Microsoft AZ-900 Online Practice
Questions and Exam Preparation
AZ-900 Exam Details
Exam Code
:AZ-900
Exam Name
:Microsoft Azure Fundamentals
Certification
:Microsoft Certifications
Vendor
:Microsoft
Total Questions
:472 Q&As
Last Updated
:May 25, 2026
Microsoft AZ-900 Online Questions &
Answers
Question 301:
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Explanation:
Box 1: Yes
Azure security center can monitor azure resources and on-premises resources.
Azure Security Center is a unified infrastructure security management system that strengthens the security posture of your data centers, and provides advanced threat protection across your hybrid workloads in the cloud - whether they're in Azure or not - as well as on premises.
Box 2: No
Only two features: Continuous assessment and security recommendations, and Azure secure score, are free.
Box 3: Yes
The advanced monitoring capabilities in Security Center also let you track and manage compliance and governance over time. The overall compliance provides you with a measure of how much your subscriptions are compliant with policies associated with your workload.
Which Azure service should you use to store certificates?
A. Azure Security Center B. an Azure Storage account C. Azure Key Vault D. Azure Information Protection
C. Azure Key Vault
Azure Key Vault is a secure store for storage various types of sensitive information including passwords and certificates.
Azure Key Vault can be used to Securely store and tightly control access to tokens, passwords, certificates, API keys, and other secrets.
Secrets and keys are safeguarded by Azure, using industry-standard algorithms, key lengths, and hardware security modules (HSMs). The HSMs used are Federal Information Processing Standards (FIPS) 140-2 Level 2 validated.
Access to a key vault requires proper authentication and authorization before a caller (user or application) can get access. Authentication establishes the identity of the caller, while authorization determines the operations that they are allowed to perform.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Explanation:
Box 1: No
A use who is assigned the owner role can transfer ownership of an azure subscription. Yes
You need to be an administrator of the billing account that has the subscription to be able to transfer the subscription. This could be a Billing Administrator or Global Administrator. A subscription owner can manage all resources and permissions within the subscription but cannot transfer ownership of the subscription.
Box 2: Yes
You can convert a free trial subscription to Pay-As-You-Go. This is common practice for people who wish to continue using the Azure services when the free trial period expires.
Box 3: Yes
You can remove the spending limit, but you can’t increase or decrease it.
The spending limit in Azure prevents spending over your credit amount. All new customers who sign up for an Azure free account or subscription types that include credits over multiple months have the spending limit turned on by default. The spending limit is equal to the amount of credit and it can’t be changed. For example, if you signed up for Azure free account, your spending limit is $200 and you can't change it to $500. However, you can remove the spending limit. So, you either have no limit, or you
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription named Subscription1. You sign in to the Azure portal and create a resource group named RG1.
From Azure documentation, you have the following command that creates a virtual machine named VM1.
az vm create --resource-group RG1 --name VM1 -- image UbuntuLTS --generate-ssh-keys
You need to create VM1 in Subscription1 by using the command.
Solution: From the Azure portal, launch Azure Cloud Shell and select PowerShell. Run the command in Cloud Shell.
Does this meet the goal?
A. Yes B. No
A. Yes
The Azure CLI command `az vm create` can be run from Azure Cloud Shell, which supports both Bash and PowerShell environments.
Cloud Shell is already authenticated with your Azure subscription (Subscription1 in this case), so the command will create the VM in Subscription1 without additional login steps.
Selecting PowerShell in Cloud Shell is valid because the Azure CLI is available in both Bash and PowerShell in Cloud Shell.
Therefore, running the command from Azure Cloud Shell in PowerShell meets the goal of creating VM1 in Subscription1.
"Azure Cloud Shell is an interactive, authenticated, browser-accessible shell for managing Azure resources. It provides Bash and PowerShell environments with the Azure CLI preinstalled."-Microsoft Learn:
"Create a new virtual machine. This command can be run from any environment with the Azure CLI installed, including Cloud Shell. If executed in Cloud Shell, the command uses the currently signed-in subscription by default."
You plan to deploy 20 virtual machines to azure environment. To ensure that a virtual machine named VM1 cannot connect to the other virtual machines, VM1 must:
Select the answer that correctly completes the sentence.
Explanation:
Question 306:
You need to configure an Azure solution that meets the following requirements:
1. Secures websites from attacks
2. Generates reports that contain details of attempted attacks What should you include in the solution?
A. Azure Firewall B. a network security group (NSG) C. Azure Information Protection D. DDoS protection
D. DDoS protection
DDoS is a type of attack that tries to exhaust application resources. The goal is to affect the application's availability and its ability to handle legitimate requests. DDoS attacks can be targeted at any endpoint that is publicly reachable through the internet.
Azure has two DDoS service offerings that provide protection from network attacks: DDoS Protection Basic and DDoS Protection Standard.
DDoS Basic protection is integrated into the Azure platform by default and at no extra cost.
You have the option of paying for DDoS Standard. It has several advantages over the basic service, including logging, alerting, and telemetry. DDoS Standard can generate reports that contain details of attempted attacks as required in this question.
In the software as a service (SaaS) cloud service, which responsibility is shared between Microsoft and the customer?
A. identity and directory infrastructure management B. application management C. information and data management D. operating system updates
A. identity and directory infrastructure management
Shared responsibility in the cloud
Division of responsibility
In an on-premises datacenter, you own the whole stack. As you move to the cloud some responsibilities transfer to Microsoft. The following diagram illustrates the areas of responsibility between you and Microsoft, according to the type of deployment of your stack.
Note: As you consider and evaluate public cloud services, it's critical to understand the shared responsibility model and which security tasks the cloud provider handles and which tasks you handle. The workload responsibilities vary depending on whether the workload is hosted on Software as a Service (SaaS), Platform as a Service (PaaS), Infrastructure as a Service (IaaS), or in an on-premises datacenter.
Match the Azure compute services to the appropriate descriptions.
To answer, drag the appropriate compute service from the column on the left to its description on the right Each service may be used once, more than once, or not at all.
NOTE: Each correct match is worth one point.
Select and Place:
Explanation:
Question 310:
You have an Azure subscription.
You need to use Azure Cloud Shell to run a deployment script.
What should you use to access Cloud Shell?
A. Azure Resource Manager (ARM) B. Microsoft Visual Studio C. a Windows command prompt D. a web browser
D. a web browser
Shell access from virtually anywhere
Connect to Azure using an authenticated, browser-based shell experience that's hosted in the cloud and accessible from virtually anywhere. Azure Cloud Shell is assigned per unique user account and automatically authenticated with each session. Get a modern command-line experience from multiple access points, including the Azure portal, shell.azure.com, Azure mobile app, Azure docs (e.g. Azure CLI, Azure PowerShell), and VS Code Azure Account extension.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Microsoft exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your AZ-900 exam preparations
and Microsoft certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.