microsoft handles infrastructure, platform, and most application security, but the customer remains accountable for identity management, user access, data classification, and compliance decisions. This model directly delineates the division of duties that organizations must understand when planning a Microsoft 365 deployment, making it the correct answer.

Why this answer

The shared responsibility model defines which security tasks are managed by Microsoft (e.g., physical security, hypervisor patching) and which remain with the customer (e.g., user access, data classification). This directly matches the requirement to understand task ownership during a planning workshop. Options like Microsoft Planner, DLP, and sensitivity labels are specific features, not the overarching cloud concept that clarifies responsibility boundaries.

Exam trap

The trap here is that candidates confuse specific security features (like DLP or sensitivity labels) with the overarching shared responsibility model, which is the foundational cloud concept that defines who owns each security task.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a project management tool for task assignment and scheduling, not a security concept or model for defining responsibility boundaries. Option B is wrong because Data Loss Prevention (DLP) is a specific security policy feature that helps prevent data leaks, but it does not explain which security tasks Microsoft handles versus the customer. Option C is wrong because sensitivity labels are a classification and protection mechanism for data, not a model that delineates shared security responsibilities between provider and tenant.

132
MCQmedium

During a Microsoft 365 planning workshop, host custom applications on virtual machines while managing the operating system. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Infrastructure as a Service (IaaS)
C.Hybrid cloud
D.Software as a Service (SaaS)
AnswerB

IaaS supplies virtualised compute, storage, and networking where the customer manages the guest operating system and hosts custom applications. This matches the stem's requirement to run custom apps on VMs while retaining OS management responsibility.

Why this answer

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, including virtual machines where you can host custom applications and have full control over the operating system. This matches the requirement because IaaS gives you the flexibility to manage the OS, install custom software, and configure the environment without worrying about the underlying physical hardware.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both involve hosting applications, but PaaS does not allow OS-level management, which is the key differentiator in this question.

How to eliminate wrong answers

Option A is wrong because Platform as a Service (PaaS) abstracts away the operating system and infrastructure management, focusing on deploying and managing applications without OS-level control, which contradicts the requirement to manage the operating system. Option C is wrong because Hybrid cloud is a deployment model that combines public and private clouds, not a service model that provides virtual machines with OS management capabilities. Option D is wrong because Software as a Service (SaaS) delivers fully managed applications accessed via a browser or client, with no access to the underlying OS or virtual machines.

133
MCQeasy

A compliance-aware administrator is selecting the right Microsoft 365 capability to add and remove capacity quickly when demand changes. Cloud concept or benefit best matches this requirement?

A.Rapid elasticity
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Rapid elasticity lets Microsoft 365 capacity scale up and down automatically with demand, so the administrator adds and removes resources quickly without manual provisioning. This matches the requirement for fast, demand-driven adjustment rather than fixed or pre-purchased capacity.

Why this answer

Rapid elasticity is a core cloud computing concept defined by NIST (SP 800-145) that allows resources to be provisioned and released automatically in response to demand. In Microsoft 365, this is demonstrated by the ability to add or remove user licenses (e.g., via the Microsoft 365 admin center or PowerShell) on a per-seat basis, scaling capacity up or down almost instantly without manual infrastructure changes.

Exam trap

The trap here is that candidates confuse a cloud concept (rapid elasticity) with a specific Microsoft 365 feature (Planner, DLP, sensitivity labels), failing to recognize that the question asks for the cloud concept or benefit, not a product or feature name.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management and project planning tool, not a cloud concept or benefit for scaling capacity. Option C is wrong because Data Loss Prevention (DLP) is a security policy feature that prevents sensitive data from being shared inappropriately, not a mechanism for adding or removing capacity. Option D is wrong because sensitivity labels are used to classify and protect data (e.g., encryption, marking), not to scale cloud resources dynamically.

134
Matchingmedium

Match each Microsoft 365 license type to its typical audience.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Large organizations with 500+ users

Organizations buying through a partner

Small and medium businesses up to 300 users

Individual users or teams buying directly

Why these pairings

Microsoft 365 licensing varies by organization size and needs. Business Basic and Business Premium target small to medium businesses, while E5 targets large enterprises. Distractors confuse the feature sets across different plans.

135
MCQmedium

Contoso Ltd. is a global consulting firm with 5,000 employees. They use Microsoft 365 E5 and have recently deployed Microsoft Copilot for Microsoft 365 to enhance productivity. The IT team wants to ensure that users' interactions with Copilot are compliant with the company's data retention policies. They need to retain all Copilot interactions for 7 years for legal reasons. Which Microsoft Purview solution should the IT team implement?

A.Apply sensitivity labels to Copilot data
B.Create retention policies for Copilot interactions
C.Set up eDiscovery cases for Copilot data
D.Configure Data Loss Prevention (DLP) policies
AnswerB

Retention policies in Microsoft Purview apply to Copilot interaction data stored in Exchange Online, letting administrators set a seven-year retention duration. This directly satisfies the legal requirement to retain all Copilot interactions for seven years without relying on manual preservation.

Why this answer

Retention policies in Microsoft Purview can be applied to Copilot interactions stored in Exchange Online and SharePoint Online to retain them for 7 years. Option A is incorrect because sensitivity labels classify data but do not enforce retention. Option C is incorrect because eDiscovery is for searching and exporting content, not setting retention.

Option D is incorrect because Data Loss Prevention (DLP) policies prevent data loss but do not retain data for legal hold.

136
Matchingmedium

Match each Microsoft 365 support channel to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Web portal for managing users, billing, and support requests

Assisted onboarding and deployment service

Peer-to-peer forums and knowledge base

Direct voice assistance for critical issues

Why these pairings

Microsoft 365 offers multiple support channels: Phone support for critical issues, Online self-help for documentation, Community forums for peer assistance, and the Service health dashboard for real-time status. Common confusions involve mixing definitions of phone and self-help or community and phone.

137
MCQeasy

A company wants to move its IT infrastructure to the cloud but must keep all customer data within a specific geographic region due to data residency laws. They also want to avoid paying for large upfront hardware costs. Which cloud characteristic best supports this need?

A.Geographic distribution (regional data centers)
B.Elasticity
C.High availability
D.Self-service
AnswerA

Cloud providers maintain physically distinct regional data centers that let customers designate a specific location for data at rest, such as an Azure region in the same country or border. This is the only attribute that directly addresses data residency and sovereignty requirements, because workload placement is tied to the chosen region's legal and regulatory jurisdiction. Scaling, availability, and self-service mechanics do not have any intrinsic capability to constrain where data is stored.

Why this answer

Geographic distribution refers to cloud providers operating multiple data centers across different regions, enabling customers to choose a specific region to store data and comply with data residency laws. This characteristic directly addresses the requirement to keep customer data within a specific geographic region while avoiding upfront hardware costs, as the cloud provider owns and manages the infrastructure.

Exam trap

The trap here is that candidates often confuse geographic distribution with high availability or elasticity, mistakenly thinking that scaling or redundancy can satisfy data residency requirements, when only region-specific data centers can enforce legal data boundaries.

How to eliminate wrong answers

Option B (Elasticity) is wrong because elasticity refers to the ability to automatically scale resources up or down based on demand, not to the geographic placement of data. Option C (High availability) is wrong because high availability ensures that services remain operational despite failures through redundancy within or across data centers, but it does not guarantee data residency in a specific region. Option D (Self-service) is wrong because self-service allows users to provision resources on demand without manual intervention from the provider, but it has no relation to geographic data placement or compliance with data residency laws.

138
MCQeasy

A marketing team needs to temporarily increase their cloud storage capacity from 5 TB to 10 TB for a product launch. They can perform this change themselves through a web portal without contacting the cloud provider. Which cloud characteristic does this scenario demonstrate?

A.On-demand self-service
B.Rapid elasticity
C.Measured service
D.Resource pooling
AnswerA

On-demand self-service is correct because the scenario describes the marketing team's user directly provisioning additional storage capacity through a web portal, without needing to submit a request or wait for a human administrator. This is the defining NIST characteristic: a consumer can unilaterally provision computing capabilities automatically, eliminating provider interaction. The user's own action makes this the most precise match.

Why this answer

This scenario demonstrates on-demand self-service because the marketing team can provision and manage their own cloud storage capacity increase from 5 TB to 10 TB through a web portal without any human interaction with the cloud provider. This is a core NIST-defined characteristic where users can unilaterally provision computing resources as needed automatically, requiring no service provider intervention.

Exam trap

The trap here is confusing 'on-demand self-service' with 'rapid elasticity' because both involve scaling, but on-demand self-service focuses on the user's ability to provision resources without provider interaction, while rapid elasticity focuses on automatic, dynamic scaling in response to load changes.

How to eliminate wrong answers

Option B (Rapid elasticity) is wrong because rapid elasticity refers to the ability to automatically scale resources up or down in response to demand, often dynamically and programmatically, not a manual one-time increase via a portal. Option C (Measured service) is wrong because measured service involves metering and billing for resource usage (pay-per-use), not the ability to self-provision capacity. Option D (Resource pooling) is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned to multiple customers, not the customer's ability to adjust their own allocation.

139
MCQhard

During requirements gathering, an IT manager says the organization must compare service models and identify where the customer manages the most layers. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Infrastructure as a Service (IaaS)
D.Hybrid cloud
AnswerC

IaaS leaves the customer managing the most layers: operating systems, runtime, middleware, applications and data, while the provider handles virtualisation, servers, storage and networking. This matches the requirement to identify the service model with the greatest customer management responsibility.

Why this answer

The IT manager's requirement is to identify the service model where the customer manages the most layers. In Infrastructure as a Service (IaaS), the cloud provider manages only the physical infrastructure (servers, storage, networking), while the customer is responsible for managing the operating system, middleware, runtime, data, and applications. This gives the customer the highest degree of control and management responsibility compared to PaaS or SaaS.

Exam trap

The trap here is that candidates often confuse 'most management' with 'most convenience,' incorrectly selecting PaaS or SaaS because they assume more provider management is the goal, whereas the question explicitly asks for the model where the customer manages the most layers.

How to eliminate wrong answers

Option A is wrong because Platform as a Service (PaaS) offloads management of the operating system, middleware, and runtime to the provider, leaving the customer to manage only applications and data — fewer layers than IaaS. Option B is wrong because Software as a Service (SaaS) shifts nearly all management to the provider, with the customer typically only managing user access and data — the fewest layers of any cloud service model. Option D is wrong because hybrid cloud is a deployment model (combining public and private cloud), not a service model, and does not define which layers the customer manages; it is irrelevant to the specific requirement of comparing service models by management responsibility.

140
Drag & Dropmedium

Drag and drop the steps to reset a user's password in Microsoft 365 admin center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order to reset a user's password in Microsoft 365 admin center is to first navigate to Users > Active users, then select the user, click Reset password, and finally enter and confirm the new password. This sequence ensures the proper workflow for password management.

141
MCQeasy

A company runs its customer relationship management (CRM) system using a cloud provider's SaaS offering. They also use virtual machines (IaaS) from the same provider to host a legacy application. In this scenario, who is responsible for patching the operating system of the virtual machines?

A.The cloud provider is fully responsible for patching all components.
B.The customer is responsible for patching the operating system of the virtual machines.
C.The cloud provider patches the OS for all services equally.
D.No patching is needed because the cloud handles everything.
AnswerB

This is the correct statement for an IaaS virtual machine. Because the customer provisions and controls the VM, they are accountable for the guest operating system and must apply patches, including critical security updates, to that OS. The provider manages the underlying physical hosts and the hypervisor, but does not access or modify the guest OS unless the customer explicitly enables a management or patching service. Therefore, the customer must have an ongoing patching process for the VM's operating system to maintain security and compliance.

Why this answer

In an IaaS model, the cloud provider is responsible for the security of the physical infrastructure, hypervisor, and network, but the customer retains responsibility for the guest operating system and applications. Since the virtual machines are IaaS resources, the customer must manage OS patches, updates, and configuration. This follows the shared responsibility model, where the customer is accountable for anything they configure or deploy within the virtual machine.

Exam trap

The trap here is that candidates confuse the IaaS model with SaaS, assuming the cloud provider patches everything, but Microsoft explicitly tests the shared responsibility model where the customer patches the OS in IaaS.

How to eliminate wrong answers

Option A is wrong because the cloud provider is not fully responsible for patching all components; in IaaS, the customer patches the OS and applications. Option C is wrong because the cloud provider does not patch the OS for all services equally; for SaaS, the provider patches the OS, but for IaaS, the customer does. Option D is wrong because patching is absolutely needed; the cloud does not handle OS-level patching for IaaS resources, and unpatched systems are vulnerable to exploits.

142
MCQeasy

Your organization uses Microsoft 365 and wants to automatically scale resources based on demand, paying only for what is used. Which cloud characteristic does this describe?

A.Fault tolerance
B.Disaster recovery
C.High availability
D.Elasticity
AnswerD

Elasticity matches the stem's demand-based scaling requirement: resources expand or contract automatically as workload fluctuates. Unlike vertical scaling, which resizes a single resource, elasticity adds or removes instances horizontally. Consumption-based billing then charges only for what is used, satisfying both stated constraints.

Why this answer

Elasticity is the cloud characteristic that allows resources to automatically scale based on demand, paying only for what is used. This matches the requirement to scale resources automatically and pay only for consumption.

Exam trap

The trap is confusing elasticity with high availability or scalability; candidates may pick high availability because it sounds like the system is always available, but elasticity specifically addresses automatic scaling and pay-per-use.

How to eliminate wrong answers

Option A is wrong because fault tolerance refers to the ability to continue operating despite component failures, not scaling. Option B is wrong because disaster recovery is about recovering from major outages, not dynamic scaling. Option C is wrong because high availability ensures uptime, but does not imply automatic scaling or pay-per-use.

143
MCQmedium

During requirements gathering, an IT manager says the organization must deploy application code without maintaining the operating system or runtime platform. Cloud concept or benefit best matches this requirement?

A.Private cloud
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Software as a Service (SaaS)
AnswerB

Platform as a Service (PaaS) is correct because it provides an integrated, managed hosting environment that includes the runtime, middleware, database, and underlying servers, allowing developers to focus exclusively on writing and deploying custom application code. The cloud provider handles operating system patching, scaling, and infrastructure maintenance, directly matching the requirement to build a custom app without managing the underlying platform. This is the service model that best fits the stated need.

Why this answer

Platform as a Service (PaaS) is the correct choice because it provides a managed hosting environment where you can deploy your own application code without needing to manage the underlying operating system or runtime platform. The IT manager's requirement explicitly states they want to avoid maintaining the OS and runtime, which is the core value proposition of PaaS. In contrast, IaaS would require them to manage the OS and runtime themselves.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both allow custom code deployment, but IaaS requires full OS and runtime management, which directly contradicts the requirement to avoid maintaining those layers.

How to eliminate wrong answers

Option A is wrong because private cloud describes a deployment model (single-tenant, on-premises or hosted) rather than a service model; it does not inherently relieve the organization from managing the OS or runtime. Option C is wrong because Infrastructure as a Service (IaaS) provides virtualized compute, storage, and networking resources, but the customer remains responsible for patching, configuring, and maintaining the operating system and runtime environment. Option D is wrong because Software as a Service (SaaS) delivers fully managed applications to end users, not a platform for deploying custom application code.

← PreviousPage 2 of 2 · 143 questions total

Ready to test yourself?

Try a timed practice session using only Describe cloud concepts questions.