Microsoft Azure Fundamentals (AZ-900) Practice Exam Questions and Answers – Part 14/15

Practice for the Microsoft Azure Fundamentals (AZ-900) exam with 14 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: True or false: Azure peering can connect two networks even though they belong to different subscriptions or customer acc. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Azure Fundamentals (AZ-900) practice test →

What you will practice

  • True or false: Azure peering can connect two networks even though they belong to different subscriptions or c…
  • Which of the following statements about Azure Management Groups is true?
  • Which of the following is an example of a PaaS offering from Azure?
  • What is a fault domain?
  • There is a well-defined division of responsibilities when it comes to applications and data in the cloud. The…
  • What is the primary purpose of Azure Data Box?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. True or false: Azure peering can connect two networks even though they belong to different subscriptions or customer accounts.

Answer: B. TRUE

Virtual network peering seamlessly connects networks across different subscriptions or Microsoft Entra tenants. For the exam, remember that peering uses the Microsoft backbone network rather than the public internet.

Q2. Which of the following statements about Azure Management Groups is true?

Answer: B. Management Groups can be used to apply policies and access controls across multiple subscriptions within the same tenant.

Management groups manage policy and role-based access control across multiple subscriptions within a single tenant. A subscription can only belong to one management group, making the simultaneous membership distractor incorrect.

Q3. Which of the following is an example of a PaaS offering from Azure?

Answer: B. Azure App Service

Azure App Service is a Platform as a Service offering that handles infrastructure management, allowing developers to deploy web apps directly. Virtual machines are Infrastructure as a Service, requiring you to manage the operating system.

Q4. What is a fault domain?

Answer: C. A physical grouping of servers within an Azure data center.

A fault domain represents a logical group of underlying hardware that share a power source and network switch. For the exam, associate update domains with planned maintenance and fault domains with hardware failures.

Q5. There is a well-defined division of responsibilities when it comes to applications and data in the cloud. The cloud vendor is typically responsible for the physical and network security of the cloud. Who is typically responsible for the se…

Answer: B. The customer, such as you

The customer is always responsible for securing and protecting their own data in the cloud. Remember the shared responsibility model: the provider secures the infrastructure, but you always manage your data and access.

Q6. What is the primary purpose of Azure Data Box?

Answer: B. To transfer large amounts of data to and from Azure

Azure Data Box is a physical device used to securely transfer massive amounts of data to and from Azure. Remember it as the offline migration tool when network bandwidth is limited or unavailable.

Q7. Many years ago, your company licensed some software that requires access to the Windows Registry to run. There is currently no option to run the app without the ability to write to the Registry. Which of the following is the only option fo…

Answer: C. IaaS

Infrastructure as a Service provides full operating system access, allowing you to modify the Windows Registry. Platform and Serverless abstract the operating system, preventing the deep system access required here.

Q8. Which Azure connectivity option can provide connectivity from your on-premises corporate network into Azure over a private line, not travelling over the public Internet?

Answer: A. Azure ExpressRoute

Azure ExpressRoute creates a private, dedicated connection between your local network and Azure. If the question specifies avoiding the public Internet, always select ExpressRoute over virtual private network options.

Q9. Fill in the blank: _________ is a cloud-based file sharing service that allows you to access your files from anywhere using standard SMB or NFS protocols.

Answer: D. Azure File Storage

Azure File Storage provides fully managed file shares in the cloud accessible via standard SMB or NFS protocols. For the exam, associate file shares with lift-and-shift migrations and replacing traditional on-premises file servers.

Q10. Which cloud pricing model is often used for applications with predictable workloads and long-term requirements?

Answer: D. Reserved instances

Reserved instances provide significant discounts by committing to a one- or three-year term for predictable workloads. Pay-as-you-go remains flexible for variable workloads but costs more long-term than reserved capacity.

Q11. A large financial institution with strict compliance requirements and a need to maintain control over sensitive data would be best suited for which cloud model?

Answer: C. Private Cloud

A private cloud is dedicated entirely to one organization, offering maximum control and security for strict compliance. While a hybrid cloud offers flexibility, private cloud specifically addresses the need for absolute data isolation.

Q12. What does redundancy mean in the context of Azure?

Answer: C. Having multiple copies of a resource to ensure availability.

Redundancy simply means maintaining multiple copies of a resource to ensure continuous availability if one component fails. While disaster recovery involves broader failover strategies, redundancy focuses on system reliability through replication.

Q13. What is the principle of least privilege in the context of Azure RBAC?

Answer: D. Granting users the minimum amount of access necessary to perform their job duties.

The principle of least privilege means granting users only the minimum access required to complete their tasks. Assigning broad roles like Owner violates this security baseline by creating unnecessary exposure and risk.

Q14. What is the primary purpose of single sign-on (SSO)?

Answer: D. To allow users to log in to multiple applications with a single set of credentials.

Single sign-on allows users to authenticate once and access multiple applications using a single set of credentials. This streamlines user access and reduces password fatigue, while multi-factor authentication handles extra security layers.

More Microsoft Azure Fundamentals (AZ-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top