CertSafari

    Free Microsoft Certified: Azure Fundamentals (AZ-900) Sample Questions

    35 free sample questions from our bank of 347+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Describe cloud concepts

    Subdomain 1.1: Describe cloud computing

    1.Which characteristics genuinely apply to serverless computing as offered through services like Azure Functions? (Choose 3.)(Select 3)

    1. A.Code execution is triggered by events, such as a file upload or an incoming HTTP request
    2. B.Billing is generally based on actual execution time rather than pre-allocated, always-on capacity
    3. C.The cloud provider handles the underlying server management, so the developer does not provision virtual machines
    4. D.The developer must manually configure and patch the operating system that hosts the running function
    5. E.A dedicated virtual machine must be reserved and kept running at all times so the function can execute instantly
    6. F.The developer must forecast peak load in advance and pre-purchase enough server capacity to cover it
    Show answer & explanation

    Correct answers: A, B, C — Code execution is triggered by events, such as a file upload or an incoming HTTP request; Billing is generally based on actual execution time rather than pre-allocated, always-on capacity; The cloud provider handles the underlying server management, so the developer does not provision virtual machines

    • A. Correct: serverless functions are event-driven, executing in response to triggers like file uploads, queue messages, or HTTP requests rather than running continuously.
    • B. Correct: serverless billing is typically pay-per-execution, charging for actual compute time consumed rather than for reserved, always-on capacity.
    • C. Correct: the defining feature of serverless is that the provider manages the underlying infrastructure, so the developer never provisions or maintains a virtual machine.
    • D. Manually configuring and patching the operating system is an IaaS responsibility; serverless computing specifically removes this burden from the developer entirely.
    • E. Keeping a dedicated virtual machine running at all times describes traditional or IaaS hosting, which contradicts the on-demand, event-triggered nature of serverless execution.
    • F. Forecasting peak load and pre-purchasing capacity is exactly the traditional capacity-planning burden that serverless computing's automatic scaling is designed to eliminate.

    Subdomain 1.1: Describe cloud computing

    2.A retailer is told that a hybrid cloud deployment requires abandoning all on-premises infrastructure and moving every workload entirely into a public cloud provider.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: B — False

    • A. This would be incorrect: hybrid cloud is defined by interconnecting private and public environments together, not by abandoning on-premises infrastructure entirely.
    • B. Correct: a hybrid deployment keeps some workloads on private, on-premises infrastructure while interconnecting them with public cloud resources, so requiring a full move to public cloud contradicts the hybrid model.

    Subdomain 1.2: Describe the benefits of using cloud services

    3.Vertical scaling (scaling up) means adding more instances of a resource, such as additional VMs, to share the load.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: B — False

    • A. This statement describes horizontal scaling, not vertical scaling, so True is not the correct assessment of the statement as written.
    • B. Correct — vertical scaling means resizing a resource to a larger or smaller SKU; adding more instances to share the load is horizontal scaling instead.

    Subdomain 1.2: Describe the benefits of using cloud services

    4.In the Infrastructure as a Service (IaaS) model, Microsoft is responsible for patching the guest operating system running inside the customer's virtual machines.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: B — False

    • A. In IaaS, the customer controls the operating system running inside the VM, so it is the customer, not Microsoft, who is responsible for patching it.
    • B. Correct — in IaaS, guest OS patching is the customer's responsibility, since Microsoft only manages the underlying virtualization infrastructure, not what the customer installs on the VM.

    Subdomain 1.3: Describe cloud service types

    5.Which statement best describes Platform as a Service (PaaS) relative to Infrastructure as a Service (IaaS) and Software as a Service (SaaS)?

    1. A.PaaS is a middle ground where the provider manages the OS and middleware while the customer manages application code and data
    2. B.PaaS gives the customer the same level of infrastructure control as IaaS, including OS patching and network configuration
    3. C.PaaS gives the customer no more responsibility than SaaS, since the provider manages the application layer as well
    4. D.PaaS eliminates the need for the provider to maintain any physical infrastructure or internet connectivity at all
    Show answer & explanation

    Correct answer: A — PaaS is a middle ground where the provider manages the OS and middleware while the customer manages application code and data

    • A. This is correct because PaaS sits between IaaS and SaaS: the provider maintains the operating system, middleware, and development tools, while the customer focuses on building and running application code.
    • B. This is incorrect because IaaS, not PaaS, leaves OS patching and network configuration to the customer; PaaS removes that burden.
    • C. This is incorrect because SaaS goes further than PaaS by also managing the finished application itself, which PaaS customers still build and deploy.
    • D. This is incorrect because the cloud provider still maintains physical infrastructure and connectivity under PaaS, just as it does under IaaS and SaaS.

    Subdomain 1.3: Describe cloud service types

    6.An IT team needs to rapidly spin up and tear down several test and development environments that closely mirror their on-premises configuration, while keeping full control over OS versions and network settings on each environment. Which cloud service type is the best fit?

    1. A.Infrastructure as a Service, since virtual machines let the team control OS versions and network settings for each environment
    2. B.Platform as a Service, since the provider chooses the OS version and manages networking within the managed runtime
    3. C.Software as a Service, since the provider ships one fixed application configuration that the team cannot reconfigure per environment
    4. D.A physical server room the team must build, cable, and power on separately for every new test environment
    Show answer & explanation

    Correct answer: A — Infrastructure as a Service, since virtual machines let the team control OS versions and network settings for each environment

    • A. Infrastructure as a Service is correct because renting virtual machines gives the team direct control over OS versions and network configuration for each environment, and they can be started and stopped quickly.
    • B. This is incorrect because Platform as a Service abstracts away OS and network management, which removes the fine-grained control the team needs to mirror their on-premises setup.
    • C. This is incorrect because a fixed hosted application offers no ability to configure OS versions or networking per environment.
    • D. This is incorrect because physical server rooms take far longer to provision and reconfigure than cloud virtual machines, which defeats the team's need for rapid spin-up and teardown.

    Subdomain 1.3: Describe cloud service types

    7.A development team wants to build and deploy a new internal web application quickly, using a managed runtime and middleware so they don't have to install, patch, or maintain the operating system underneath their code. Which cloud service type matches this requirement?

    1. A.Platform as a Service supplies a managed runtime and middleware so developers deploy code without maintaining the OS.
    2. B.Infrastructure as a Service requires the team to install and patch the operating system running on rented virtual machines.
    3. C.Software as a Service offers a finished application with no option for the team to deploy its own custom code.
    4. D.A colocation facility requires the team to rack and manage its own physical servers alongside the middleware stack.
    Show answer & explanation

    Correct answer: A — Platform as a Service supplies a managed runtime and middleware so developers deploy code without maintaining the OS.

    • A. Platform as a Service matches because the provider maintains the operating system, middleware, and runtime, leaving developers free to focus only on their application code.
    • B. This is incorrect because virtual machines under Infrastructure as a Service still require the team to install and patch the OS themselves, which is exactly the burden they want to avoid.
    • C. This is incorrect because a fully packaged application does not provide a place to deploy custom-built code at all.
    • D. This is incorrect because a colocation facility still requires the team to own and manage physical hardware and the middleware stack running on it.

    Subdomain 1.2: Describe the benefits of using cloud services

    8.Complete the statement: A pricing approach in which a customer pays only for the resources actually consumed, with no large upfront hardware purchase required, is known as ___ pricing.

    1. A.Consumption-based, because charges scale directly with the amount of compute, storage, or other resources actually used.
    2. B.Fixed-capacity, because the customer commits to and pays for a set amount of hardware capacity every month.
    3. C.Perpetual-license, because the customer purchases the right to use the software indefinitely through one upfront payment.
    4. D.Flat-rate, because the customer pays the same predetermined amount regardless of how much the resource is used.
    Show answer & explanation

    Correct answer: A — Consumption-based, because charges scale directly with the amount of compute, storage, or other resources actually used.

    • A. Consumption-based pricing charges for what is actually used, which is exactly the pay-as-you-go model described, with no large upfront hardware purchase.
    • B. Fixed-capacity pricing requires committing to and paying for a set amount of capacity regardless of actual usage, which contradicts paying only for what is consumed.
    • C. A perpetual license is a one-time upfront purchase for indefinite use, which is the opposite of a usage-based, no-upfront-cost model.
    • D. A flat rate charges the same amount no matter how much is used, which does not match a model where cost scales with actual consumption.

    Subdomain 1.1: Describe cloud computing

    9.A company runs a customer database on an Azure virtual machine that it manages itself, installing the database engine and applying its own patches. Under the shared responsibility model, which party is responsible for the physical security of the datacenter hosting that virtual machine?

    1. A.Microsoft, because physical datacenter security always stays with the cloud provider no matter which service model is chosen.
    2. B.The company, because deploying a workload on a virtual machine shifts all physical security duties to the customer managing it.
    3. C.Both parties equally, because IaaS splits every layer of responsibility fifty-fifty between customer and provider.
    4. D.Neither party, because physical security is outsourced to a third-party auditor once resources move to the cloud.
    Show answer & explanation

    Correct answer: A — Microsoft, because physical datacenter security always stays with the cloud provider no matter which service model is chosen.

    • A. Correct: the physical datacenter, physical network, and physical hosts always stay with the cloud provider no matter which service model (IaaS, PaaS, or SaaS) the customer chooses.
    • B. Deploying a virtual machine shifts operating-system and workload responsibilities to the customer, but it never moves physical datacenter security, which always belongs to the provider.
    • C. Responsibility does shift toward the customer under IaaS for things like the OS and applications, but physical security specifically is never split fifty-fifty — it stays entirely with the provider.
    • D. There is no third-party auditor taking over physical security in the shared responsibility model; that duty is retained directly by the cloud provider itself.

    Domain 2: Describe Azure architecture and services

    Subdomain 2.1: Describe the core architectural components of Azure

    10.A retail company operating only within the European Union must keep customer data physically stored inside the EU at all times, but still wants automatic geo-redundant backup of its storage account to a second Azure region for disaster recovery. Which concept should the architecture rely on to choose that second region?

    1. A.Deploy geo-redundant storage using the storage account's region pair, since Azure pairs almost all regions within the same geography to satisfy data-residency requirements.
    2. B.Deploy geo-redundant storage to any Azure region worldwide, because Azure automatically restricts backup replication to regions that share the source region's legal jurisdiction.
    3. C.Deploy geo-redundant storage using a second availability zone in the same region, since zones in different physical locations already satisfy cross-region backup requirements.
    4. D.Deploy geo-redundant storage to a sovereign cloud such as Azure Government, because sovereign clouds are the only Azure environments that guarantee data stays within a single geography.
    Show answer & explanation

    Correct answer: A — Deploy geo-redundant storage using the storage account's region pair, since Azure pairs almost all regions within the same geography to satisfy data-residency requirements.

    • A. Correct — Azure pairs almost all regions with another region in the same geography specifically so that geo-redundant replication keeps data within the same broad jurisdiction while still protecting against a regional outage.
    • B. Incorrect — Azure does not automatically restrict replication targets by jurisdiction; the customer must deliberately choose a paired or otherwise appropriate region, since geo-redundant storage can technically replicate to any enabled secondary region the service allows.
    • C. Incorrect — availability zones are physically separate datacenters within the same region, not a different region, so replicating only across zones does not provide the cross-region disaster recovery that geo-redundant storage requires.
    • D. Incorrect — sovereign clouds like Azure Government are separate, isolated Azure environments for specific regulatory audiences; they are not a general mechanism for keeping backups within a chosen geography, and ordinary EU workloads run in global Azure regions instead.

    Subdomain 2.1: Describe the core architectural components of Azure

    11.A cloud administrator is compiling a reference sheet about Azure region pairs before a design review. Which of the following are genuine benefits that Microsoft documents for using a region pair? (Select 3.)(Select 3)

    1. A.Planned system updates are staggered across the paired regions so both aren't updated at the same time.
    2. B.One region in the pair is prioritized for recovery first if a geography-wide outage occurs.
    3. C.Almost all region pairs are located within the same geography to help meet data-residency needs.
    4. D.Deploying resources into a region pair automatically provides high availability without any extra configuration.
    5. E.Region pairs guarantee zero data loss during failover between the two paired regions.
    6. F.Every Azure region is guaranteed to have exactly one paired region assigned to it.
    Show answer & explanation

    Correct answers: A, B, C — Planned system updates are staggered across the paired regions so both aren't updated at the same time.; One region in the pair is prioritized for recovery first if a geography-wide outage occurs.; Almost all region pairs are located within the same geography to help meet data-residency needs.

    • A. Correct — Azure documentation states it strives to stagger planned updates across paired regions specifically to reduce the chance that a faulty update affects both regions at once.
    • B. Correct — Microsoft designates one region in each pair as the priority for recovery during a large-scale geography-wide outage, so components spread across the pair have a defined recovery order.
    • C. Correct — almost all paired regions share the same geography as their pair, which is called out specifically as supporting data-residency requirements for customers who must keep data within a jurisdiction.
    • D. Incorrect — Microsoft explicitly states that deploying to a region in a pair does not automatically make workloads more resilient or provide automatic high availability; customers must still design their own redundancy.
    • E. Incorrect — no documented guarantee promises zero data loss on failover; Microsoft-managed failover between paired regions is described as a last resort used only in catastrophic situations, not a lossless guarantee.
    • F. Incorrect — many newer regions are nonpaired and rely on availability zones instead of a paired region for resiliency, so pairing is not guaranteed for every region.

    Subdomain 2.1: Describe the core architectural components of Azure

    12.An engineer wants to place a resource group's resources in a different Azure region than the resource group itself, purely for team-organization reasons unrelated to compliance. True or False: this is against Azure's technical requirements and cannot be done.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: B — False

    • A. This is incorrect — resources can be located in a different region than their resource group, even though Microsoft recommends keeping them together to reduce the impact of a regional outage.
    • B. This is correct — Azure does not require resources to be deployed in the same region as their resource group; the recommendation to co-locate them is a best practice, not a hard requirement.

    Subdomain 2.2: Describe Azure compute and networking services

    13.An e-commerce site experiences unpredictable spikes in traffic during flash sales and needs a group of identical, load-balanced VM instances that automatically add or remove instances as demand changes. Which Azure resource should be deployed?

    1. A.Azure Virtual Machine Scale Sets, which manage a group of identical, load-balanced VMs and automatically scale the instance count based on demand
    2. B.Azure Availability Sets, which group existing VMs into separate fault and update domains but never add or remove any VM instances automatically at all
    3. C.Azure Virtual Desktop, which delivers virtualized Windows desktops to end users rather than hosting a scalable backend application tier
    4. D.Azure ExpressRoute, which provides a private network circuit to on-premises datacenters rather than compute capacity for an application
    Show answer & explanation

    Correct answer: A — Azure Virtual Machine Scale Sets, which manage a group of identical, load-balanced VMs and automatically scale the instance count based on demand

    • A. Virtual Machine Scale Sets are purpose-built to run a group of identical, load-balanced VMs and automatically increase or decrease the instance count in response to demand, matching the flash-sale scenario.
    • B. Availability sets improve fault and update resiliency for a fixed set of VMs but do not automatically add or remove instances, so they cannot handle sudden traffic spikes on their own.
    • C. Azure Virtual Desktop delivers remote desktop and app sessions to end users, which is an unrelated use case to scaling a backend application tier.
    • D. This service provides a private connection between an on-premises datacenter and Azure and does not supply any application compute capacity.

    Subdomain 2.2: Describe Azure compute and networking services

    14.Which TWO statements correctly describe Azure ExpressRoute?(Select 2)

    1. A.ExpressRoute connections reach Azure through a private connection that does not travel over the public internet
    2. B.ExpressRoute uses Border Gateway Protocol (BGP) to dynamically exchange routes between the on-premises network and Azure
    3. C.ExpressRoute requires every client device to install VPN client software before it can reach Azure resources
    4. D.ExpressRoute is available only as a point-to-site connection intended for individual remote users
    5. E.ExpressRoute traffic is always routed through the public internet to reach the nearest Azure region
    Show answer & explanation

    Correct answers: A, B — ExpressRoute connections reach Azure through a private connection that does not travel over the public internet; ExpressRoute uses Border Gateway Protocol (BGP) to dynamically exchange routes between the on-premises network and Azure

    • A. ExpressRoute connections are established through a connectivity provider over a private circuit that bypasses the public internet, which is one of its defining characteristics.
    • B. ExpressRoute uses BGP to dynamically exchange routes between the on-premises network, the Azure private addresses, and Microsoft public addresses.
    • C. ExpressRoute is a network-level connection established by a connectivity provider circuit, not a client VPN, so individual devices do not need VPN client software to use it.
    • D. ExpressRoute is a dedicated circuit-based service aimed at continuous site connectivity; point-to-site connections for individual users are a VPN Gateway feature, not ExpressRoute.
    • E. This is the opposite of how ExpressRoute works; its defining feature is that traffic does not travel over the public internet.

    Subdomain 2.2: Describe Azure compute and networking services

    15.Complete the sentence: Configuring an Azure DNS private zone for a virtual network allows resources in that network to resolve ____.

    1. A.custom domain names to private IP addresses within the virtual network, without publishing those records on the public internet
    2. B.public internet domain names faster by caching every public DNS record locally inside the virtual network for all connected resources
    3. C.VPN Gateway connection status by returning a health check result about the tunnel state instead of a name resolution
    4. D.Availability Zone placement for a VM by returning the physical zone number instead of any private IP address
    Show answer & explanation

    Correct answer: A — custom domain names to private IP addresses within the virtual network, without publishing those records on the public internet

    • A. An Azure DNS private zone lets resources in a virtual network resolve custom domain names to private IP addresses, and those records are not exposed on the public internet.
    • B. A private zone resolves names to private records scoped to the virtual network; it is not a caching layer for speeding up public internet name resolution.
    • C. DNS resolution returns name-to-IP-address mappings, not connection health status, so this does not describe what a private zone provides.
    • D. DNS records map names to IP addresses; they do not report which Availability Zone a VM is placed in.

    Subdomain 2.4: Describe Azure identity, access, and security

    16.An IT team is rolling out passwordless sign-in across the company and needs to shortlist which methods are actually supported for Microsoft Entra ID. Which three should make the shortlist? (Choose 3.)(Select 3)

    1. A.Windows Hello for Business
    2. B.Traditional password combined with security questions
    3. C.Self-service password reset
    4. D.FIDO2 security key
    5. E.Username and password only
    6. F.Microsoft Authenticator phone sign-in
    Show answer & explanation

    Correct answers: A, D, F — Windows Hello for Business; FIDO2 security key; Microsoft Authenticator phone sign-in

    • A. This is correct: it is a passwordless method that uses a device-bound PIN or biometric gesture instead of a typed password.
    • B. This still relies on a typed password as the primary credential, so it is not a passwordless method.
    • C. This lets a user reset a forgotten password, but it assumes a password still exists, so it is not itself a passwordless sign-in method.
    • D. This is correct: a physical security key that proves possession is a supported passwordless authentication method.
    • E. A username and password is the traditional password-based method, which is exactly what passwordless authentication is meant to replace.
    • F. This is correct: approving a sign-in through the phone app instead of typing a password is a supported passwordless method.

    Subdomain 2.4: Describe Azure identity, access, and security

    17.A colleague claims that if a user is granted the Reader role at the subscription level and separately granted the Contributor role at one resource group inside that subscription, their effective permissions in that resource group are simply the sum of both roles. Is this claim correct?

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: A — True

    • A. This statement is correct: Azure RBAC is an additive model, so a user's effective permissions in that resource group combine into the sum of the Reader assignment and the Contributor assignment.
    • B. This option would be correct only if roles subtracted from each other or the most restrictive one always won, but Azure RBAC does not work that way, so this does not apply here.

    Subdomain 2.3: Describe Azure storage services

    18.After creating a Standard general-purpose v1 storage account two years ago, an administrator now wants access tiers and lifecycle management, which v1 accounts do not support. What is the recommended path forward?

    1. A.Upgrade the account in place to general-purpose v2, which adds access tiers without downtime or copying data
    2. B.Delete the account and manually recreate every blob container and file share from a fresh local backup copy
    3. C.Change the account's redundancy option from LRS to GRS, which is claimed to automatically add access tier support
    4. D.Enable the archive tier directly on the v1 account, on the assumption that archive works independent of account type
    Show answer & explanation

    Correct answer: A — Upgrade the account in place to general-purpose v2, which adds access tiers without downtime or copying data

    • A. Microsoft provides an in-place upgrade from general-purpose v1 to general-purpose v2 that requires no downtime and no data copying, and it unlocks access tiers and lifecycle management once completed.
    • B. A destructive recreate-from-backup approach is unnecessary because Microsoft explicitly supports an in-place upgrade path from v1 to v2 without needing to delete and rebuild the account.
    • C. Changing the redundancy setting only affects how many copies of data are kept and where; it does not change the account type or add access tier and lifecycle management capabilities.
    • D. Access tiers, including archive, are a general-purpose v2 (or Blob Storage account) capability; a v1 account does not gain tiering just by attempting to set a tier without upgrading first.

    Subdomain 2.3: Describe Azure storage services

    19.An administrator needs to copy several terabytes of files from an on-premises server into an Azure Files share using a scriptable command that can run unattended as part of a nightly automation job. Which tool best fits this requirement?

    1. A.AzCopy, a command-line utility built for high-performance, scriptable bulk data transfers to and from Azure Storage
    2. B.Azure Storage Explorer, a graphical desktop application intended for manual, visual browsing and ad-hoc transfers
    3. C.Azure File Sync, a service that keeps an on-premises server continuously synchronized as a cache of an Azure file share
    4. D.Azure Migrate, an assessment and orchestration service for planning server and database migrations to Azure
    Show answer & explanation

    Correct answer: A — AzCopy, a command-line utility built for high-performance, scriptable bulk data transfers to and from Azure Storage

    • A. AzCopy is a command-line tool purpose-built for high-performance bulk data transfers to and from Azure Storage, and its scriptable nature makes it well suited to run unattended inside a nightly automation job.
    • B. Storage Explorer is a graphical desktop application meant for manually browsing and transferring files by hand, which does not fit an unattended, scripted automation job.
    • C. Azure File Sync is designed for an ongoing, continuously active synchronization relationship between a server and an Azure file share, not for a one-off scripted bulk copy job.
    • D. Azure Migrate is focused on assessing and orchestrating the migration of servers, databases, and virtual desktops, not on scripting file transfers into Azure Files.

    Subdomain 2.3: Describe Azure storage services

    20.A team is comparing storage account performance tiers for a workload that requires consistently low latency and high throughput because it backs I/O-intensive virtual machine disks and database engines. They must choose between the Standard and Premium performance tiers in the portal. Which should they pick, and why?

    1. A.Premium, because it uses solid-state drives to deliver consistent low-latency, high-throughput performance
    2. B.Standard, because it uses solid-state drives and is the newer, faster-performing option overall
    3. C.Premium, because it always replicates data to a secondary region regardless of the redundancy setting chosen
    4. D.Standard, because it is the only performance tier that supports storing block blobs at all
    Show answer & explanation

    Correct answer: A — Premium, because it uses solid-state drives to deliver consistent low-latency, high-throughput performance

    • A. Premium performance storage accounts are backed by solid-state drives and are recommended for scenarios needing consistent low latency and high throughput, such as I/O-intensive VM disks and databases.
    • B. Standard performance accounts are backed by traditional hard disk drives, not solid-state drives, and Premium is the tier built for higher performance, not Standard.
    • C. Performance tier and redundancy setting are independent choices; selecting Premium does not by itself force geo-replication to a secondary region.
    • D. Both Standard and Premium performance tiers can store block blobs, so block blob support alone is not a reason to prefer Standard over Premium for this workload.

    Subdomain 2.4: Describe Azure identity, access, and security

    21.A security architect redesigns access policies so that every request, whether it originates inside or outside the corporate network, must be authenticated and authorized before being granted, instead of trusting requests that come from inside the office network. Which security model does this redesign reflect?

    1. A.Zero Trust, which requires explicit verification of every request no matter its source.
    2. B.Defense-in-depth, which layers several independent security controls across the network.
    3. C.Role-based access control, which governs the actions an authenticated identity can take.
    4. D.Multifactor authentication, which strengthens the proof of identity during sign-in.
    Show answer & explanation

    Correct answer: A — Zero Trust, which requires explicit verification of every request no matter its source.

    • A. This is correct because verifying every request explicitly regardless of where it originates matches the architect's decision to stop trusting requests just because they come from inside the network.
    • B. This describes layering multiple independent security controls so that a failure in one layer does not compromise the whole environment, which is a related but different concept from removing implicit network trust.
    • C. This governs what an already-authenticated identity can do on a resource, but it does not itself define whether network location should be trusted during authentication.
    • D. This strengthens the proof of identity during sign-in, but on its own it does not describe the broader principle of never trusting a request based on network location.

    Subdomain 2.1: Describe the core architectural components of Azure

    22.A government contractor must run Azure workloads for a U.S. federal agency under a compliance framework that requires physical and logical isolation from the commercial Azure cloud used by the general public. Which type of Azure environment satisfies this requirement?

    1. A.A sovereign cloud such as Azure Government, which is operated as a separate, isolated environment for customers with specific regulatory or national-security requirements.
    2. B.A dedicated management group created inside the standard public Azure cloud, since management groups already provide full physical isolation from other tenants.
    3. C.A resource group configured with a resource lock, since locks prevent any other Azure customer from accessing resources inside that resource group.
    4. D.A single-tenant subscription within the public Azure cloud, since Azure isolates each subscription onto its own dedicated datacenter hardware, kept separate from other tenants.
    Show answer & explanation

    Correct answer: A — A sovereign cloud such as Azure Government, which is operated as a separate, isolated environment for customers with specific regulatory or national-security requirements.

    • A. Correct — sovereign clouds like Azure Government run in physically and logically separate environments built for customers who must meet specific regulatory, national-security, or jurisdictional requirements that the public cloud doesn't satisfy on its own.
    • B. Incorrect — a management group is a logical container for organizing subscriptions under shared policy or access settings within the same Azure cloud; it does not move workloads into a physically separate environment.
    • C. Incorrect — a resource lock only prevents accidental deletion or modification of resources by authorized users within the same subscription; it has no effect on which physical cloud environment or datacenters the resources run in.
    • D. Incorrect — subscriptions are billing and management boundaries within a shared pool of Azure infrastructure, not physically isolated environments, so a standard subscription in the public cloud does not meet a requirement for separation from that same public cloud.

    Domain 3: Describe Azure management and governance

    Subdomain 3.2: Describe features and tools in Azure for governance and compliance

    23.A governance team is designing controls for a new subscription. Which of the following are valid uses of Azure Policy? (Choose 3)(Select 3)

    1. A.Restrict new resource deployments to a specific set of approved Azure regions.
    2. B.Require every deployed resource to send diagnostic logs to a designated Log Analytics workspace.
    3. C.Grant a support engineer temporary read access to billing invoices for the subscription.
    4. D.Block resource-deletion actions initiated by users who have not enabled multifactor authentication.
    5. E.Encrypt data stored in an Azure SQL Database using a customer-managed key at rest.
    6. F.Estimate the total cost of ownership of migrating an on-premises workload to Azure.
    Show answer & explanation

    Correct answers: A, B, D — Restrict new resource deployments to a specific set of approved Azure regions.; Require every deployed resource to send diagnostic logs to a designated Log Analytics workspace.; Block resource-deletion actions initiated by users who have not enabled multifactor authentication.

    • A. Restricting allowed deployment regions is a documented common use case for Azure Policy, enforced through built-in definitions such as Allowed Locations.
    • B. Requiring diagnostic logs to flow to a Log Analytics workspace is a standard governance action that Azure Policy can enforce on resource configuration.
    • C. Granting temporary read access to billing data is an identity and access management task handled through RBAC, not something Azure Policy enforces.
    • D. Azure Policy can inspect the identity context of a request and block resource-delete actions when the requester has not enabled multifactor authentication.
    • E. Encrypting data at rest with a customer-managed key is a feature configured within the data service itself, not a control that Azure Policy implements.
    • F. Estimating total cost of ownership for a migration is performed with cost-management tools such as the TCO calculator, not with Azure Policy.

    Subdomain 3.2: Describe features and tools in Azure for governance and compliance

    24.A security architect reviewing a subscription's governance posture notes several resource locks already applied. Which statements correctly describe how those locks behave? (Choose 3)(Select 3)

    1. A.A ReadOnly lock on a resource group blocks moving existing resources into or out of that group.
    2. B.Removing a CanNotDelete lock automatically also removes any ReadOnly lock applied at the same scope.
    3. C.Locks override individual user role assignments, applying the same restriction to every user at that scope.
    4. D.A resource lock on a storage account also restricts data-plane operations against blobs stored inside it.
    5. E.Management groups can have locks applied directly to them just like subscriptions and resource groups.
    6. F.The most restrictive lock in an inheritance chain from parent to child scope takes precedence.
    Show answer & explanation

    Correct answers: A, C, F — A ReadOnly lock on a resource group blocks moving existing resources into or out of that group.; Locks override individual user role assignments, applying the same restriction to every user at that scope.; The most restrictive lock in an inheritance chain from parent to child scope takes precedence.

    • A. A ReadOnly lock at a resource group scope does prevent moving resources in or out of that group, since a move is treated as a write operation.
    • B. Locks are independent objects; removing one lock has no effect on any other lock applied at the same scope, so it would not remove a separate ReadOnly lock.
    • C. Resource locks apply their restriction to every user and role at the locked scope, overriding whatever RBAC permissions those users otherwise hold.
    • D. Locks only protect control-plane operations; they do not restrict data-plane operations, so blob data inside a locked storage account is not protected by the lock.
    • E. Management groups cannot have locks applied to them directly; locks are supported at the subscription, resource group, and resource levels.
    • F. When locks exist at multiple levels in the hierarchy, the most restrictive one in that inheritance chain is the one that takes effect.

    Subdomain 3.1: Describe cost management in Azure

    25.A batch-processing job can tolerate being interrupted and restarted at any time, and the team wants the lowest possible compute price for it by using unused Azure capacity. Which pricing option fits this workload?

    1. A.Spot Virtual Machines
    2. B.Reserved Instances
    3. C.Azure Hybrid Benefit
    4. D.Pay-as-you-go on-demand pricing
    Show answer & explanation

    Correct answer: A — Spot Virtual Machines

    • A. This option offers unused Azure compute capacity at a steep discount, in exchange for accepting that the virtual machine can be reclaimed with little notice, which matches an interruption-tolerant batch job.
    • B. This option requires a one- or three-year commitment to a fixed VM size for a lower rate; it does not offer the deepest discount available for interruptible workloads.
    • C. This benefit reduces cost by reusing an existing on-premises license; it does not offer the steep, capacity-based discount that an interruptible workload can take advantage of.
    • D. This option charges the standard hourly rate with no commitment and no interruption risk, which costs more than accepting reclaimable capacity for a tolerant workload.

    Subdomain 3.1: Describe cost management in Azure

    26.Complete the sentence: A key-value pair such as `Environment = Production` that is attached to a resource so spending can later be filtered and grouped in billing reports is called a ____.

    1. A.Tag
    2. B.Resource lock
    3. C.Policy assignment
    4. D.Management group
    Show answer & explanation

    Correct answer: A — Tag

    • A. A tag is exactly this kind of metadata key-value pair, applied to a resource so it can be identified, filtered, and grouped in cost and billing reports.
    • B. A resource lock controls whether a resource can be deleted or modified; it carries no key-value data and plays no role in billing reports.
    • C. A policy assignment enforces a rule or compliance requirement on resources; it is not a key-value label used for cost grouping.
    • D. A management group is a container used to organize subscriptions for governance; it is not a per-resource key-value label.

    Subdomain 3.1: Describe cost management in Azure

    27.Azure tags can be applied to management groups in addition to resources, resource groups, and subscriptions.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: B — False

    • A. This would be incorrect: management groups are explicitly excluded from the scopes that support tags.
    • B. This is accurate: tags can be applied to resources, resource groups, and subscriptions, but management groups do not support tags at all.

    Subdomain 3.3: Describe features and tools for managing and deploying Azure resources

    28.A cloud architect is designing an automated deployment pipeline and needs to select which Azure Resource Manager deployment mode to use for a resource group. Complete the statement: choosing the ____ deployment mode means any resource already in the resource group but not listed in the template will be deleted during the deployment.

    1. A.Complete
    2. B.Incremental
    3. C.Partial
    4. D.Preview
    Show answer & explanation

    Correct answer: A — Complete

    • A. Complete mode tells Resource Manager to treat the template as the full desired state of the resource group, deleting any existing resource that is not declared in the template.
    • B. Incremental mode, the default, adds or updates the resources in the template and leaves existing resources not listed in the template untouched rather than deleting them.
    • C. Partial is not a deployment mode that Azure Resource Manager offers for ARM template deployments.
    • D. Preview is not a deployment mode; Resource Manager supports only Incremental and Complete modes for deployments.

    Subdomain 3.3: Describe features and tools for managing and deploying Azure resources

    29.A DevOps engineer is scripting a repeatable deployment pipeline and can choose to run Azure CLI commands from several places. Which of the following are valid ways to run the Azure CLI? (Select all that apply.)(Select 4)

    1. A.From the Bash environment inside Azure Cloud Shell, where the CLI is already preinstalled
    2. B.From a locally installed copy of the CLI on a Windows, macOS, or Linux workstation
    3. C.From within a CI/CD pipeline step that invokes CLI commands as part of an automated build or release
    4. D.From a Docker container that has the official Microsoft Azure CLI image installed
    5. E.Only from inside the Azure portal's dashboard tile editor, with no other entry point supported
    6. F.Only from a physical Azure datacenter console that Microsoft operators access directly
    Show answer & explanation

    Correct answers: A, B, C, D — From the Bash environment inside Azure Cloud Shell, where the CLI is already preinstalled; From a locally installed copy of the CLI on a Windows, macOS, or Linux workstation; From within a CI/CD pipeline step that invokes CLI commands as part of an automated build or release; From a Docker container that has the official Microsoft Azure CLI image installed

    • A. Cloud Shell's Bash environment comes with the Azure CLI preinstalled and authenticated, making it one of the most common ways to run CLI commands without any local setup.
    • B. The Azure CLI can be installed locally on Windows, macOS, or Linux, letting engineers run the same commands directly from their own machine.
    • C. CLI commands are commonly invoked from CI/CD pipeline steps to automate resource provisioning as part of build and release workflows.
    • D. Microsoft publishes an official Azure CLI Docker image, so the CLI can be run inside a container as part of containerized tooling or pipelines.
    • E. The dashboard tile editor is a portal customization feature, not a place to run command-line commands, and it is not the only entry point for the CLI.
    • F. Customers never access a physical Azure datacenter console directly; the Azure CLI runs on user-accessible tools like Cloud Shell, local installs, and containers, not datacenter hardware.

    Subdomain 3.3: Describe features and tools for managing and deploying Azure resources

    30.Every request sent through the Azure portal, CLI, PowerShell, or REST API is authenticated and forwarded to the correct service by the same underlying layer, which is why all of these tools produce consistent results and capabilities.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: A — True

    • A. This is correct — Azure Resource Manager receives, authenticates, and authorizes every request from any Azure API, tool, or SDK before forwarding it, which is exactly what keeps behavior consistent across the portal, CLI, and PowerShell.
    • B. This is incorrect — Resource Manager genuinely is the shared layer behind the portal, CLI, PowerShell, and REST API, so labeling this statement false does not match how Azure request handling works.

    Subdomain 3.4: Describe monitoring tools in Azure

    31.A finance team is auditing which Azure monitoring tools their organization already pays extra for versus which are included at no additional cost. Which two of the following are available in Azure at no additional charge beyond the resources they observe? (Choose 2)(Select 2)

    1. A.Azure Advisor recommendations
    2. B.The public Azure Status page
    3. C.Extended data retention in a Log Analytics workspace beyond the free tier
    4. D.Premium third-party SIEM integration bundled with every subscription
    Show answer & explanation

    Correct answers: A, B — Azure Advisor recommendations; The public Azure Status page

    • A. Azure Advisor recommendations are provided at no additional cost to any Azure subscription, since Advisor simply analyzes configuration and usage data that already exists.
    • B. The Azure Status page is a public webpage available to anyone without an Azure subscription or any charge, showing the health of Azure services globally.
    • C. Extending log data retention beyond the free allotment in a Log Analytics workspace incurs additional cost based on data volume and retention period, so it is not free.
    • D. There is no premium third-party SIEM integration automatically bundled free with every Azure subscription; such integrations are separate products with their own licensing.

    Subdomain 3.4: Describe monitoring tools in Azure

    32.True or False: Azure Advisor generates its recommendations by analyzing an organization's actual resource configuration and usage telemetry, rather than from a static checklist that ignores how the resources are actually used.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: A — True

    • A. This is true; Advisor analyzes real resource configuration and usage telemetry to produce recommendations personalized to the actual deployment, not a generic static checklist.
    • B. This is not the correct answer, since Advisor genuinely bases its recommendations on live configuration and telemetry analysis rather than a fixed, usage-independent checklist.

    Subdomain 3.4: Describe monitoring tools in Azure

    33.A logistics company's web portal, instrumented with Application Insights, shows a sudden rise in HTTP 500 errors after a deployment. The on-call engineer needs to correlate this with any concurrent Azure platform issue in the same region before rolling back. Which second tool should they check alongside Application Insights?

    1. A.Azure Service Health, which shows whether a platform outage hit the deployment's region.
    2. B.Azure Advisor, to check whether it flagged new cost optimization recommendations after the deployment.
    3. C.Cost analysis, to review this month's spending trend for the App Service plan hosting the portal.
    4. D.Resource locks, to confirm which resources in the portal's resource group are protected from deletion.
    Show answer & explanation

    Correct answer: A — Azure Service Health, which shows whether a platform outage hit the deployment's region.

    • A. Service Health is the right second check because it reports whether a concurrent Azure platform outage or incident in that region could be contributing to the error spike, which matters before deciding to roll back application code.
    • B. Advisor's cost recommendations are unrelated to diagnosing a sudden application error spike and would not help determine whether a platform issue is involved.
    • C. Reviewing spending trends has no bearing on diagnosing an application error spike or ruling out a concurrent platform incident.
    • D. Resource lock configuration governs whether resources can be deleted or modified and has no diagnostic value for an application error spike.

    Subdomain 3.2: Describe features and tools in Azure for governance and compliance

    34.An administrator assigns an Azure Policy definition with a deny effect to a resource group to block storage accounts outside a set of allowed SKUs. A developer with Contributor access tries to create a disallowed SKU. What happens?

    1. A.The deployment succeeds because Contributor access always overrides policy assignments scoped to a resource group.
    2. B.The deployment is logged as non-compliant but still completes, since deny effects only apply during scheduled evaluation cycles.
    3. C.The deployment request is blocked because Azure Policy evaluates resource properties regardless of the requester's role assignment.
    4. D.The deployment is redirected automatically to a compliant SKU, since the deployIfNotExists effect remediates it during the request.
    Show answer & explanation

    Correct answer: C — The deployment request is blocked because Azure Policy evaluates resource properties regardless of the requester's role assignment.

    • A. Contributor access does not override a policy assignment; Azure Policy evaluates resource state independently of who is making the request.
    • B. A deny effect is enforced at the moment of the request, not only on the periodic compliance cycle, so the deployment does not complete.
    • C. This is correct because Azure Policy checks resource properties against the assigned rule regardless of the requester's permissions, and the deny effect stops the non-compliant deployment immediately.
    • D. deployIfNotExists deploys a related compliant resource after the fact; it does not silently substitute a different SKU for a denied request.

    Subdomain 3.2: Describe features and tools in Azure for governance and compliance

    35.Which role assignments allow a user to create or delete a management lock?

    1. A.Any role holder at the subscription scope, since locks apply independently of any RBAC role assignments.
    2. B.Reader, since viewing a lock's configuration is treated the same as managing its lifecycle.
    3. C.Contributor, since it grants full read and write access to every resource property and setting.
    4. D.Owner or User Access Administrator, since lock management requires Microsoft.Authorization permissions.
    Show answer & explanation

    Correct answer: D — Owner or User Access Administrator, since lock management requires Microsoft.Authorization permissions.

    • A. Locks being independent of RBAC for their enforcement does not mean any role can manage them; creating or removing a lock still requires specific permissions.
    • B. Reader access only allows viewing resources and their settings; it does not grant the write permissions needed to create or remove a lock.
    • C. Contributor access does not include the Microsoft.Authorization permissions needed for lock management, so it cannot create or delete locks.
    • D. This is correct because managing locks requires Microsoft.Authorization/locks actions, which the Owner and User Access Administrator roles grant.

    Want the full experience?

    These are just samples. Practice the full Microsoft Certified: Azure Fundamentals (AZ-900) question bank in quiz mode — free, no signup, with domain practice and exam simulation.