AZ-900 Practice Test PDF (Free Printable 2026 October)
Free AZ practice test with questions and answer explanations. π’ Prepare for the 2026 October exam with instant scoring.
The Microsoft Azure Fundamentals certification is one of the most accessible entry points into cloud computing, and passing the AZ-900 exam is a concrete way to prove that you understand the core concepts employers care about. This page gives you a free, printable az 900 practice test PDF you can download and study anywhere β at your desk, on the train, or away from a screen entirely. The PDF covers all three exam domains: cloud concepts, Azure architecture and services, and Azure management and governance, with question difficulty calibrated to match the real exam.
Many candidates underestimate the AZ-900 and then find themselves surprised by the breadth of topics tested. The exam expects you to understand not just what Azure services exist, but how they relate to each other, which pricing model applies in which scenario, and why governance tools matter in an enterprise context. Working through a full practice test PDF before your exam date gives you a complete picture of where your knowledge is strong and where you need more review. Combine this az900 practice test PDF with the free interactive az 900 practice tests on this site for a well-rounded study plan.
Did You Know? Passing the AZ-900 exam on your first attempt saves both time and money. Start with diagnostic practice tests to identify weak areas.
Cloud Concepts Domain
The cloud concepts domain accounts for roughly 25β30% of the AZ-900 exam and tests your understanding of what cloud computing is, why organizations adopt it, and how different service and deployment models work. At the core of this domain is the distinction between the three service models: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). With IaaS, the cloud provider supplies the virtualized infrastructure β compute, storage, and networking β while you manage the operating system, middleware, and applications. Azure Virtual Machines is the canonical IaaS example. PaaS removes OS management from your plate, giving you a managed platform on which to deploy and run applications; Azure App Service and Azure SQL Database are PaaS offerings. SaaS delivers complete, ready-to-use applications over the internet β Microsoft 365 is the most familiar example in the Azure ecosystem.
The shared responsibility model defines which security and operational tasks belong to Microsoft and which belong to the customer, and this boundary shifts depending on the service model. In IaaS, customers are responsible for patching the guest OS and securing their applications. In PaaS, Microsoft handles the underlying infrastructure and platform but customers remain responsible for their data and user access. In SaaS, nearly all responsibility shifts to the provider. Understanding this model is critical because exam questions frequently present scenarios asking who is responsible for a specific security control in a given deployment type.
Consumption-based pricing (pay-as-you-go) is a defining characteristic of public cloud, contrasted with traditional capital expenditure (CapEx) models where organizations purchase and depreciate hardware upfront. Cloud computing shifts spending to operational expenditure (OpEx), which is more predictable, scalable, and aligned with actual usage. Other key cloud benefits tested on the AZ-900 include high availability (the ability to remain operational despite component failures), scalability (adding resources to handle increased demand), elasticity (automatically adjusting resources up and down as demand changes), reliability (resilient, distributed infrastructure), predictability (consistent performance and cost), security (built-in controls and compliance frameworks), and manageability (tools to deploy, monitor, and control resources at scale).
Azure Architecture and Services Domain
Regions, Availability Zones, and the Azure Global Infrastructure
The Azure Architecture and Services domain is the largest on the exam, weighted at approximately 35β40%. It covers Microsoft's global infrastructure and the breadth of Azure services across compute, networking, storage, and identity. Azure is built on a worldwide network of physical datacenters organized into regions β geographic areas each containing one or more datacenters connected by low-latency networks. As of 2026, Azure operates over 60 regions globally, giving organizations the ability to deploy workloads close to their users. Within a region, Availability Zones are physically separate datacenters with independent power, cooling, and networking. Deploying across multiple Availability Zones provides high availability by ensuring that a failure in one zone does not affect services running in another.
At the management level, Azure resources are organized into a hierarchy: individual resources sit inside resource groups, which exist within subscriptions, which can be grouped under management groups at the top level. This hierarchy maps directly to governance and billing: subscriptions define billing boundaries and resource quotas, while management groups allow organizations to apply policies and access controls across multiple subscriptions simultaneously. Azure Resource Manager (ARM) is the control plane that underlies all resource deployment and management in Azure β whether you use the Azure portal, Azure CLI, PowerShell, or infrastructure-as-code tools like Bicep or Terraform, all requests flow through ARM.
Core Azure Services: Compute, Networking, Storage, and Identity
The compute category includes Azure Virtual Machines (IaaS virtual servers), Azure App Service (PaaS web hosting), Azure Container Instances (serverless containers), Azure Kubernetes Service (managed Kubernetes), and Azure Functions (serverless event-driven compute). Each service suits different workload types, and exam questions frequently test your ability to match a business requirement to the correct compute option. Networking services include Azure Virtual Network (VNet) for isolated private networking, Azure VPN Gateway and Azure ExpressRoute for hybrid connectivity to on-premises environments, Azure Load Balancer and Azure Application Gateway for traffic distribution, and Azure DNS for domain name resolution.
Storage services include Azure Blob Storage (unstructured object storage ideal for images, videos, and backups), Azure Disk Storage (managed block storage for VMs), Azure Files (managed file shares accessible via SMB and NFS protocols), and Azure Queue Storage (message queuing for decoupled application architectures). Azure Active Directory (now Microsoft Entra ID) is the cloud identity and access management service that handles authentication and authorization across Azure and Microsoft 365. Azure AD supports multi-factor authentication (MFA), single sign-on (SSO), and Conditional Access policies that enforce security controls based on user, device, location, and risk signals.
Azure Management and Governance Domain
Cost Management, Azure Policy, and RBAC
The management and governance domain covers approximately 25β30% of the exam and focuses on the tools Azure provides to control costs, enforce compliance, manage access, and monitor the health of cloud resources. Azure Cost Management and Billing gives organizations visibility into their spending, the ability to set budgets and alerts, and tools to analyze cost trends over time. Understanding how to use Cost Management to identify waste β such as idle VMs or over-provisioned storage β is a practical skill tested in scenario questions. Azure Advisor is a free personalized recommendation service that analyzes your Azure deployment and suggests improvements across reliability, security, performance, operational excellence, and cost optimization.
Azure Policy is the governance tool used to define and enforce organizational standards across Azure resources. Policies can audit existing resources, deny the creation of non-compliant resources, or automatically remediate configurations that drift from the defined standard. Policy initiatives (groups of related policies) simplify compliance at scale. Azure Policy integrates with regulatory compliance frameworks, making it possible to map your Azure environment's compliance posture to standards like ISO 27001, NIST, and PCI-DSS from within the Azure portal.
Role-Based Access Control (RBAC) is the authorization system used to manage who has access to which Azure resources and what they can do with them. RBAC assigns roles β built-in or custom β to users, groups, or service principals at a specific scope: a resource, resource group, subscription, or management group. The principle of least privilege is fundamental to good RBAC design, meaning each identity receives only the permissions it needs to perform its function and no more. Resource locks are a complementary governance feature that prevent accidental deletion or modification of critical resources, independent of RBAC permissions. Two lock types exist: ReadOnly (no changes allowed) and Delete (no deletion allowed).
Azure Monitor, Service Trust Portal, and Exam Readiness
Azure Monitor is the unified observability platform for Azure, collecting metrics, logs, and traces from Azure resources and applications. Within Azure Monitor, Log Analytics provides a query environment for exploring log data, while Application Insights delivers application performance monitoring (APM) for custom applications. Alerts can be configured to notify teams or trigger automated actions when metrics cross defined thresholds. The Service Trust Portal is Microsoft's transparency hub, hosting audit reports, compliance documentation, and data protection information for Azure, Microsoft 365, and Dynamics 365. Understanding the purpose of the Service Trust Portal β and how it differs from operational tools like Azure Advisor or Azure Monitor β is a common exam question. Together, these governance and management tools form the framework that allows enterprises to operate Azure environments at scale while maintaining security, compliance, and cost discipline.
- βDefine IaaS, PaaS, and SaaS with at least one Azure service example for each model
- βUnderstand the shared responsibility model and how customer vs. provider responsibilities shift across service types
- βExplain CapEx vs. OpEx and how consumption-based pricing applies to cloud adoption decisions
- βKnow the seven cloud benefit concepts: high availability, scalability, elasticity, reliability, predictability, security, and manageability
- βUnderstand Azure's global infrastructure: regions, region pairs, availability zones, and sovereign regions
- βMap the Azure resource hierarchy: resources β resource groups β subscriptions β management groups
- βIdentify the correct Azure compute service for a given scenario (VM vs. App Service vs. Functions vs. AKS)
- βKnow Azure storage types: Blob, Disk, Files, and Queue Storage and their primary use cases
- βUnderstand Azure RBAC: role assignment, scope hierarchy, and the principle of least privilege
- βReview Azure Policy, resource locks, Cost Management, Azure Advisor, Azure Monitor, and Service Trust Portal purposes
Download the PDF, work through every question in a single timed sitting, and note every answer you are uncertain about β those are your study priorities. Then return to the full library of interactive az 900 practice tests to drill the weak areas before exam day. The combination of offline PDF review and immediate online feedback is the fastest path to a confident, passing score on the AZ-900.
How to Use This AZ-900 Practice Test PDF to Pass First Try
The strongest study results come from treating this az900 practice test as a diagnostic rather than a memorization sheet. Download the printable AZ-900 exam questions PDF and complete every item in one 45-minute timed sitting that mirrors the real exam, resisting the urge to check answers mid-run. When you finish, score yourself and separate the questions you answered confidently from the ones you guessed β those guesses, not your correct answers, are your real study list for the week ahead.
Next, map each missed question back to its exam domain so you know whether your gap is in cloud concepts, Azure architecture and services, or management and governance. If most misses cluster in one domain, spend your next sessions there before broadening out. Alternate between the offline PDF and the interactive az 900 practice tests on this site, because the printable format builds recall under time pressure while the online version gives instant explanations for every answer choice.
Repeat the full set until you are consistently scoring at least 85 percent, comfortably above the 700-of-1000 (roughly 70 percent) passing bar. Candidates who complete multiple timed runs of free AZ-900 practice questions and answers, review every explanation, and close their weakest domain first are the ones who walk into the exam and pass on their first attempt.
βοΈ What is the difference between IaaS, PaaS, and SaaS on AZ-900?
IaaS gives you virtualized compute, storage, and networking while you manage the OS and apps (Azure Virtual Machines). PaaS removes OS management and provides a managed platform (Azure App Service, Azure SQL Database). SaaS delivers a ready-to-use application such as Microsoft 365. Matching a scenario to the right model is a core AZ-900 practice test skill.
START AZ-900 PRACTICE TESTπ Who is responsible for what in the shared responsibility model?
The shared responsibility model splits security and operational duties between Microsoft and the customer based on the service model. In IaaS you patch the guest OS; in PaaS Microsoft runs the platform but you own your data and access; in SaaS Microsoft handles almost everything. AZ-900 exam questions and answers frequently test who secures a given control.
START AZ-900 PRACTICE TESTπ° What is the difference between CapEx and OpEx in the cloud?
CapEx (capital expenditure) means buying and depreciating hardware upfront, while OpEx (operational expenditure) means paying for resources as you consume them. Azure uses consumption-based, pay-as-you-go pricing, shifting IT spend to OpEx. This cost model is predictable, scalable, and a recurring topic in az900 practice test questions.
START AZ-900 PRACTICE TESTπ What is the difference between an Azure region and an Availability Zone?
A region is a geographic area containing one or more datacenters connected by a low-latency network, and you pick one when deploying a resource. Availability Zones are physically separate datacenters inside a single region, each with independent power, cooling, and networking. Deploying across zones protects against datacenter-level failures.
START AZ-900 PRACTICE TESTποΈ What is the Azure resource hierarchy?
Azure organizes resources into a four-level hierarchy: individual resources live in resource groups, which sit inside subscriptions, which can be grouped under management groups. Subscriptions set billing boundaries and quotas, while management groups apply policy and access across many subscriptions at once. Azure Resource Manager (ARM) is the control plane for all of it.
START AZ-900 PRACTICE TESTπ₯οΈ Which Azure compute service fits which workload?
Azure Virtual Machines give full IaaS control, Azure App Service hosts web apps as PaaS, Azure Container Instances run serverless containers, Azure Kubernetes Service manages container orchestration, and Azure Functions run event-driven serverless code. AZ-900 exam questions often describe a requirement and ask you to pick the correct compute option.
START AZ-900 PRACTICE TESTπΎ What are the four main Azure storage types?
Azure Blob Storage holds unstructured objects like images, video, and backups; Azure Disk Storage provides managed block storage for VMs; Azure Files offers managed SMB/NFS file shares; and Azure Queue Storage buffers messages between decoupled application components. Knowing each typeβs use case is tested across free az 900 practice questions.
START AZ-900 PRACTICE TESTπ‘οΈ What does Azure Policy do and how is it different from RBAC?
Azure Policy enforces organizational standards by auditing, denying, or remediating resource configurations that drift from a defined rule. Role-Based Access Control (RBAC) instead governs who can access a resource and what they can do, following least privilege. Policy controls resource compliance; RBAC controls identity permissions β a distinction AZ-900 loves to test.
START AZ-900 PRACTICE TESTπ What is Microsoft Entra ID (Azure Active Directory)?
Microsoft Entra ID, formerly Azure Active Directory, is Azureβs cloud identity and access management service that authenticates and authorizes users across Azure and Microsoft 365. It supports multi-factor authentication, single sign-on, and Conditional Access policies that enforce controls based on user, device, location, and risk signals.
START AZ-900 PRACTICE TESTπ How many questions are on the AZ-900 and what is the passing score?
The AZ-900 exam has roughly 40 to 60 questions and a 45-minute time limit, mixing multiple-choice, drag-and-drop, and scenario items. The passing score is 700 out of 1000, about 70 percent. Microsoft does not publish an exact question-to-score formula, so scaled scoring means every question area matters.
START AZ-900 PRACTICE TESTSample AZ-900 Practice Questions
Try these questions from our free AZ-900 practice tests. The correct answer and an explanation follow each question.
A company wants to host a web application in Azure. They require full control over the underlying operating system and want to install custom software. Which Azure compute service is the most appropriate choice?
- A. Azure App Service
- B. Azure Functions
- C. Azure Virtual Machines
- D. Azure Container Instances
Answer: C. Azure Virtual Machines
Azure Virtual Machines (VMs) provide Infrastructure-as-a-Service (IaaS), giving users complete control over the operating system and the ability to install any custom software, which meets the company's requirements. Azure App Service is a PaaS offering that abstracts the OS, Azure Functions is for serverless event-driven code, and Container Instances are for running containers without managing servers.
What is the main purpose of Azure Queue Storage?
- A. Storing large files
- B. Hosting relational databases
- C. Storing and retrieving messages between application components
- D. Serving static websites
Answer: C. Storing and retrieving messages between application components
Azure Queue Storage stores large numbers of messages for asynchronous communication between components.
Which Azure identity service is used to manage user identities and provide authentication for Azure resources and Microsoft 365?
- A. Microsoft Entra ID (Azure Active Directory)
- B. Azure Key Vault
- C. Azure Security Center
- D. Azure Policy
Answer: A. Microsoft Entra ID (Azure Active Directory)
Microsoft Entra ID (formerly Azure Active Directory) is Azure's cloud-based identity and access management service, providing authentication and authorization for Azure and Microsoft 365.
Which Azure service uses declarative JSON or Bicep templates to deploy and configure Azure resources consistently?
- A. Azure Blueprints
- B. Azure ARM Templates
- C. Azure Policy
- D. Azure Advisor
Answer: B. Azure ARM Templates
Azure Resource Manager (ARM) templates are JSON files that define the infrastructure and configuration for your Azure solution using infrastructure-as-code.
Official Resources
- Microsoft Learn β Azure Fundamentals (AZ-900) certification is the official exam page with the current skills outline, exam length, and scheduling details.
- Microsoft Learn β free Azure Fundamentals learning path provides Microsoftβs own no-cost modules covering cloud concepts and core Azure services tested on AZ-900.
Join the Discussion
Connect with other students preparing for this exam. Share tips, ask questions, and get advice from people who have been there.
View discussion (9 replies)