Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company hosts a line-of-business application on an Azure virtual machine. The IT team is responsible for configuring the operating system, installing security updates, and managing the application code. An auditor asks who is responsible for the physical security of the data center where the virtual machine runs. According to the shared responsibility model for cloud services, who is responsible?

⚠ Common exam trap

The trap here is that candidates mistakenly think the customer is responsible for all security when they manage the OS and application, but physical security always remains the provider's responsibility under the shared responsibility model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft

Under the shared responsibility model, Microsoft is responsible for the physical security of its Azure data centers, including access controls, surveillance, and environmental safeguards. The customer is responsible for securing the virtual machine's operating system, applications, and data, but not the physical infrastructure. Therefore, Microsoft retains responsibility for physical security even when the customer manages the guest OS and application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The customer

    Why it's wrong here

    In an IaaS deployment, the customer is explicitly relieved of the burden of managing the physical infrastructure, including physical security. Customers do not have direct physical access to Microsoft's data centers and are therefore not responsible for securing the physical premises, servers, or networking hardware. The customer's security responsibilities begin at the operating system layer and extend upwards to applications, data, and network configurations within their virtualized environment.

    When this WOULD be correct

    This option would be correct if the question asked about responsibility for configuring the operating system, installing security updates, or managing the application code on the VM, as those are customer responsibilities under the IaaS model.

  • Microsoft

    Why this is correct

    In an Infrastructure-as-a-Service (IaaS) model, Microsoft retains full responsibility for the physical security of the underlying data centers, including the buildings, servers, networking hardware, and environmental controls. This encompasses safeguarding against unauthorized physical access, environmental threats, and ensuring the integrity of the foundational infrastructure. This division of responsibility is a fundamental aspect of the shared responsibility model, where the cloud provider manages the "security of the cloud."

  • Both the customer and Microsoft equally

    Why it's wrong here

    The shared responsibility model does not imply an equal division of duties; instead, it delineates distinct areas of accountability between the cloud provider and the customer. While both parties have security responsibilities, Microsoft is solely accountable for the physical security of the data center infrastructure in an IaaS model, whereas the customer is responsible for security in the cloud, covering operating systems, applications, and data. Therefore, physical security is not a shared equal responsibility.

    When this WOULD be correct

    This option would be correct in a scenario where the question asks about responsibility for securing the virtual machine's operating system and applications, or for a hybrid deployment where the customer manages some physical infrastructure (e.g., on-premises servers connected to Azure).

  • Neither – physical security is no longer needed in the cloud

    Why it's wrong here

    The premise that physical security is no longer needed in the cloud is fundamentally incorrect and dangerous. Physical security remains absolutely critical to protect the underlying hardware, network components, and data storage from unauthorized access, theft, or damage. While the customer no longer manages it directly, Microsoft, as the cloud provider, assumes this vital responsibility, implementing stringent controls like biometric access, surveillance, and environmental monitoring to secure its global data centers.

    When this WOULD be correct

    In a question about responsibility for securing the guest operating system or application code on an IaaS virtual machine, where the customer retains full control and responsibility for those layers, 'Neither – physical security is no longer needed' would be incorrect; but if the question asked about a SaaS service where the provider manages everything including physical security, then 'Neither' might be chosen incorrectly. However, no valid scenario makes this option correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

MicrosoftCorrect answer

Why this is correct

In an Infrastructure-as-a-Service (IaaS) model, Microsoft retains full responsibility for the physical security of the underlying data centers, including the buildings, servers, networking hardware, and environmental controls. This encompasses safeguarding against unauthorized physical access, environmental threats, and ensuring the integrity of the foundational infrastructure. This division of responsibility is a fundamental aspect of the shared responsibility model, where the cloud provider manages the "security of the cloud."

The customerWrong answer — click to see why

Why this is wrong here

In the shared responsibility model, physical security of the data center is always the responsibility of the cloud provider (Microsoft), not the customer. The customer is responsible for securing their own data, applications, and configurations on the VM.

★ When this WOULD be the correct answer

This option would be correct if the question asked about responsibility for configuring the operating system, installing security updates, or managing the application code on the VM, as those are customer responsibilities under the IaaS model.

Why candidates choose this

Candidates may mistakenly think that because they manage the VM's OS and applications, they also bear responsibility for the underlying physical infrastructure, not realizing that physical security is always the provider's duty.

Both the customer and Microsoft equallyWrong answer — click to see why

Why this is wrong here

In the shared responsibility model, physical security of the data center is always the responsibility of the cloud provider (Microsoft), not shared. The customer is responsible for securing the OS, applications, and data, but not the physical infrastructure.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the question asks about responsibility for securing the virtual machine's operating system and applications, or for a hybrid deployment where the customer manages some physical infrastructure (e.g., on-premises servers connected to Azure).

Why candidates choose this

Candidates may mistakenly believe that all security responsibilities are shared equally, not understanding that physical security is exclusively the provider's responsibility under IaaS.

Neither – physical security is no longer needed in the cloudWrong answer — click to see why

Why this is wrong here

Physical security of the data center is always the responsibility of the cloud provider (Microsoft) under the shared responsibility model; it is never eliminated in cloud computing.

★ When this WOULD be the correct answer

In a question about responsibility for securing the guest operating system or application code on an IaaS virtual machine, where the customer retains full control and responsibility for those layers, 'Neither – physical security is no longer needed' would be incorrect; but if the question asked about a SaaS service where the provider manages everything including physical security, then 'Neither' might be chosen incorrectly. However, no valid scenario makes this option correct.

Why candidates choose this

Candidates may mistakenly believe that cloud computing eliminates the need for physical security because they think all security is abstracted away or handled automatically by the provider.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.