AZ-900 Practice Questions
These original AZ-900 questions practice cloud models, Azure service choices, governance, identity, and monitoring.
- They are not copied from Microsoft's secure exam and do not predict a score or reproduce the live format.
- Answer each item before reading the explanation, then identify which requirement makes the best option fit.
On this page5 sections
How to use this practice set
This is a short set of original practice questions written to teach AZ-900 concepts. It is not Microsoft's Practice Assessment, a full-length mock exam, or a reproduction of secure questions. Microsoft does not publish an exact AZ-900 item count or fixed item mix. Use the questions to learn why a service fits a requirement and why nearby options do not.
Try each item before reading its rationale. In your notes, record the need in the scenario, the concept you applied, and why the strongest distractor does not solve the same problem. If your choice was correct by guess, mark it for review. The goal is to transfer understanding to different wording.
A company wants to run its own application and operating system on virtualized resources in Azure. It wants control over the guest operating system and is prepared to manage it. Which service model best describes this approach?
- Software as a service (SaaS).
- Infrastructure as a service (IaaS).
- Platform as a service (PaaS).
- A private cloud by definition.
An administrator wants to reduce the chance that an authorized operator accidentally deletes a production resource. Which Azure feature most directly helps protect the resource from deletion?
- A resource lock.
- A tag.
- Azure Monitor alert.
- A public endpoint.
A team wants to know whether an Azure service issue or planned maintenance may affect resources in its subscription. Which tool is designed for this kind of information?
- Azure Advisor.
- Azure Service Health.
- Application Insights.
- Azure Policy.
A company wants to assign a user permission to manage virtual machines in a specific resource group without granting the same permission across the subscription. Which Azure capability should it use?
- Azure role-based access control at the resource-group scope.
- A subscription tag.
- Microsoft Purview.
- Azure Service Health.
Before deploying a new application, a team wants an estimate of expected Azure charges based on planned services and usage. Which tool is the most direct fit?
- Azure pricing calculator.
- Azure Monitor alerts.
- Microsoft Entra ID.
- A resource lock.
A company uses a SaaS application hosted by a cloud provider. Which responsibility remains with the customer?
- Maintain the provider's datacenter cooling systems.
- Manage user access and protect the company's data through appropriate configuration and use.
- Replace failed physical disks in the provider's storage cluster.
- Patch the provider's physical host operating system.
What these questions cover
The set includes cloud service models, governance, monitoring, access control, cost estimation, and shared responsibility. Those ideas span the three current AZ-900 domains: Cloud concepts, Azure architecture and services, and Azure management and governance. Six questions are not a representative sample of every skill or the distribution on a candidate's exam.
Notice how the requirement controls the answer. If the question asks about an authorized operator deleting a resource, a lock is relevant. If it asks who can perform an action, RBAC is relevant. If it asks whether an Azure service has an incident, Service Health fits. A familiar Azure product may be technically useful yet still fail to answer the specific question.
Several options may be helpful in a real design. A production environment may use RBAC, Policy, locks, monitoring, and backups together. An exam item asks for the most direct tool for one stated goal. Choose that fit, then understand the other controls' boundaries.
A method for narrowing the options
Start by naming the action or outcome requested: estimate, prevent, authorize, monitor, migrate, host, or identify an outage. Then translate the requirement into a capability. For example, ‘who can do what at this scope’ points toward authorization and RBAC. ‘Stop accidental deletion’ points toward a lock. ‘Show likely charges before deployment’ points toward an estimate.
Eliminate choices that answer another question. A notification is not prevention. Metadata is not a permission. Monitoring is not governance. Authentication is not authorization. A service that can display cost after use may not be the right tool for estimating cost before deployment. Naming the verb often makes the distinction clear.
Check cloud responsibility questions by identifying which layer is described. In IaaS, customers manage more of the operating system than in PaaS or SaaS. Across service models, customers still manage identities, data, access, and configuration. Avoid answer choices that transfer every security responsibility to the provider simply because the application runs in cloud.
How to review a miss
If you missed an item, do not only record the right letter. Explain the distinction you overlooked. If you selected Advisor for a service incident, write that Advisor recommends improvements while Service Health addresses service issues and maintenance. If you selected Policy for a user's permission, write that Policy controls configuration while RBAC grants resource actions.
Then create a new scenario with different nouns. Instead of a production virtual machine, use a database or storage account. Instead of an operator deleting a resource, ask who can alter a network rule. The answer may change with the requirement. This checks whether you learned a service purpose or merely memorized an example.
Use the Microsoft Practice Assessment to identify further gaps and consult the official study guide for scope. Microsoft says its practice items differ from the secure exam and do not model the complete test length or complexity. Do not turn the percentage on this set into an expected AZ-900 scaled score.
Read the official outline alongside practice
The current outline is measured as of July 20, 2026. It includes public, private, and hybrid cloud; consumption and pricing; Azure geography and resource hierarchy; compute, networking, storage, identity and security; cost, governance, deployment, and monitoring. Return to the outline when an example makes you realize a task is unfamiliar.
The Microsoft exam sandbox can familiarize you with the general navigation and item interactions. It does not reveal which question types AZ-900 will use, and Microsoft does not publish an exact exam item mix. Learn the interface separately from the Azure content.
Practice the foundational distinctions until you can answer in new contexts. A service name is useful only if you understand its purpose. If you can state what need a feature addresses, what it does not do, and which nearby option solves a different problem, you are building the kind of knowledge the outline describes.
A final self-check is to explain the boundary between nearby services without relying on the answer choices. Describe RBAC as authorization over Azure resources, Entra ID as identity and authentication, Policy as configuration governance, and Service Health as information about service incidents and maintenance. Then vary the scenario: a user can sign in but cannot create a virtual machine; a resource has a prohibited configuration; or a service incident affects a region. Each clue points to a different problem layer. This short explanation exercise is more useful than memorizing which option letter was correct.
Common questions
Are these official AZ-900 questions?
No. They are original examples for learning and do not reproduce Microsoft's secure exam or Practice Assessment.
Can this set predict my AZ-900 score?
No. Six questions are too few to predict a score and are not scored using Microsoft's scaled system.
Are the correct answers always the only useful Azure tools?
No. Real designs may combine tools. Each item asks for the best fit for one stated requirement.
What score passes AZ-900?
Microsoft requires 700 or greater on its 1-to-1,000 scaled scoring system.