SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company hosts a line-of-business application on an Azure virtual machine. The IT team is responsible for configuring the operating system, installing security updates, and managing the application code. An auditor asks who is responsible for the physical security of the data center where the virtual machine runs. According to the shared responsibility model for cloud services, who is responsible?
⚠ Common exam trap
The trap here is that candidates mistakenly think the customer is responsible for all security when they manage the OS and application, but physical security always remains the provider's responsibility under the shared responsibility model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft
Under the shared responsibility model, Microsoft is responsible for the physical security of its Azure data centers, including access controls, surveillance, and environmental safeguards. The customer is responsible for securing the virtual machine's operating system, applications, and data, but not the physical infrastructure. Therefore, Microsoft retains responsibility for physical security even when the customer manages the guest OS and application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The customer
Why it's wrong here
In an IaaS deployment, the customer is explicitly relieved of the burden of managing the physical infrastructure, including physical security. Customers do not have direct physical access to Microsoft's data centers and are therefore not responsible for securing the physical premises, servers, or networking hardware. The customer's security responsibilities begin at the operating system layer and extend upwards to applications, data, and network configurations within their virtualized environment.
When this WOULD be correct
This option would be correct if the question asked about responsibility for configuring the operating system, installing security updates, or managing the application code on the VM, as those are customer responsibilities under the IaaS model.
- ✓
Microsoft
Why this is correct
In an Infrastructure-as-a-Service (IaaS) model, Microsoft retains full responsibility for the physical security of the underlying data centers, including the buildings, servers, networking hardware, and environmental controls. This encompasses safeguarding against unauthorized physical access, environmental threats, and ensuring the integrity of the foundational infrastructure. This division of responsibility is a fundamental aspect of the shared responsibility model, where the cloud provider manages the "security of the cloud."
- ✗
Both the customer and Microsoft equally
Why it's wrong here
The shared responsibility model does not imply an equal division of duties; instead, it delineates distinct areas of accountability between the cloud provider and the customer. While both parties have security responsibilities, Microsoft is solely accountable for the physical security of the data center infrastructure in an IaaS model, whereas the customer is responsible for security in the cloud, covering operating systems, applications, and data. Therefore, physical security is not a shared equal responsibility.
When this WOULD be correct
This option would be correct in a scenario where the question asks about responsibility for securing the virtual machine's operating system and applications, or for a hybrid deployment where the customer manages some physical infrastructure (e.g., on-premises servers connected to Azure).
- ✗
Neither – physical security is no longer needed in the cloud
Why it's wrong here
The premise that physical security is no longer needed in the cloud is fundamentally incorrect and dangerous. Physical security remains absolutely critical to protect the underlying hardware, network components, and data storage from unauthorized access, theft, or damage. While the customer no longer manages it directly, Microsoft, as the cloud provider, assumes this vital responsibility, implementing stringent controls like biometric access, surveillance, and environmental monitoring to secure its global data centers.
When this WOULD be correct
In a question about responsibility for securing the guest operating system or application code on an IaaS virtual machine, where the customer retains full control and responsibility for those layers, 'Neither – physical security is no longer needed' would be incorrect; but if the question asked about a SaaS service where the provider manages everything including physical security, then 'Neither' might be chosen incorrectly. However, no valid scenario makes this option correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓MicrosoftCorrect answer▾
Why this is correct
In an Infrastructure-as-a-Service (IaaS) model, Microsoft retains full responsibility for the physical security of the underlying data centers, including the buildings, servers, networking hardware, and environmental controls. This encompasses safeguarding against unauthorized physical access, environmental threats, and ensuring the integrity of the foundational infrastructure. This division of responsibility is a fundamental aspect of the shared responsibility model, where the cloud provider manages the "security of the cloud."
✗The customerWrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, physical security of the data center is always the responsibility of the cloud provider (Microsoft), not the customer. The customer is responsible for securing their own data, applications, and configurations on the VM.
★ When this WOULD be the correct answer
This option would be correct if the question asked about responsibility for configuring the operating system, installing security updates, or managing the application code on the VM, as those are customer responsibilities under the IaaS model.
Why candidates choose this
Candidates may mistakenly think that because they manage the VM's OS and applications, they also bear responsibility for the underlying physical infrastructure, not realizing that physical security is always the provider's duty.
✗Both the customer and Microsoft equallyWrong answer — click to see why▾
Why this is wrong here
In the shared responsibility model, physical security of the data center is always the responsibility of the cloud provider (Microsoft), not shared. The customer is responsible for securing the OS, applications, and data, but not the physical infrastructure.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the question asks about responsibility for securing the virtual machine's operating system and applications, or for a hybrid deployment where the customer manages some physical infrastructure (e.g., on-premises servers connected to Azure).
Why candidates choose this
Candidates may mistakenly believe that all security responsibilities are shared equally, not understanding that physical security is exclusively the provider's responsibility under IaaS.
✗Neither – physical security is no longer needed in the cloudWrong answer — click to see why▾
Why this is wrong here
Physical security of the data center is always the responsibility of the cloud provider (Microsoft) under the shared responsibility model; it is never eliminated in cloud computing.
★ When this WOULD be the correct answer
In a question about responsibility for securing the guest operating system or application code on an IaaS virtual machine, where the customer retains full control and responsibility for those layers, 'Neither – physical security is no longer needed' would be incorrect; but if the question asked about a SaaS service where the provider manages everything including physical security, then 'Neither' might be chosen incorrectly. However, no valid scenario makes this option correct.
Why candidates choose this
Candidates may mistakenly believe that cloud computing eliminates the need for physical security because they think all security is abstracted away or handled automatically by the provider.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.