Practice for the Microsoft Azure Fundamentals (AZ-900) exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is a primary benefit of choosing a consumption-based (pay-per-use) pricing model instead of a time-based (hourly or. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Azure Fundamentals (AZ-900) practice test →
What you will practice
- What is a primary benefit of choosing a consumption-based (pay-per-use) pricing model instead of a time-based…
- Which statement correctly describes the difference between the public cloud and the private cloud deployment…
- You discover an Azure service labeled 'private preview'. Which of the following statements about services in…
- In the Azure shared responsibility model, who is responsible for securing the access keys (account keys) for…
- Which Azure service provides a centralized security dashboard that consolidates cloud security posture, recom…
- Which of the following is an essential design principle for achieving high availability in a cloud computing…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. What is a primary benefit of choosing a consumption-based (pay-per-use) pricing model instead of a time-based (hourly or always-on) pricing model for cloud services?
Answer: B. Significant cost savings when the resources aren't needed for constant use.
A consumption-based model eliminates ongoing charges during idle periods, providing significant cost savings for workloads with unpredictable usage. However, time-based reserved instances often remain cheaper for continuous, steady-state workloads running constantly throughout the year.
Q2. Which statement correctly describes the difference between the public cloud and the private cloud deployment models?
Answer: C. A public cloud is available to the general public or a large industry group and is owned by a cloud service provider, while a private cloud is owned and operated by a single organization for exclusive use.
A public cloud delivers computing services over the internet for shared use, whereas a private cloud dedicates infrastructure exclusively to one organization. This exclusivity provides greater internal control for security compliance compared to multi-tenant public environments.
Q3. You discover an Azure service labeled 'private preview'. Which of the following statements about services in private preview is true?
Answer: B. Access to services in private preview mode is limited and usually requires approval from Microsoft or an invitation.
Private previews restrict access to invited testers who agree to specific terms before evaluating unreleased features. Services in preview lack formal guarantees and should never be deployed within critical production environments due to potential instability.
Q4. In the Azure shared responsibility model, who is responsible for securing the access keys (account keys) for your Azure Storage account?
Answer: B. I am responsible for securing the access keys
The customer is always responsible for managing and securing their own service credentials, including storage account access keys. Microsoft secures the underlying physical infrastructure, but you must rotate and protect your keys.
Q5. Which Azure service provides a centralized security dashboard that consolidates cloud security posture, recommendations, and threat protection for Azure resources?
Answer: C. Microsoft Defender for Cloud
Microsoft Defender for Cloud is the unified security management system that provides a centralized dashboard for security posture and threat protection. Azure Monitor tracks operational health, while Key Vault secures secrets rather than scanning for threats.
Q6. Which of the following is an essential design principle for achieving high availability in a cloud computing environment?
Answer: C. The system must be designed for resilience, with no single points of failure.
Designing for resilience and eliminating single points of failure is the fundamental principle of high availability. Option A is too specific, while demanding one hundred percent uptime is impossible due to planned maintenance.
Q7. Can you grant someone access to your Azure subscription without sharing your username and password (for example, by assigning them a role through Microsoft Entra ID and role-based access control)?
Answer: A. YES
You can grant access by assigning users or groups to specific roles using role-based access control. This principle ensures users receive only the permissions necessary for their tasks without sharing credentials.
Q8. Your organization has an Azure Policy that restricts which virtual machine SKUs/sizes can be deployed. Which of the following actions would allow you to create a VM that the policy currently blocks? Correct answer
Answer: A. The only way is to remove the policy, create the resource and add the policy back
Azure Policy evaluates resources during creation, meaning even an Owner cannot bypass a deny assignment. To deploy the blocked virtual machine, you must remove or exclude the policy. Owners do not override policy enforcement, making that choice a trap.
Q9. Which of the following Azure actions is most likely to produce the most immediate reduction in your Azure costs? Correct answer
Answer: A. Using Azure Reserved Instances for most of your virtual machines
Using Azure Reserved Instances provides a significant discount compared to pay-as-you-go pricing, generating the largest immediate cost reduction for steady virtual machine workloads. Auto-shutdown helps dev environments but saves less than reservations.
Q10. In Azure high-availability design, what is the primary purpose of Availability Zones?
Answer: D. They allow manual selection of data centers for virtual machine placement to achieve superior availability compared to other options.
Availability Zones are distinct physical datacenters within a single Azure region, protecting applications from localized facility failures. Resource groups act as logical containers for organizing resources, while regions define entirely separate geographic areas.
Q11. You subscribe to Azure DDoS Protection at the IP protection tier (DDoS Protection Standard), which provides advanced protection for public IPs. Which type of DDoS attack is NOT mitigated by this service?
Answer: C. Application (L7) level attacks
Azure DDoS Protection at the network layer mitigates layer three and four volumetric attacks. It does not stop application layer attacks, which require a Web Application Firewall to inspect HTTP traffic and block exploits like SQL injection.
Q12. Which Azure service provides a fully managed, hosted relational SQL database (Platform as a Service)?
Answer: A. Azure SQL Database
Azure SQL Database is a fully managed Platform as a Service relational database. SQL Server in a virtual machine is Infrastructure as a Service, while Cosmos DB and Table Storage are non relational database services.
Q13. Under typical/default Azure service limits, what is the maximum number of virtual machines that can be included in a single Azure Virtual Machine Scale Set (VMSS)?
Answer: D. 1000
A virtual machine scale set can support up to one thousand instances when using Azure Marketplace images. If an exam asks about scale set limits, remember that custom images reduce this maximum limit to six hundred instances.
Q14. Your company stores data in Azure Blob Storage and wants to ensure that this data is automatically encrypted when saved and decrypted only when accessed by authorized users. Which Azure feature provides this capability by default?
Answer: A. Azure Storage Service Encryption (SSE)
Azure Storage Service Encryption automatically encrypts data at rest by default. While Key Vault secures secrets and Disk Encryption handles virtual machine disks, standard blob storage handles its own built in encryption transparently.
Q15. Which Azure website tool lets you estimate future costs by adding Azure products and services to a shopping cart and calculating the pricing?
Answer: A. Azure Pricing Calculator
The Azure Pricing Calculator allows you to estimate future costs by configuring products in a virtual shopping cart. Remember that Azure Advisor recommends cost optimizations for existing resources, rather than forecasting new bills.
Q16. Which of the following is something that Azure AI Services can currently do?
Answer: C. All of these! Azure can do it all!
Azure AI Services provide capabilities like realistic speech, audio transcription, translation, and image recognition. Since the platform supports all these individual features, the comprehensive option is the correct choice.
More Microsoft Azure Fundamentals (AZ-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.