40 questions · All three domains · 2026 objectives
Objectives verified against Microsoft Learn on 22 August 2026.
These questions reflect the difficulty and style of the real AZ-900 exam. Click an answer to reveal whether you got it right and why. Your score tracks as you go.
Questions marked [NEW 2026] cover objectives added in the 2026 updates. These will appear on your exam and are missing from older prep materials.
Score:0 / 0
—
Q1Cloud Concepts
A company runs all their servers in a local data centre. They buy new hardware every 3 years when capacity is needed. Which cost model does this describe?
CapEx (Capital Expenditure) involves large upfront purchases of physical assets that are depreciated over time. On-premises data centres are the classic CapEx model. Cloud computing is OpEx — you pay for what you consume, with no upfront hardware investment.
Q2Cloud Concepts
Under the Shared Responsibility Model, which item is ALWAYS the customer's responsibility regardless of whether they use IaaS, PaaS, or SaaS?
Customer data and user access management is always the customer's responsibility, no matter which service model they use. Microsoft manages everything else to varying degrees depending on IaaS/PaaS/SaaS. The customer always controls who can access their data and what data they store.
Q3Cloud Concepts
A company's e-commerce site handles 200 orders per day on most days but processes 2,000 orders per day during sale events. They want to avoid paying for unused capacity. Which cloud benefit best describes automatically adjusting resources to match this demand pattern?
Elasticity specifically describes automatic scaling both up and down in response to demand — expanding when load increases and contracting when it drops, so you never pay for idle capacity. Scalability is the ability to scale but doesn't imply automatic bidirectional adjustment. High Availability is about uptime, not resource scaling.
Q4Cloud Concepts
A business wants to run Azure virtual machines alongside their on-premises servers, with both environments connected and able to communicate. Which cloud deployment model should they use?
Hybrid cloud connects on-premises infrastructure with a public cloud provider, allowing both environments to communicate and share data. Multi-cloud uses two or more public cloud providers simultaneously. Private cloud is on-premises or dedicated infrastructure only.
Q5Cloud Concepts
Under the Shared Responsibility Model for PaaS, which tasks remain the customer's responsibility?
Managing application data and user access. In PaaS, Microsoft manages the OS, runtime, middleware, hardware, and virtualisation. The customer manages applications, data, and who can access them. Memory aid: in SaaS you manage data and access only; in PaaS you add application management; in IaaS you also manage the OS and runtime.
Q6Cloud ConceptsNEW 2026
A company's DR plan requires that no more than 4 hours of transaction data is lost in a catastrophic failure. Which metric describes this requirement?
RPO. Recovery Point Objective defines how much data can be lost — the maximum age of data that must be recoverable. In this case RPO = 4 hours. RTO defines how quickly systems must be restored (how much downtime is acceptable). Both are now formal AZ-900 2026 objectives.
Q7Azure Architecture & Services
A developer stops their Azure virtual machine by shutting it down from within the Windows guest operating system. What happens to billing?
Stopping a VM from the guest OS puts it into a Stopped state but it remains allocated — Azure still reserves compute resources for it and continues billing for compute. To stop compute billing, you must Deallocate the VM via the Azure Portal, CLI, or API. Storage costs (the OS disk) continue regardless.
Q8Azure Architecture & Services
A company needs to host a public-facing web application without managing the underlying operating system, runtime, or patching. The app needs auto-scaling and can be deployed from a GitHub repository. Which Azure service fits best?
Azure App Service is PaaS — Microsoft manages the OS, runtime, and middleware. It supports auto-scaling, multiple languages, and has native GitHub Actions integration for CI/CD deployment. VMs require OS management (IaaS). ACI runs individual containers. AKS is for Kubernetes orchestration at scale.
Q9Azure Architecture & Services
A company needs a private connection between their on-premises data centre and Azure that does NOT travel over the public internet, with guaranteed bandwidth and lower latency than a VPN. What should they use?
Azure ExpressRoute provides a private dedicated connection to Azure through a connectivity provider — it never touches the public internet, gives predictable latency, and offers bandwidth guarantees. VPN Gateway encrypts traffic but routes it over the public internet. Bastion provides browser-based RDP/SSH to VMs, not a data centre connection.
Q10Azure Architecture & Services
An organisation stores financial audit documents that must be retained for 7 years. The documents are accessed at most once per year during audits. Which Azure Blob Storage access tier minimises the monthly storage cost?
Archive tier has the lowest storage cost and is designed for data that is almost never accessed. Trade-offs: data must be 'rehydrated' (moved out of Archive) before it can be read, which takes hours, and a 180-day minimum storage period applies. For documents accessed once a year with no urgency requirement, Archive is the right economic choice.
Q11Azure Architecture & ServicesNEW 2026
[NEW 2026] An application running in Azure App Service needs to retrieve secrets from Azure Key Vault. The security team requires that no credentials, passwords, or keys appear in the application code or configuration files. What is the recommended approach?
Managed Identity lets Azure App Service authenticate to Key Vault using an automatically-managed Entra ID identity — no credentials to create, store, or rotate. The App Service receives a token from Azure AD automatically. This is the solution to the 'secret zero' problem: how do you store the first credential securely? With Managed Identity, there is no credential to store.
Q12Azure Architecture & ServicesNEW 2026
[NEW 2026] A team is choosing between ARM Templates and Bicep for their infrastructure deployments. Which statement accurately describes the relationship between the two?
Bicep compiles to ARM JSON and produces identical results. It does not replace ARM — it is a cleaner syntax that generates ARM Templates. Every ARM Template capability is available in Bicep. Both are declarative (describe desired state), idempotent (running twice produces the same result), and support version control. Microsoft considers Bicep the preferred approach for new projects.
Q13Azure Architecture & ServicesNEW 2026
[NEW 2026] A company processes millions of IoT sensor readings per second from factory equipment and streams them into a real-time analytics pipeline. Which Azure messaging service is designed for this scale of event ingestion?
Azure Event Hubs is designed for high-throughput event ingestion — millions of events per second from IoT devices, applications, or logs. It is partitioned for parallelism and supports long retention for replay. Service Bus is for reliable transactional messaging between services (lower volume). Event Grid routes events to handlers for reactive architectures. Notification Hubs is for mobile push notifications.
Q14Azure Architecture & Services
A company needs a private connection to Azure from their data centre that does not travel over the public internet and offers guaranteed bandwidth. What should they use?
Azure ExpressRoute. ExpressRoute is a private dedicated connection through a connectivity provider that never touches the public internet, with guaranteed bandwidth and lower latency. VPN Gateway encrypts traffic but sends it over the public internet. Bastion provides browser-based RDP/SSH access to VMs.
Q15Azure Architecture & ServicesNEW 2026
An application in Azure App Service needs to read secrets from Azure Key Vault without storing any credentials in code. What is the recommended approach?
Managed Identity. Managed Identity lets App Service authenticate to Key Vault using an auto-managed Entra ID identity — no credentials to create, store, or rotate. This solves the "secret zero" problem. System-Assigned Managed Identity is tied to one resource; User-Assigned can be shared across multiple resources.
Q16Azure Architecture & ServicesNEW 2026
A company needs to process e-commerce orders reliably, with guaranteed delivery, message ordering, and a dead-letter queue for failed messages. Which Azure messaging service should they use?
Azure Service Bus. Service Bus is the enterprise message broker designed for reliable transactional messaging: guaranteed delivery, FIFO ordering, duplicate detection, dead-letter queues, and transactions. Event Hubs is for high-throughput event streaming (IoT telemetry, logs). Event Grid routes events to handlers reactively. Notification Hubs sends mobile push notifications.
Q17Azure Architecture & ServicesNEW 2026
Which statement accurately describes the relationship between ARM Templates and Bicep?
Bicep compiles to ARM JSON. Bicep produces identical results to ARM Templates — it is a cleaner syntax that generates ARM JSON during deployment. Every ARM capability is available in Bicep. Both are declarative, idempotent, and version-control friendly. Microsoft considers Bicep the preferred approach for new projects.
Q18Azure Architecture & ServicesNEW 2026
A company's Global Administrator is attempting to manage Azure resources but is being denied access. What is the most likely reason?
Entra ID roles and Azure RBAC roles are separate systems. Entra ID roles (like Global Administrator) manage the directory: users, groups, apps. Azure RBAC roles manage resources: VMs, storage, subscriptions. A Global Administrator has zero Azure resource access by default and must be explicitly granted an Azure RBAC role.
Q19Management & Governance
A team leader needs to allow a developer to create and manage virtual machines in a resource group but must not allow them to grant access to others. Which built-in RBAC role is the minimum needed?
Contributor grants full resource management permissions (create, modify, delete) within the assigned scope but cannot manage role assignments (cannot grant access to others). Owner includes both resource management and access management. Reader is view-only. User Access Administrator manages RBAC only with no resource permissions.
Q20Management & Governance
A security team needs to ensure that no Azure resources are created outside of three approved regions (UK South, UK West, West Europe). Any deployment attempt outside these regions must be blocked immediately. Which Azure service enforces this?
Azure Policy with the Deny effect evaluates resource creation requests and blocks non-compliant ones before they succeed. The built-in 'Allowed locations' policy definition does exactly this. Resource Locks prevent deletion or modification of existing resources but do not block creation. Blueprints package governance controls together but use Policy for the actual enforcement.
Q21Management & GovernanceNEW 2026
[NEW 2026] A finance team wants to reduce Azure spending and is evaluating two options. Option A: commit to spending $8/hour on any compute, in any region, for 1 year. Option B: reserve a specific D4s_v3 VM in UK South for 1 year. The team needs flexibility to change VM sizes as workloads evolve. Which option should they choose?
Azure Savings Plans (Option A) commit to a fixed hourly spend rate that applies to any eligible compute regardless of VM size, series, or Azure region — exactly the flexibility the team needs as workloads evolve. Azure Reservations (Option B) lock in a specific VM SKU in a specific region, which offers less flexibility. Reservations can offer a slightly higher discount, but flexibility is the stated requirement here.
Q22Management & Governance
An operations team is responding to a major service degradation and needs to know: (1) whether the issue is specific to their resources or affecting all Azure customers globally, and (2) a personalised timeline of the incident for their subscriptions. Which Azure tools answer these two questions?
Azure Status (status.azure.com) is the public, global Azure service health page — it shows all Azure services in all regions and affects everyone. Azure Service Health is personalised — it shows incidents, planned maintenance, and health advisories specifically for the services and regions you are using. For an incident, check Status first to understand scope, then Service Health for your specific impact.
Q23Management & Governance
Which Azure tool should you use BEFORE a cloud migration to compare the total cost of running a workload on-premises vs on Azure?
Azure TCO Calculator. The Total Cost of Ownership Calculator is specifically designed to compare on-premises infrastructure cost vs Azure — it builds the business case for migration. Azure Pricing Calculator estimates what an Azure deployment would cost. Cost Management + Billing tracks actual spend after deployment. Advisor gives recommendations once you are on Azure.
Q24Management & Governance
An Azure Policy with which effect BLOCKS the creation of non-compliant resources before they are deployed?
Deny. The Deny effect evaluates resource creation requests and rejects those that don't comply with the policy before they succeed. Audit logs non-compliance without blocking. Append adds fields to the resource. DeployIfNotExists auto-deploys a companion resource when one is missing.
Q25Management & Governance
A Contributor on a resource group tries to delete a VM and is blocked. No error about permissions appears — just a refusal. What is the most likely cause?
A Resource Lock. Resource Locks override RBAC. Even an Owner cannot delete a locked resource — they must remove the lock first. CanNotDelete locks prevent deletion while allowing read and modify. ReadOnly locks prevent all changes. Contributor has full resource management including deletion when no lock is present.
Q26Management & GovernanceNEW 2026
A company wants to reduce Azure compute costs with flexibility to change VM sizes as workloads evolve over the next year. Which cost commitment tool is most appropriate?
Azure Savings Plans. Savings Plans commit to a fixed hourly spend ($/hour) that applies to any eligible compute regardless of VM size, series, or region — exactly the flexibility needed when workloads change. Azure Reservations lock in a specific VM SKU and region (less flexible, potentially higher discount). Spot VMs can be evicted and are unsuitable for production workloads.
Q27Management & Governance
A company needs to verify their environment's compliance with ISO 27001 and download Microsoft's actual ISO 27001 audit report. Which tools provide each of these?
Defender for Cloud and Service Trust Portal. Microsoft Defender for Cloud includes a Regulatory Compliance dashboard showing your posture against standards like ISO 27001. The Service Trust Portal is where Microsoft publishes the actual third-party audit reports and certifications for Azure — you log in to download them. The Microsoft Trust Center is the public overview page; the STP is where the reports live.
Q28Cloud Concepts
A dev team provisions a full test environment in Azure in 10 minutes; the same on-premises took 3 weeks for hardware procurement. This demonstrates:
Cloud agility means resources can be rapidly provisioned and de-provisioned on demand, eliminating hardware procurement cycles and enabling teams to experiment and deploy in minutes rather than weeks.
Q29Cloud Concepts
Which statement BEST describes the consumption-based cloud pricing model?
Consumption-based pricing means you are charged based on actual usage—no idle resource costs. When resources stop, charges stop. Contrasts with CapEx where you pay for capacity regardless of utilization.
Q30Cloud Concepts
Which statement BEST describes 'manageability of the cloud' as a benefit?
Manageability means you can manage your cloud environment through a web portal, CLI, APIs, or PowerShell—including monitoring health, autoscaling, and receiving alerts based on configured metrics.
Q31Cloud Concepts
Which cloud service type delivers a complete application managed entirely by the provider and accessed over the internet?
SaaS delivers fully managed applications where the provider handles everything—infrastructure, platform, application, and data. Users simply sign in and use the software via a browser or client.
Q32Cloud Concepts
In an IaaS deployment, which component is the CUSTOMER responsible for?
In IaaS the customer manages the guest OS, middleware, runtime, data, and applications. The provider manages physical hardware, network, and virtualization layer.
Q33Azure Architecture & Services
Which Azure AI service provides pre-built APIs for vision, speech, language, and decision-making without requiring machine learning expertise?
Azure AI Services (formerly Cognitive Services) provides pre-built AI models via REST APIs: Vision (OCR, image analysis), Speech (TTS, STT), Language (LUIS, text analytics), and Decision (Anomaly Detector, Content Moderator).
Q34Azure Architecture & Services
Which Azure built-in role allows full management of all Azure resources AND the ability to grant access to others?
Owner has full access to all Azure resources AND can assign roles to others. Contributor can manage resources but cannot grant access. Reader can only view. User Access Administrator can manage access but not resources.
Q35Azure Architecture & Services
Which security model principle requires verifying every access request explicitly, regardless of whether it originates inside or outside the corporate network?
Zero Trust assumes breach and verifies every access request explicitly—regardless of network location. It relies on strong identity, device compliance checks, least-privilege access, and continuous monitoring.
Q36Management & Governance
Which Azure technology enables infrastructure as code by using JSON files to declaratively define and consistently deploy Azure resources?
ARM Templates are JSON files that declaratively describe Azure infrastructure. They are idempotent (same template = same result), support parameterization for reuse, and integrate with CI/CD pipelines for automated deployments.
Q37Management & Governance
A global company needs to ensure ALL Azure resources across 200 subscriptions are tagged with a 'DataClassification' tag. What is the MOST efficient approach?
Assigning an Azure Policy at the root Management Group with a Deny effect requiring the DataClassification tag is the most efficient approach. It applies automatically to ALL 200 subscriptions and all future resources—no manual effort per subscription.
Q38Management & Governance
Which Azure Service Health component shows the health status of YOUR specific Azure resources and whether platform issues have affected them?
Resource Health shows the current and historical health of specific Azure resources (e.g., a VM or SQL DB), helping distinguish between platform-initiated issues (Azure side) and customer-initiated degradations (config changes, scaling events).
Q39Management & Governance
Which Azure program allows customers with existing Windows Server and SQL Server licenses with Software Assurance to bring those licenses to Azure and reduce costs?
Azure Hybrid Benefit applies on-premises Windows Server and SQL Server licenses with Software Assurance to Azure, reducing compute costs by up to 40% (Windows) or 85% (SQL Server with reservations combined).
Q40Management & Governance
Which Azure tool helps estimate total cost savings of migrating from on-premises to Azure, including hidden costs like power, cooling, and IT labor?
The TCO Calculator models the full cost of on-premises infrastructure (hardware, software, datacenter, IT labor, power, cooling) vs. Azure services, revealing potential savings including often-overlooked hidden costs.
548 questions with explanations, 607 flashcards and 6 PDF study guides. $30 once — no subscription.
508 more questions in the full bundle
Five practice modes — Random, Wrong Only, Never Seen, Weak Spots, Smart Mix — so you always drill exactly where you need to. Full explanation on every question. Weighted to the real domain proportions.
All 40 questions are written from scratch against the current AZ-900 exam objectives. They are not exam dumps — reproducing actual exam questions violates Microsoft's Terms of Service and undermines the value of the certification. These are original scenario-based questions designed to test the same concepts at the same difficulty level.
The real exam is 40–60 questions in 45–60 minutes with a passing score of 700/1000. Questions are scenario-based — not "define this term" but "given this situation, which Azure service or feature should you use?"
If you are consistently scoring above 80% on this set, you have a solid grasp of the concepts. Run similar sets across all domains before booking your exam date.