Microsoft Azure Fundamentals (AZ-900) Exam — Questions and Answers
Question 1: What does Azure Advisor provide?
- A billing forecast tool
- Personalized best-practice recommendations to optimize Azure resources (Correct answer)
- A ticketing system for Azure support cases
- A real-time threat intelligence feed
Correct answer: Personalized best-practice recommendations to optimize Azure resources
Azure Advisor analyzes your configurations and usage telemetry and offers personalized recommendations across reliability, security, performance, cost, and operational excellence.
Question 2: What is the main difference between scalability and elasticity?
- Scalability is the capacity to grow; elasticity is the automatic, dynamic adjustment to demand (Correct answer)
- Elasticity only applies to storage
- Scalability only reduces resources
- They are identical concepts
Correct answer: Scalability is the capacity to grow; elasticity is the automatic, dynamic adjustment to demand
Scalability is the ability to grow capacity, while elasticity adjusts resources automatically and dynamically.
Question 3: Azure Advisor provides recommendations across several categories. Which category helps reduce spending?
- Security
- Reliability
- Performance
- Cost (Correct answer)
Correct answer: Cost
Azure Advisor's Cost category suggests ways to optimize and reduce Azure spending.
Question 4: Which Azure AD edition feature provides self-service password reset for users?
- Self-Service Password Reset (SSPR) (Correct answer)
- Service principals
- Managed identities
- Azure Key Vault
Correct answer: Self-Service Password Reset (SSPR)
SSPR lets users reset their own passwords without contacting a help desk, reducing support overhead.
Question 5: Which Azure feature lets you define a budget and automatically receive email alerts when spending reaches a percentage of that budget?
- Azure Policy cost controls
- Azure Advisor cost recommendations
- Azure Pricing Calculator
- Azure Cost Management budgets (Correct answer)
Correct answer: Azure Cost Management budgets
Azure Cost Management budgets allow you to set a spending limit and configure alert thresholds (e.g., 80%, 100%) that trigger email notifications to stakeholders.
Question 6: What do the aspects of data replication, geo-distribution, and cloud-based backup services entail?
- a hybrid cloud deployment
- a cost reduction plan
- a disaster recovery plan (Correct answer)
- an elastic application configuration
Correct answer: a disaster recovery plan
Data replication, geo-distribution, and cloud-based backup services are all critical components of a robust disaster recovery plan. These strategies ensure that data and applications remain available and recoverable even in the event of a major outage, natural disaster, or cyberattack. By distributing data across multiple locations and maintaining backups, organizations can minimize downtime and data loss.
Question 7: What does an SLA of 99.9% uptime roughly translate to in allowable downtime per month?
- About 43 minutes (Correct answer)
- About 8 hours
- About 3 days
- Zero downtime
Correct answer: About 43 minutes
A 99.9% monthly SLA permits roughly 43 minutes of downtime.
Question 8: What does CapEx (capital expenditure) refer to in a cloud context?
- Upfront spending on physical infrastructure (Correct answer)
- Refunds for unused services
- Free trial credits
- Ongoing pay-as-you-go costs
Correct answer: Upfront spending on physical infrastructure
CapEx is upfront capital spending on physical assets like servers and datacenters.
Question 9: What service helps you securely connect to a VM over RDP/SSH without exposing a public IP address?
- Azure Firewall
- Azure Bastion (Correct answer)
- Azure DDoS Protection
- Azure Key Vault
Correct answer: Azure Bastion
Azure Bastion provides secure RDP and SSH connectivity to VMs directly through the Azure portal without public IPs.
Question 10: Which purchasing option offers up to a 72% discount in exchange for a one- or three-year commitment to Azure compute?
- Reserved Instances (Correct answer)
- Spot pricing
- Azure Hybrid Benefit
- Pay-as-you-go
Correct answer: Reserved Instances
Azure Reserved Instances provide large discounts for one- or three-year usage commitments.
Question 11: What defense strategy uses multiple layers of security controls throughout an environment?
- Perimeter-only security
- Single point defense
- Open access model
- Defense in depth (Correct answer)
Correct answer: Defense in depth
Defense in depth applies layered security controls so that if one layer fails, others still protect resources.
Question 12: Which Azure feature provides a unified view of alerts, health events, and diagnostics across your Azure resources?
- Azure Monitor (Correct answer)
- Azure Advisor
- Azure Security Center
- Azure Sentinel
Correct answer: Azure Monitor
Azure Monitor collects, analyzes, and acts on telemetry data from your cloud and on-premises environments, providing dashboards, alerts, and log analytics.
Question 13: An administrator needs to ensure that all newly created virtual machines in a specific subscription are of an allowed size (SKU) to control costs. Which Azure service can be used to enforce this rule?
- Azure Monitor
- Azure Role-Based Access Control (RBAC)
- Azure Policy (Correct answer)
- Microsoft Defender for Cloud
Correct answer: Azure Policy
Azure Policy is a service that allows you to create, assign, and manage policies to enforce organizational rules and standards for Azure resources. It can be used to restrict which VM SKUs can be deployed, ensuring compliance with cost management goals.
Question 14: In the shared responsibility model for cloud computing, which of the following is ALWAYS the customer's responsibility, regardless of the service model (IaaS, PaaS, or SaaS)?
- Patching the host operating system
- Network controls
- Information and data (Correct answer)
- Physical datacenter security
Correct answer: Information and data
Across all cloud service models (IaaS, PaaS, SaaS), the customer is always responsible for securing their own information and data, as well as managing user accounts and identities. [8, 10, 27] The cloud provider is responsible for the physical security of the datacenter, and responsibility for OS patching and network controls varies depending on the service model. [3, 10]
Question 15: What is a key advantage of cloud elasticity during a sudden traffic spike?
- It deletes excess data automatically
- It disables the application
- It permanently lowers your bill
- It automatically provisions extra resources to handle the load (Correct answer)
Correct answer: It automatically provisions extra resources to handle the load
Elasticity automatically adds resources to handle spikes, then releases them after.
Question 16: A company is planning to migrate its on-premises data center to Azure. They need a tool to estimate the potential cost savings by comparing their current on-premises infrastructure costs with the projected costs of running the same workloads in Azure. Which Azure tool is specifically designed for this purpose?
- Azure Advisor
- Azure Cost Management
- Azure Pricing Calculator
- Total Cost of Ownership (TCO) Calculator (Correct answer)
Correct answer: Total Cost of Ownership (TCO) Calculator
The Total Cost of Ownership (TCO) Calculator is designed to help you compare the costs of running your workloads on-premises versus in Azure to estimate potential savings. The Pricing Calculator is used for estimating the cost of specific Azure services you plan to use, while Azure Cost Management helps monitor and control spending, and Azure Advisor provides optimization recommendations.
Question 17: What is the Azure SLA concept that defines the minimum uptime percentage Microsoft commits to for a service?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Monthly uptime percentage guarantee expressed in the service agreement (Correct answer)
- Mean Time Between Failures (MTBF)
Correct answer: Monthly uptime percentage guarantee expressed in the service agreement
Azure SLAs define the minimum uptime and connectivity guarantees Microsoft commits to, expressed as a percentage (e.g., 99.9%, 99.95%, 99.99%) of monthly uptime.
Question 18: Which tool compares the cost of running workloads on-premises versus in Azure?
- Total Cost of Ownership (TCO) Calculator (Correct answer)
- Cost analysis
- Azure Advisor
- Azure Pricing Calculator
Correct answer: Total Cost of Ownership (TCO) Calculator
The TCO Calculator estimates savings from migrating on-premises workloads to Azure.
Question 19: Which Azure compute choice provides the greatest level of customer control over the environment?
- Azure Container Instances
- Azure Functions
- Azure App Service
- Azure Virtual Machines (Correct answer)
Correct answer: Azure Virtual Machines
Virtual Machines give the most control because the customer manages the entire OS and software stack.
Question 20: Which tool estimates the cost of Azure services before you deploy them?
- Azure Backup
- Azure Monitor
- Azure Sentinel
- Pricing Calculator (Correct answer)
Correct answer: Pricing Calculator
The Azure Pricing Calculator estimates costs of services before provisioning them.
Question 21: Which Azure networking service provides secure connectivity between Azure virtual networks in different regions using the Microsoft backbone?
- Azure Load Balancer
- Azure VNet Peering (Global VNet Peering) (Correct answer)
- Azure Private Endpoint
- Azure VPN Gateway
Correct answer: Azure VNet Peering (Global VNet Peering)
Global VNet Peering connects Azure virtual networks across different regions, allowing resources in different regions to communicate privately using Microsoft's backbone network.
Question 22: Which Azure feature provides centralized, secure storage for secrets, keys, and certificates?
- Azure Key Vault (Correct answer)
- Azure Advisor
- Azure Monitor
- Azure Blueprints
Correct answer: Azure Key Vault
Azure Key Vault securely stores and manages secrets, encryption keys, and certificates.
Question 23: Which of the following is an Azure service that gives consumers the ability to encrypt and monitor their network traffic?
- Azure Traffic Manager
- Azure Firewall (Correct answer)
- Azure Content Delivery Network
- Azure Load Balancer
Correct answer: Azure Firewall
Azure Firewall is a managed, cloud-based network security service that protects Azure Virtual Network resources. It provides threat protection, allows users to centrally create, enforce, and log application and network connectivity policies, and can encrypt and monitor network traffic to enhance security across your Azure environment.
Question 24: What does Single Sign-On (SSO) primarily provide to users?
- Access to multiple applications with one set of credentials (Correct answer)
- Automatic VM patching
- Encryption of data at rest
- Network traffic filtering
Correct answer: Access to multiple applications with one set of credentials
SSO lets users authenticate once and access multiple connected applications without signing in again.
Question 25: Which of the following is a primary benefit of the public cloud deployment model?
- Complete control over the physical hardware.
- Dedicated hardware for a single organization.
- No capital expenditure (CapEx) to get started. (Correct answer)
- Meeting specific, unique compliance and legal requirements.
Correct answer: No capital expenditure (CapEx) to get started.
The public cloud operates on a consumption-based or pay-as-you-go model, eliminating the need for upfront capital expenditure (CapEx) on physical hardware and infrastructure. [26, 30] Resources are owned and operated by a third-party cloud provider, and control, dedicated hardware, and meeting unique compliance needs are more characteristic of private or hybrid clouds. [15, 26]
Question 26: What does Azure Application Gateway provide that a basic load balancer does not?
- Layer 7 web traffic routing with a web application firewall (Correct answer)
- Free virtual machines
- Global DNS resolution
- Physical datacenter hosting
Correct answer: Layer 7 web traffic routing with a web application firewall
Application Gateway is a layer 7 load balancer that supports URL-based routing and includes an optional web application firewall.
Question 27: Which of the following is the primary purpose of Azure Role-Based Access Control (RBAC)?
- To manage who has access to Azure resources, what they can do with them, and what areas they can access. (Correct answer)
- To enforce organizational standards and assess compliance for resources.
- To encrypt secrets, keys, and certificates used by applications.
- To filter network traffic to and from Azure resources in a virtual network.
Correct answer: To manage who has access to Azure resources, what they can do with them, and what areas they can access.
Azure RBAC is an authorization system used to manage access to Azure resources. It allows you to grant specific permissions to users, groups, and services at a defined scope, ensuring they have only the access needed to perform their jobs.
Question 28: What is required to access data stored in the Archive access tier?
- Rehydration to an online tier (Correct answer)
- A premium subscription
- Nothing, it is instantly available
- A virtual machine
Correct answer: Rehydration to an online tier
Archive tier data must be rehydrated to the Hot or Cool tier before it can be read.
Question 29: Which benefit of cloud computing reduces the need for an organization to maintain its own security staff for physical infrastructure?
- Vertical scaling
- Tagging
- Agility
- Shared responsibility with the provider (Correct answer)
Correct answer: Shared responsibility with the provider
Under the shared responsibility model, the provider secures the physical infrastructure.
Question 30: In a SaaS model, who is responsible for managing the application software?
- The customer
- The end user's IT team
- The cloud provider (Correct answer)
- An external auditor
Correct answer: The cloud provider
In SaaS, the cloud provider manages the application and underlying stack.
Question 31: Choose the response that fully completes the statement. <br> <br> It's known as ____________ to expand the computing power of an app by adding RAM or CPUs to a virtual machine.
- horizontal scaling
- high availability
- vertical scaling (Correct answer)
- disaster recovery
Correct answer: vertical scaling
Vertical scaling, also known as "scaling up," involves increasing the capacity of an existing resource, such as a virtual machine. This is achieved by adding more RAM, CPU cores, or storage to that single instance. While it enhances the power of an individual machine, it has limits based on the maximum capacity of a single server.
Question 32: What is the main function of Azure Blueprints?
- Cache web content globally
- Render virtual machine graphics
- Send email notifications
- Deploy a repeatable set of governed resources and policies (Correct answer)
Correct answer: Deploy a repeatable set of governed resources and policies
Azure Blueprints package resources, policies, and role assignments into repeatable deployments.
Question 33: Which Azure CLI command format is used to create a resource group in the East US region?
- az group create --name MyRG --location eastus (Correct answer)
- New-AzResourceGroup -Name MyRG -Location eastus
- az resource-group add --name MyRG --region eastus
- azure group new --name MyRG --region eastus
Correct answer: az group create --name MyRG --location eastus
The Azure CLI uses the 'az group create' command with --name and --location parameters to create a new resource group.
Question 34: What type of authentication uses a fingerprint or facial recognition instead of a password?
- Certificate authentication
- Token-based authentication
- Shared key authentication
- Biometric authentication (Correct answer)
Correct answer: Biometric authentication
Biometric authentication, such as Windows Hello, verifies identity using physical characteristics like fingerprints or face.
Question 35: Which Azure concept refers to physically separate datacenters within a single Azure region, each with independent power, cooling, and networking?
- Azure Availability Zones (Correct answer)
- Azure Paired Regions
- Azure Edge Zones
- Azure Regions
Correct answer: Azure Availability Zones
Availability Zones are unique physical locations within an Azure region. Each zone is made up of one or more datacenters equipped with independent infrastructure, protecting applications and data from datacenter-level failures.
Question 36: What Azure feature allows you to estimate the cost of Azure services before deploying them?
- Azure Cost Management
- Azure Pricing Calculator (Correct answer)
- Azure Advisor
- Azure Monitor
Correct answer: Azure Pricing Calculator
The Azure Pricing Calculator is a web-based tool that lets you configure and estimate the monthly costs of Azure products before you deploy them.
Question 37: Which statement about Azure resource tags is true?
- Tags are automatically inherited by all child resources
- Tags encrypt the resource
- Each resource can have only one tag
- Tags are not inherited from resource groups by default (Correct answer)
Correct answer: Tags are not inherited from resource groups by default
Tags applied to a resource group are not automatically inherited by resources within it.
Question 38: Which shared responsibility item is ALWAYS the customer's responsibility regardless of service model?
- Hypervisor maintenance
- Data and information classification (Correct answer)
- Physical datacenter security
- Network cabling
Correct answer: Data and information classification
The customer always retains responsibility for their data and its classification.
Question 39: Which service model is best suited for developers who want to deploy code without managing servers or OS?
- PaaS (Correct answer)
- IaaS
- Colocation
- On-premises
Correct answer: PaaS
PaaS provides a managed platform so developers focus on code, not infrastructure.
Question 40: Which type of resource lock prevents deletion of a resource but still allows modification?
- Modify
- ReadOnly
- Delete
- CanNotDelete (Correct answer)
Correct answer: CanNotDelete
A CanNotDelete lock allows reading and modifying a resource but blocks its deletion.
Microsoft Azure Fundamentals (AZ-900) Exam
The AZ-900 exam validates foundational knowledge of cloud services and how those services are provided with Microsoft Azure.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds