SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company is migrating its on-premises workloads to Azure. The CISO wants to understand the division of security responsibilities between Microsoft and the customer across cloud service models. For which cloud service model does the customer have the most security responsibility?
⚠ Common exam trap
Candidates often confuse 'most responsibility' with 'most control' and incorrectly pick on-premises (Option D), forgetting that the question explicitly asks about cloud service models, where IaaS gives the customer the greatest security responsibility among the cloud options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Infrastructure as a Service (IaaS)
In the Infrastructure as a Service (IaaS) model, the customer is responsible for securing the operating system, applications, data, and network configurations, while Microsoft only secures the physical datacenter, host servers, and hypervisor. This gives the customer the most security responsibility compared to PaaS or SaaS, where Microsoft manages more of the stack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Software as a Service (SaaS)
Why it's wrong here
Software as a Service (SaaS) is incorrect because it provides a fully managed application where the cloud provider assumes responsibility for nearly the entire security stack, including the application, runtime, operating system, and underlying infrastructure. This model is about consuming a ready-to-use application, not migrating custom on-premises workloads that require specific configuration or direct access to the operating system. The customer's security responsibilities are minimal, primarily limited to data classification and user access management, which does not align with migrating existing, potentially complex, custom applications.
When this WOULD be correct
A question asks: 'For which cloud service model does the customer have the least security responsibility?' or 'Which model shifts the most security responsibility to the cloud provider?'
- ✗
Platform as a Service (PaaS)
Why it's wrong here
Platform as a Service (PaaS) is incorrect because it abstracts away much of the underlying infrastructure, including the operating system, middleware, and runtime, allowing developers to focus solely on their applications and data. While PaaS offers moderate customer responsibility, it is primarily designed for developing and deploying new cloud-native applications or modernizing existing ones, rather than a direct "lift-and-shift" of traditional on-premises workloads that might require specific OS-level access or custom middleware configurations. The CISO would lose significant control over the environment compared to IaaS, which might be necessary for existing applications.
When this WOULD be correct
A question asks: 'For which cloud service model does the customer have the most control over the application runtime environment without managing the underlying OS?' In that context, PaaS would be correct because it provides a platform for deploying apps while abstracting OS and infrastructure management.
- ✓
Infrastructure as a Service (IaaS)
Why this is correct
Infrastructure as a Service (IaaS) is the correct choice for migrating existing on-premises workloads to Azure because it provides the most control over the underlying operating systems, applications, and data, closely mirroring an on-premises environment. In IaaS, the customer is responsible for securing the operating system, applications, network configuration, and data, while Azure manages the physical infrastructure, virtualization, and networking fabric. This model facilitates a "lift-and-shift" approach, allowing the CISO to maintain significant security responsibility and control over their familiar stack within the cloud.
- ✗
On-premises
Why it's wrong here
On-premises is not a cloud service model, but rather the traditional computing environment from which the organization is migrating. While an on-premises setup places 100% of the security responsibility on the customer, the question specifically asks about cloud service models for workloads being moved to Azure. Therefore, it is an inappropriate answer as the CISO is actively seeking to leverage cloud capabilities, not remain entirely within their existing data center.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Infrastructure as a Service (IaaS)Correct answer▾
Why this is correct
Infrastructure as a Service (IaaS) is the correct choice for migrating existing on-premises workloads to Azure because it provides the most control over the underlying operating systems, applications, and data, closely mirroring an on-premises environment. In IaaS, the customer is responsible for securing the operating system, applications, network configuration, and data, while Azure manages the physical infrastructure, virtualization, and networking fabric. This model facilitates a "lift-and-shift" approach, allowing the CISO to maintain significant security responsibility and control over their familiar stack within the cloud.
✗Software as a Service (SaaS)Wrong answer — click to see why▾
Why this is wrong here
In SaaS, the customer has the least security responsibility because Microsoft manages the entire stack, including applications, data, and infrastructure. The question asks for the model with the most customer responsibility, which is IaaS.
★ When this WOULD be the correct answer
A question asks: 'For which cloud service model does the customer have the least security responsibility?' or 'Which model shifts the most security responsibility to the cloud provider?'
Why candidates choose this
Candidates may mistakenly think SaaS requires significant customer security effort due to data protection and access control, overlooking that the provider secures the underlying platform and application.
✗Platform as a Service (PaaS)Wrong answer — click to see why▾
Why this is wrong here
In PaaS, the customer manages applications and data, while Microsoft handles the runtime, middleware, OS, and infrastructure. This gives the customer less security responsibility than IaaS, where they manage everything from the OS upward.
★ When this WOULD be the correct answer
A question asks: 'For which cloud service model does the customer have the most control over the application runtime environment without managing the underlying OS?' In that context, PaaS would be correct because it provides a platform for deploying apps while abstracting OS and infrastructure management.
Why candidates choose this
Candidates may confuse 'most responsibility' with 'most control over applications,' thinking PaaS gives them more security duties than IaaS because they still manage the app layer, but they overlook that IaaS requires managing the OS, network, and storage as well.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.