Microsoft

AZ-900 Practice Test: 10 Original Questions

Ten questions across the three AZ-900 skill areas: cloud concepts, Azure architecture and services, and Azure management and governance. Each one is a short scenario about which model, service or tool fits, and each answer links to the Microsoft Learn page it rests on.

These questions were written for CertBlaze from the official Microsoft Azure Fundamentals exam guide, with AI assistance. They are not taken from the real exam, an exam dump or any other question bank. Each answer names the official page it is based on; if you spot a mistake, please tell us.

What this set covers

  • Describe cloud concepts: 3 questions
  • Describe Azure architecture and services: 4 questions
  • Describe Azure management and governance: 3 questions

Question 1

Describe cloud concepts

A bank keeps its core customer database in its own data center for regulatory reasons and runs its public website and analytics in Azure, with a private connection between the two. Which cloud model is this?

A. Public cloud
B. Private cloud
C. Hybrid cloud
D. Multi-cloud
Show Answer
Correct Answer: C
Explanation:
A hybrid cloud combines on-premises (private) infrastructure with a public cloud and connects them. A purely public (A) or purely private (B) model uses only one side. Multi-cloud (D) means using more than one public cloud provider.
Source: Define cloud models (Microsoft Learn)

Question 2

Describe cloud concepts

Under the shared responsibility model, in which cloud service type is the customer responsible for patching the operating system?

A. None; the provider always patches the operating system
B. Platform as a service (PaaS)
C. Software as a service (SaaS)
D. Infrastructure as a service (IaaS)
Show Answer
Correct Answer: D
Explanation:
With IaaS the provider runs the physical hosts, network and datacenter, while the customer manages the operating system, applications and data on its virtual machines. In PaaS (B) and SaaS (C) the provider also manages the operating system.
Source: Shared responsibility in the cloud (Microsoft Learn)

Question 3

Describe cloud concepts

Which statement describes the consumption-based model of cloud computing?

A. You buy hardware up front and depreciate it over several years.
B. You pay a fixed monthly fee regardless of usage.
C. You pay only for the resources you use, with no up-front infrastructure cost.
D. You must reserve capacity for at least one year before using it.
Show Answer
Correct Answer: C
Explanation:
In the consumption-based model you pay for what you use, which turns infrastructure from a capital expense into an operating expense. Up-front hardware purchases (A) are the capital expense model. Fixed fees (B) and mandatory reservations (D) are not how the model is defined, although Azure does offer optional reservations for discounts.
Source: Describe the consumption-based model (Microsoft Learn)

Question 4

Describe Azure architecture and services

A company wants its two web servers to keep running if a single datacenter in an Azure region fails. Where should it deploy the virtual machines?

A. In two resource groups
B. In one virtual network with two subnets
C. In two availability zones in the same region
D. In two management groups
Show Answer
Correct Answer: C
Explanation:
Availability zones are physically separate datacenters within one region, with independent power, cooling and networking, so VMs in different zones survive a single datacenter failure. Resource groups (A) and management groups (D) are logical containers, and subnets (B) are network divisions; none of them places VMs in separate datacenters.
Source: What are availability zones? (Microsoft Learn)

Question 5

Describe Azure architecture and services

A developer needs to run a single container for a short batch task without managing virtual machines or a container orchestrator. Which Azure service fits best?

A. Azure Kubernetes Service (AKS)
B. Azure Virtual Desktop
C. Azure Virtual Machine Scale Sets
D. Azure Container Instances
Show Answer
Correct Answer: D
Explanation:
Azure Container Instances runs containers on demand without VMs or an orchestrator to manage, which suits simple or short-lived tasks. AKS (A) is a managed Kubernetes cluster for orchestrating many containers. Scale sets (C) run VMs you manage, and Virtual Desktop (B) delivers desktops and apps to users.
Source: What is Azure Container Instances? (Microsoft Learn)

Question 6

Describe Azure architecture and services

A company must keep scanned contracts for ten years. The files are almost never read, a retrieval delay of several hours is acceptable, and storage cost must be as low as possible. Which blob access tier should it use?

A. Hot
B. Cool
C. Cold
D. Archive
Show Answer
Correct Answer: D
Explanation:
The Archive tier has the lowest storage cost and is offline, so a blob must be rehydrated before it can be read, which can take hours. Hot (A), Cool (B) and Cold (C) are online tiers with higher storage prices that suit data you need to read without waiting.
Source: Access tiers for blob data (Microsoft Learn)

Question 7

Describe Azure architecture and services

A company wants users to approve each sign-in in an authenticator app on their phone in addition to entering a password. Which feature provides this?

A. Microsoft Entra multifactor authentication
B. Azure role-based access control (Azure RBAC)
C. Microsoft Entra Connect
D. Azure Key Vault
Show Answer
Correct Answer: A
Explanation:
Microsoft Entra multifactor authentication asks for a second form of verification, such as an authenticator app approval, after the password. Azure RBAC (B) controls what a signed-in user may do, Entra Connect (C) synchronizes on-premises identities, and Key Vault (D) stores secrets and keys.
Source: How it works: Microsoft Entra multifactor authentication (Microsoft Learn)

Question 8

Describe Azure management and governance

Company policy says resources may only be created in West Europe and North Europe. Which Azure feature can enforce this automatically?

A. Azure role-based access control (Azure RBAC)
B. Resource locks
C. Azure Policy
D. Azure Advisor
Show Answer
Correct Answer: C
Explanation:
Azure Policy evaluates resource properties such as location and can deny deployments that break a rule; a built-in definition restricts allowed locations. RBAC (A) controls who can act, not what the resource may look like. Locks (B) prevent deletion or changes to existing resources. Advisor (D) only recommends.
Source: What is Azure Policy? (Microsoft Learn)

Question 9

Describe Azure management and governance

Administrators need full access to a production storage account, but the company wants to prevent anyone from deleting it by mistake. What should it apply?

A. A CanNotDelete resource lock
B. An Azure Policy assignment
C. A Microsoft Defender for Cloud recommendation
D. A new resource group
Show Answer
Correct Answer: A
Explanation:
A CanNotDelete lock lets authorized users read and modify the resource but blocks deletion until the lock is removed, regardless of their role. Azure Policy (B) governs resource properties at deployment time rather than blocking a delete. Defender for Cloud (C) gives security recommendations, and a resource group (D) is only a container.
Source: Lock your resources to protect your infrastructure (Microsoft Learn)

Question 10

Describe Azure management and governance

Before deploying anything, a team wants to estimate the monthly cost of three virtual machines, a SQL database and some blob storage. Which tool should it use?

A. The Total Cost of Ownership (TCO) calculator
B. The Azure pricing calculator
C. Microsoft Cost Management
D. Azure Advisor
Show Answer
Correct Answer: B
Explanation:
The pricing calculator estimates the cost of Azure services you plan to use. The TCO calculator (A) compares the cost of running on-premises against Azure. Cost Management (C) reports and budgets spend for resources that already exist, and Advisor (D) recommends optimizations.
Source: Compare the pricing and TCO calculators (Microsoft Learn)