Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

AZ-900 Practice Questions

Updated 8 min read
Key takeaway

These original AZ-900 questions practice cloud models, Azure service choices, governance, identity, and monitoring.

  • They are not copied from Microsoft's secure exam and do not predict a score or reproduce the live format.
  • Answer each item before reading the explanation, then identify which requirement makes the best option fit.
On this page5 sections
  1. How to use this practice set
  2. What these questions cover
  3. A method for narrowing the options
  4. How to review a miss
  5. Read the official outline alongside practice

How to use this practice set

This is a short set of original practice questions written to teach AZ-900 concepts. It is not Microsoft's Practice Assessment, a full-length mock exam, or a reproduction of secure questions. Microsoft does not publish an exact AZ-900 item count or fixed item mix. Use the questions to learn why a service fits a requirement and why nearby options do not.

Try each item before reading its rationale. In your notes, record the need in the scenario, the concept you applied, and why the strongest distractor does not solve the same problem. If your choice was correct by guess, mark it for review. The goal is to transfer understanding to different wording.

Question 1: cloud service model

A company wants to run its own application and operating system on virtualized resources in Azure. It wants control over the guest operating system and is prepared to manage it. Which service model best describes this approach?

  1. Software as a service (SaaS).
  2. Infrastructure as a service (IaaS).
  3. Platform as a service (PaaS).
  4. A private cloud by definition.
Answer: B. IaaS provides virtualized infrastructure while leaving the customer responsible for more of the operating system and workload. SaaS is a complete application consumed by the customer. PaaS manages more of the runtime and hosting platform. A private cloud describes a cloud deployment model, not the service model asked for.
Question 2: resource protection

An administrator wants to reduce the chance that an authorized operator accidentally deletes a production resource. Which Azure feature most directly helps protect the resource from deletion?

  1. A resource lock.
  2. A tag.
  3. Azure Monitor alert.
  4. A public endpoint.
Answer: A. A resource lock can help prevent deletion or modification at a scope. A tag adds metadata for organization or reporting but does not block an action. An Azure Monitor alert can notify someone about a condition but does not prevent the deletion. A public endpoint controls access path and does not protect against an authorized operator's mistake.
Question 3: service health

A team wants to know whether an Azure service issue or planned maintenance may affect resources in its subscription. Which tool is designed for this kind of information?

  1. Azure Advisor.
  2. Azure Service Health.
  3. Application Insights.
  4. Azure Policy.
Answer: B. Azure Service Health provides information about Azure service issues and planned maintenance relevant to the customer. Azure Advisor provides recommendations for improving resources. Application Insights focuses on application performance monitoring. Azure Policy governs or audits resource configuration. They can all support operational work but answer different questions.
Question 4: identity and access

A company wants to assign a user permission to manage virtual machines in a specific resource group without granting the same permission across the subscription. Which Azure capability should it use?

  1. Azure role-based access control at the resource-group scope.
  2. A subscription tag.
  3. Microsoft Purview.
  4. Azure Service Health.
Answer: A. Azure RBAC assigns permissions to identities at scopes such as resource group or subscription. The scenario asks who can manage Azure resources and at what scope. A tag organizes metadata and does not grant permission. Purview supports data governance and compliance functions. Service Health reports Azure service issues.
Question 5: cost estimation

Before deploying a new application, a team wants an estimate of expected Azure charges based on planned services and usage. Which tool is the most direct fit?

  1. Azure pricing calculator.
  2. Azure Monitor alerts.
  3. Microsoft Entra ID.
  4. A resource lock.
Answer: A. The pricing calculator estimates expected costs before resources are deployed. Monitor alerts track conditions and can notify operators; they do not estimate a design's cost. Entra ID handles identity. A lock protects a resource from certain changes, not future charges.
Question 6: shared responsibility

A company uses a SaaS application hosted by a cloud provider. Which responsibility remains with the customer?

  1. Maintain the provider's datacenter cooling systems.
  2. Manage user access and protect the company's data through appropriate configuration and use.
  3. Replace failed physical disks in the provider's storage cluster.
  4. Patch the provider's physical host operating system.
Answer: B. In SaaS, the provider manages much of the application infrastructure, but the customer still manages identities, data, access, and appropriate configuration. Datacenter facilities, physical disks, and provider hosts are provider responsibilities. SaaS reduces operational work; it does not eliminate the customer's security responsibilities.

What these questions cover

The set includes cloud service models, governance, monitoring, access control, cost estimation, and shared responsibility. Those ideas span the three current AZ-900 domains: Cloud concepts, Azure architecture and services, and Azure management and governance. Six questions are not a representative sample of every skill or the distribution on a candidate's exam.

Notice how the requirement controls the answer. If the question asks about an authorized operator deleting a resource, a lock is relevant. If it asks who can perform an action, RBAC is relevant. If it asks whether an Azure service has an incident, Service Health fits. A familiar Azure product may be technically useful yet still fail to answer the specific question.

Several options may be helpful in a real design. A production environment may use RBAC, Policy, locks, monitoring, and backups together. An exam item asks for the most direct tool for one stated goal. Choose that fit, then understand the other controls' boundaries.

A method for narrowing the options

Start by naming the action or outcome requested: estimate, prevent, authorize, monitor, migrate, host, or identify an outage. Then translate the requirement into a capability. For example, ‘who can do what at this scope’ points toward authorization and RBAC. ‘Stop accidental deletion’ points toward a lock. ‘Show likely charges before deployment’ points toward an estimate.

Eliminate choices that answer another question. A notification is not prevention. Metadata is not a permission. Monitoring is not governance. Authentication is not authorization. A service that can display cost after use may not be the right tool for estimating cost before deployment. Naming the verb often makes the distinction clear.

Check cloud responsibility questions by identifying which layer is described. In IaaS, customers manage more of the operating system than in PaaS or SaaS. Across service models, customers still manage identities, data, access, and configuration. Avoid answer choices that transfer every security responsibility to the provider simply because the application runs in cloud.

How to review a miss

If you missed an item, do not only record the right letter. Explain the distinction you overlooked. If you selected Advisor for a service incident, write that Advisor recommends improvements while Service Health addresses service issues and maintenance. If you selected Policy for a user's permission, write that Policy controls configuration while RBAC grants resource actions.

Then create a new scenario with different nouns. Instead of a production virtual machine, use a database or storage account. Instead of an operator deleting a resource, ask who can alter a network rule. The answer may change with the requirement. This checks whether you learned a service purpose or merely memorized an example.

Use the Microsoft Practice Assessment to identify further gaps and consult the official study guide for scope. Microsoft says its practice items differ from the secure exam and do not model the complete test length or complexity. Do not turn the percentage on this set into an expected AZ-900 scaled score.

Read the official outline alongside practice

The current outline is measured as of July 20, 2026. It includes public, private, and hybrid cloud; consumption and pricing; Azure geography and resource hierarchy; compute, networking, storage, identity and security; cost, governance, deployment, and monitoring. Return to the outline when an example makes you realize a task is unfamiliar.

The Microsoft exam sandbox can familiarize you with the general navigation and item interactions. It does not reveal which question types AZ-900 will use, and Microsoft does not publish an exact exam item mix. Learn the interface separately from the Azure content.

Practice the foundational distinctions until you can answer in new contexts. A service name is useful only if you understand its purpose. If you can state what need a feature addresses, what it does not do, and which nearby option solves a different problem, you are building the kind of knowledge the outline describes.

A final self-check is to explain the boundary between nearby services without relying on the answer choices. Describe RBAC as authorization over Azure resources, Entra ID as identity and authentication, Policy as configuration governance, and Service Health as information about service incidents and maintenance. Then vary the scenario: a user can sign in but cannot create a virtual machine; a resource has a prohibited configuration; or a service incident affects a region. Each clue points to a different problem layer. This short explanation exercise is more useful than memorizing which option letter was correct.

Common questions

Are these official AZ-900 questions?

No. They are original examples for learning and do not reproduce Microsoft's secure exam or Practice Assessment.

Can this set predict my AZ-900 score?

No. Six questions are too few to predict a score and are not scored using Microsoft's scaled system.

Are the correct answers always the only useful Azure tools?

No. Real designs may combine tools. Each item asks for the best fit for one stated requirement.

What score passes AZ-900?

Microsoft requires 700 or greater on its 1-to-1,000 scaled scoring system.