AZ-900 Shared Responsibility Model
Practice Test 2026–2027 | Azure
Security Responsibilities, Cloud
Governance & Detailed Answers
1. In the shared responsibility model, which party is generally responsible for
securing the physical data center infrastructure used by Azure?
A. The customer
B. The application developer
C. Microsoft
D. The end user
Answer: Microsoft
Rationale: Microsoft operates and secures Azure's physical data centers,
including the physical facilities, networking infrastructure, and underlying
hardware.
2. Which responsibility always remains with the customer regardless of whether
they use IaaS, PaaS, or SaaS?
A. Physical server maintenance
B. Physical network security
,C. Data and identity access management
D. Hypervisor patching
Answer: Data and identity access management
Rationale: Customers remain responsible for protecting their data and
managing identities and access appropriately, although the exact scope of other
responsibilities changes by service model.
3. A company deploys virtual machines in Azure using IaaS. Who is primarily
responsible for patching the guest operating system?
A. Microsoft
B. The customer
C. The internet service provider
D. The Azure region administrator
Answer: The customer
Rationale: In IaaS, Microsoft manages the physical infrastructure and
virtualization layer, while the customer manages the guest operating system,
including its updates and patches.
4. Which cloud service model transfers the greatest amount of infrastructure
management responsibility from the customer to Microsoft?
A. IaaS
B. PaaS
C. SaaS
D. On-premises
Answer: SaaS
Rationale: SaaS provides the highest level of provider management among
these models. Microsoft manages the application platform and infrastructure,
while the customer focuses primarily on data, identities, access, and
configuration.
,5. An organization uses Azure App Service to host a web application. Which
responsibility is generally handled by Microsoft?
A. Writing secure application code
B. Managing the physical servers
C. Determining user permissions within the application
D. Classifying business data
Answer: Managing the physical servers
Rationale: App Service is a PaaS offering, so Microsoft manages the underlying
physical infrastructure and platform components while customers remain
responsible for their applications and data.
6. Which statement best describes the shared responsibility model?
A. Microsoft is responsible for all security tasks in Azure
B. Customers are responsible for all security tasks in Azure
C. Security responsibilities are divided between Microsoft and the customer
D. Security is the responsibility of the internet provider
Answer: Security responsibilities are divided between Microsoft and the
customer
Rationale: The shared responsibility model defines which security and
management responsibilities belong to the cloud provider and which remain
with the customer.
7. A customer accidentally grants excessive permissions to an Azure Storage
account. Who is responsible for correcting the access configuration?
A. Microsoft
B. The customer
C. The Azure hardware vendor
D. The data center operator
Answer: The customer
, Rationale: Customers are responsible for configuring access controls and
permissions for their cloud resources. Microsoft provides the platform and
security capabilities but does not automatically determine the customer's
intended access policies.
8. In an IaaS environment, who is generally responsible for configuring the
firewall rules associated with a customer's virtual network?
A. Microsoft exclusively
B. The customer
C. The physical data center team
D. The ISP
Answer: The customer
Rationale: Customers manage many network security configurations for their
IaaS resources, including network security rules and traffic controls within their
Azure environment.
9. Which component is Microsoft responsible for securing in Azure IaaS?
A. Customer's application code
B. Customer's guest operating system
C. Physical hosts
D. Customer's user passwords
Answer: Physical hosts
Rationale: Microsoft manages the physical hosts and underlying Azure
infrastructure. The customer manages software and configurations running
within their virtual machines.
10. A customer uses Microsoft 365 as a SaaS service. Who is responsible for the
physical security of Microsoft's data centers?
A. The customer
B. Microsoft