Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 37 pages
Exam (elaborations)

AZ-900 Shared Responsibility Model Practice Test 2026–2027 | Azure Security Responsibilities, Cloud Governance, Questions & Detailed Answers

Document preview thumbnail
Preview 4 out of 37 pages

Prepare for the Microsoft Azure Fundamentals AZ-900 2026–2027 exam with focused practice on the Azure Shared Responsibility Model. Review how security and management responsibilities are divided between Microsoft and the customer across cloud service models, including IaaS, PaaS, and SaaS. Practice realistic certification-style questions covering physical security, operating systems, applications, data protection, identity, access management, compliance, and cloud governance. Detailed answers and rationales explain responsibility boundaries and help candidates identify which party is accountable for specific security tasks. Ideal for students, IT professionals, cloud learners, and AZ-900 certification candidates.

Content preview

___________________________________________________________________


AZ-900 Shared Responsibility Model
Practice Test 2026–2027 | Azure
Security Responsibilities, Cloud
Governance & Detailed Answers

1. In the shared responsibility model, which party is generally responsible for
securing the physical data center infrastructure used by Azure?

A. The customer
B. The application developer
C. Microsoft
D. The end user

Answer: Microsoft

Rationale: Microsoft operates and secures Azure's physical data centers,
including the physical facilities, networking infrastructure, and underlying
hardware.

2. Which responsibility always remains with the customer regardless of whether
they use IaaS, PaaS, or SaaS?

A. Physical server maintenance
B. Physical network security

,C. Data and identity access management
D. Hypervisor patching

Answer: Data and identity access management

Rationale: Customers remain responsible for protecting their data and
managing identities and access appropriately, although the exact scope of other
responsibilities changes by service model.

3. A company deploys virtual machines in Azure using IaaS. Who is primarily
responsible for patching the guest operating system?

A. Microsoft
B. The customer
C. The internet service provider
D. The Azure region administrator

Answer: The customer

Rationale: In IaaS, Microsoft manages the physical infrastructure and
virtualization layer, while the customer manages the guest operating system,
including its updates and patches.

4. Which cloud service model transfers the greatest amount of infrastructure
management responsibility from the customer to Microsoft?

A. IaaS
B. PaaS
C. SaaS
D. On-premises

Answer: SaaS

Rationale: SaaS provides the highest level of provider management among
these models. Microsoft manages the application platform and infrastructure,
while the customer focuses primarily on data, identities, access, and
configuration.

,5. An organization uses Azure App Service to host a web application. Which
responsibility is generally handled by Microsoft?

A. Writing secure application code
B. Managing the physical servers
C. Determining user permissions within the application
D. Classifying business data

Answer: Managing the physical servers

Rationale: App Service is a PaaS offering, so Microsoft manages the underlying
physical infrastructure and platform components while customers remain
responsible for their applications and data.

6. Which statement best describes the shared responsibility model?

A. Microsoft is responsible for all security tasks in Azure
B. Customers are responsible for all security tasks in Azure
C. Security responsibilities are divided between Microsoft and the customer
D. Security is the responsibility of the internet provider

Answer: Security responsibilities are divided between Microsoft and the
customer

Rationale: The shared responsibility model defines which security and
management responsibilities belong to the cloud provider and which remain
with the customer.

7. A customer accidentally grants excessive permissions to an Azure Storage
account. Who is responsible for correcting the access configuration?

A. Microsoft
B. The customer
C. The Azure hardware vendor
D. The data center operator

Answer: The customer

, Rationale: Customers are responsible for configuring access controls and
permissions for their cloud resources. Microsoft provides the platform and
security capabilities but does not automatically determine the customer's
intended access policies.

8. In an IaaS environment, who is generally responsible for configuring the
firewall rules associated with a customer's virtual network?

A. Microsoft exclusively
B. The customer
C. The physical data center team
D. The ISP

Answer: The customer

Rationale: Customers manage many network security configurations for their
IaaS resources, including network security rules and traffic controls within their
Azure environment.

9. Which component is Microsoft responsible for securing in Azure IaaS?

A. Customer's application code
B. Customer's guest operating system
C. Physical hosts
D. Customer's user passwords

Answer: Physical hosts

Rationale: Microsoft manages the physical hosts and underlying Azure
infrastructure. The customer manages software and configurations running
within their virtual machines.

10. A customer uses Microsoft 365 as a SaaS service. Who is responsible for the
physical security of Microsoft's data centers?

A. The customer
B. Microsoft

Document information

Uploaded on
September 1, 2026
Number of pages
37
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
mml1030
2.6
(5)
Sold
8
Followers
0
Items
1207
Last sold
5 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions