CertKeen
Microsoft AzureBeta · expanding bank

Azure Fundamentals (AZ-900) Practice Exam

Practice questions for the Microsoft Azure Fundamentals (AZ-900) certification: cloud concepts including the shared responsibility model, IaaS/PaaS/SaaS, deployment models, and the consumption-based model; Azure architecture including regions, availability zones, resource hierarchy, compute, networking, storage, migration, and identity with Microsoft Entra ID, RBAC, Zero Trust, and Defender for Cloud; and management and governance including cost tools, tags, Azure Policy, resource locks, Microsoft Purview, management tools, Azure Arc, infrastructure as code, Advisor, Service Health, and Azure Monitor. Every question includes a written explanation.

100 questions · 12 free preview

$19 · lifetime access
Try free sample

Studying more than one? All Microsoft Azure exams for $29 · every exam for $79

Free sample questions

  1. Sample · question 1 · Containers vs virtual machines

    Emberlight Games notices that its containers start in seconds while its virtual machines take minutes. What is the main reason containers are more lightweight than VMs?

    • A.Containers always run on dedicated physical servers
    • B.Containers cannot store any data
    • C.Containers are billed only once per year
    • D.Containers share the host operating system kernel instead of each running a full guest OScorrect

    Why: A VM virtualizes hardware and runs a complete guest operating system, while containers virtualize at the OS level and share the host's kernel, so they are smaller and start faster. Containers do not require dedicated physical servers. They can use attached storage, and billing frequency has nothing to do with startup speed.

    Open this question on its own page →
  2. Sample · question 2 · Point-to-site VPN for individual devices

    A consultant at Fairwind Architects works from home and needs her laptop to connect securely to an Azure virtual network. The company does not need to connect an entire office network. Which connection type fits best?

    • A.ExpressRoute
    • B.Point-to-site VPNcorrect
    • C.Virtual network peering
    • D.Site-to-site VPN

    Why: A point-to-site VPN through Azure VPN Gateway connects an individual client device to an Azure virtual network. Site-to-site VPN connects an entire on-premises network, and ExpressRoute is a private circuit for organizations. Virtual network peering connects Azure virtual networks to each other, not client devices.

    Open this question on its own page →
  3. Sample · question 3 · Azure File Sync caching on-premises

    Hollowbrook Legal wants to centralize its file shares in Azure Files while keeping frequently used files cached on a Windows Server in its branch office for fast local access. Which service provides this?

    • A.Azure Migrate
    • B.Azure Data Box
    • C.Azure File Synccorrect
    • D.Azure Queue Storage

    Why: Azure File Sync synchronizes Azure file shares with Windows Servers, which can act as local caches for fast access to frequently used files. Data Box is for one-time offline bulk transfers. Queue Storage stores messages, and Azure Migrate assesses and migrates workloads rather than keeping files in sync.

    Open this question on its own page →
  4. Sample · question 4 · Microsoft Entra Connect identity sync

    Saddleback Tools has user accounts in on-premises Active Directory Domain Services and wants those identities synchronized to Microsoft Entra ID so users can sign in to cloud apps with the same accounts. What should it use?

    • A.Microsoft Entra Connectcorrect
    • B.Azure Policy
    • C.Azure DNS
    • D.Azure Arc

    Why: Microsoft Entra Connect (including its cloud sync option) synchronizes identities from on-premises Active Directory to Microsoft Entra ID, giving users a common identity for on-premises and cloud resources. Azure Arc extends Azure management to non-Azure infrastructure. Azure Policy enforces resource rules, and Azure DNS hosts DNS zones.

    Open this question on its own page →
  5. Sample · question 5 · External partner access with B2B

    Goldcrest Events wants employees of a partner agency to access a shared project app by using the partner's own work accounts, rather than creating new accounts and passwords for them. Which capability supports this?

    • A.Azure Virtual Desktop
    • B.Resource locks
    • C.Azure Reservations
    • D.Microsoft Entra External ID B2B collaborationcorrect

    Why: B2B collaboration in Microsoft Entra External ID lets organizations invite external users who sign in with their own existing identities. Azure Virtual Desktop delivers desktops but does not solve identity federation. Resource locks protect resources, and Reservations are a pricing option.

    Open this question on its own page →
  6. Sample · question 6 · Defense in depth perimeter layer

    In the defense-in-depth model, which layer is primarily concerned with protecting against distributed denial-of-service (DDoS) attacks and filtering traffic at the network edge?

    • A.Perimetercorrect
    • B.Data
    • C.Application
    • D.Physical security

    Why: The perimeter layer uses protections such as DDoS mitigation and perimeter firewalls to filter large-scale attacks before they reach internal resources. The data layer protects stored information, the application layer focuses on secure code, and physical security covers access to buildings and hardware.

    Open this question on its own page →
  7. Sample · question 7 · AzCopy command-line data transfer

    An engineer at Peregrine Maps wants a command-line utility to copy blobs and files to and from Azure Storage accounts in scripts. Which tool is designed for this?

    • A.Azure Service Health
    • B.Microsoft Purview
    • C.AzCopycorrect
    • D.Azure Advisor

    Why: AzCopy is a command-line utility for copying data to, from, and between Azure Storage accounts, and it works well in scripts. Advisor provides recommendations, Service Health reports platform status, and Purview governs data; none of them copy storage data.

    Open this question on its own page →
  8. Sample · question 8 · Azure Table Storage NoSQL data

    Marblehead Sensors needs to store large amounts of structured, non-relational data as key and attribute entities without a fixed schema, at low cost. Which Azure Storage service fits best?

    • A.Azure Queue Storage
    • B.Azure Table Storagecorrect
    • C.Azure Disk Storage
    • D.Azure Files

    Why: Azure Table Storage stores structured NoSQL data as entities with keys and properties, without enforcing a schema. Azure Files provides file shares, Queue Storage holds messages between components, and Disk Storage provides block storage for VMs.

    Open this question on its own page →
  9. Sample · question 9 · Azure operated by 21Vianet

    Which statement about the Azure sovereign cloud in China is correct?

    • A.It is available only to Microsoft employees
    • B.It is operated by Microsoft's US government division
    • C.It is physically separated from global Azure and operated by 21Vianetcorrect
    • D.It is an availability zone of an Asian public region

    Why: Azure in China is a sovereign cloud that is physically separated from the global Azure cloud and operated by 21Vianet rather than directly by Microsoft. It is not part of Azure Government, not an availability zone of another region, and it is offered to customers rather than being limited to Microsoft staff.

    Open this question on its own page →
  10. Sample · question 10 · Azure mobile app for monitoring

    An operations lead at Cedar Hollow Farms wants to check the health of Azure resources, view alerts, and run quick fixes from her phone while away from her desk. Which tool fits best?

    • A.Bicep
    • B.Azure Data Box
    • C.The TCO calculator
    • D.The Azure mobile appcorrect

    Why: The Azure mobile app lets users monitor resources, view alerts, and perform common management tasks from a phone, including access to Cloud Shell. The TCO calculator estimates cost savings, Bicep is an infrastructure-as-code language, and Data Box is a physical data transfer device.

    Open this question on its own page →
  11. Sample · question 11 · Root management group

    Which statement about the root management group in Azure is correct?

    • A.The root management group contains only resource groups
    • B.Each Microsoft Entra tenant has a single top-level root management groupcorrect
    • C.Each subscription has its own root management group
    • D.The root management group can be deleted when it is empty

    Why: Every Microsoft Entra tenant has one top-level root management group, and all other management groups and subscriptions fold up into it, so policies or role assignments there can apply across the directory. It is not per subscription, it cannot be deleted, and it contains management groups and subscriptions rather than resource groups directly.

    Open this question on its own page →
  12. Sample · question 12 · Azure Disk Storage for VM disks

    When Nettlefield Clinic creates an Azure virtual machine, which Azure Storage service provides the managed disks used for its operating system and data volumes?

    • A.Azure Disk Storagecorrect
    • B.Azure Queue Storage
    • C.Azure Table Storage
    • D.Azure Files

    Why: Azure Disk Storage provides block-level managed disks that attach to Azure VMs for operating system and data volumes. Queue Storage and Table Storage hold messages and NoSQL entities. Azure Files offers shared file systems accessed over SMB or NFS rather than VM block disks.

    Open this question on its own page →

Like the sample?

Other practice exams