Courseiva

Who Is Responsible for Security in Azure IaaS?

A company deploys a web application on Azure virtual machines (VMs) in an Infrastructure-as-a-Service (IaaS) model. The company is responsible for managing the guest operating system, the application code, and the data stored on the VMs. According to the shared responsibility model, which of the following security responsibilities does Microsoft retain in this scenario?

Quick Answer

The answer is that Microsoft retains responsibility for protecting the physical datacenter and the underlying hardware. This is correct because in the shared responsibility model for IaaS, the cloud provider manages the physical layer up to the hypervisor, including servers, storage, networking, and physical security, while the customer manages everything above the hypervisor, such as the guest OS, application code, and data. On the SC-900 exam, this distinction tests your understanding of how responsibilities shift across service models; a common trap is assuming Microsoft handles the guest OS in IaaS, when in fact that is the customer’s job. A helpful memory tip is to think of IaaS as “Infrastructure as a Service”—Microsoft secures the infrastructure (the building and the racks), while you secure everything you install inside.

⚠ Common exam trap

A common mix-up: candidates confuse 'security of the cloud' (Microsoft's responsibility for the physical infrastructure) with 'security in the cloud' (the customer's responsibility for their own configurations, applications, and data), leading them to incorrectly assign guest OS or application-level tasks to Microsoft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Protecting the physical datacenter and the underlying hardware

In an IaaS model, Microsoft retains responsibility for the physical datacenter, including physical security, the network infrastructure, and the underlying hardware (servers, storage, networking). This is because the customer manages the guest OS, application, and data, while Microsoft manages the physical layer up to the hypervisor. Option A correctly identifies this retained responsibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Protecting the physical datacenter and the underlying hardware

    Why this is correct

    Microsoft retains responsibility for the physical security of datacenters, servers, storage, and networking hardware in all cloud models, including IaaS.

  • Configuring the operating system firewall on each VM

    Why it's wrong here

    Configuring the OS-level firewall is a customer responsibility, as the customer manages the guest OS.

    When this WOULD be correct

    In a Platform-as-a-Service (PaaS) scenario where the customer deploys a web app using Azure App Service, Microsoft manages the underlying OS and its firewall, so configuring the OS firewall would be Microsoft's responsibility.

  • Installing and patching the application software

    Why it's wrong here

    The customer is responsible for managing and patching application software deployed on IaaS VMs.

    When this WOULD be correct

    In a Platform-as-a-Service (PaaS) model where the customer deploys a web app using Azure App Service, Microsoft manages the runtime environment, including installing and patching the application platform software (e.g., .NET framework).

  • Managing user access to the application

    Why it's wrong here

    Identity and access management for the application is the customer's responsibility.

    When this WOULD be correct

    In a SaaS model, such as Microsoft 365, the provider manages the application, and the customer is responsible for managing user access to the application. A question asking about customer responsibilities in a SaaS deployment would make this option correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Protecting the physical datacenter and the underlying hardwareCorrect answer

Why this is correct

Microsoft retains responsibility for the physical security of datacenters, servers, storage, and networking hardware in all cloud models, including IaaS.

Configuring the operating system firewall on each VMWrong answer — click to see why

Why this is wrong here

In the IaaS model, Microsoft is responsible for the physical infrastructure, not for guest OS configuration. Configuring the OS firewall is the customer's responsibility.

★ When this WOULD be the correct answer

In a Platform-as-a-Service (PaaS) scenario where the customer deploys a web app using Azure App Service, Microsoft manages the underlying OS and its firewall, so configuring the OS firewall would be Microsoft's responsibility.

Why candidates choose this

Candidates may confuse the shared responsibility model boundaries, thinking that since Microsoft provides the VM, they also manage its OS-level security settings like the firewall.

Installing and patching the application softwareWrong answer — click to see why

Why this is wrong here

In an IaaS model, the customer is responsible for managing the guest OS, application code, and data, including installing and patching application software. Microsoft does not manage the application layer.

★ When this WOULD be the correct answer

In a Platform-as-a-Service (PaaS) model where the customer deploys a web app using Azure App Service, Microsoft manages the runtime environment, including installing and patching the application platform software (e.g., .NET framework).

Why candidates choose this

Candidates may confuse IaaS with PaaS or SaaS, assuming Microsoft handles all software patching, or they may overestimate Microsoft's responsibility in the shared responsibility model.

Managing user access to the applicationWrong answer — click to see why

Why this is wrong here

In an IaaS model, Microsoft retains responsibility for the physical infrastructure, not for managing user access to applications. User access management is the customer's responsibility.

★ When this WOULD be the correct answer

In a SaaS model, such as Microsoft 365, the provider manages the application, and the customer is responsible for managing user access to the application. A question asking about customer responsibilities in a SaaS deployment would make this option correct.

Why candidates choose this

Candidates may confuse shared responsibility boundaries, thinking that since Microsoft provides the platform, they also manage access control, but in IaaS, access management is entirely the customer's duty.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company hosts a line-of-business application on an Azure virtual machine. The IT team is responsible for configuring the operating system, installing security updates, and managing the application code. An auditor asks who is responsible for the physical security of the data center where the virtual machine runs. According to the shared responsibility model for cloud services, who is responsible?

hard
  • A.The customer
  • B.Microsoft
  • C.Both the customer and Microsoft equally
  • D.Neither – physical security is no longer needed in the cloud

Why B: Under the shared responsibility model, Microsoft is responsible for the physical security of its Azure data centers, including access controls, surveillance, and environmental safeguards. The customer is responsible for securing the virtual machine's operating system, applications, and data, but not the physical infrastructure. Therefore, Microsoft retains responsibility for physical security even when the customer manages the guest OS and application.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.