Microsoft AZ-900: Applying Azure Fundamentals to Scenarios

AZ-900 scenario questions are fundamentally classification problems. The exam describes a business requirement and asks which cloud concept, Azure service category, security control, governance tool or monitoring service best matches it. The current AZ-900 outline remains foundational, so choose the simplest matching concept instead of designing a complex architecture.

Scenario one: demand changes sharply every month

The relevant cloud benefits are elasticity and scalability. The organization wants resources to increase with demand and potentially decrease afterward rather than purchasing fixed peak capacity in advance.

Consumption-based pricing can reinforce the economic benefit when resources are governed appropriately.

Scenario two: a company wants control of guest operating systems

IaaS is the most likely service-model answer because the customer manages the operating system and software on a virtual machine. PaaS would remove more infrastructure responsibility, while SaaS delivers a finished application.

The shared-responsibility model is the real concept being tested.

Scenario three: an application must survive a datacenter-level failure

Availability zones are the relevant architectural concept where supported because zones are isolated locations within a region. Simply placing resources in one resource group or subscription does not create resilience.

The scenario is about failure domain, not management hierarchy.

Scenario four: two Azure virtual networks need private connectivity

VNet peering is a foundational answer when the requirement is connecting Azure virtual networks directly. VPN Gateway is more relevant when encrypted tunnel connectivity is required across networks or locations, and ExpressRoute is dedicated private connectivity from on-premises through a provider.

The words “two VNets” are the key clue.

Scenario five: a user should view resources but not modify them

Azure RBAC with an appropriate read-only role fits authorization. MFA strengthens authentication but does not define which resource actions are allowed. Azure Policy governs resource compliance rather than individual user permission.

A strong answer separates identity proof from authorization.

Scenario six: every storage account must follow a required setting

Azure Policy is designed to audit or enforce resource standards across a scope. A resource lock prevents certain changes or deletion but does not evaluate a broad configuration standard.

Tags can organize resources but are not equivalent to compliance enforcement.

Scenario seven: management wants to estimate a new environment before deployment

Azure Pricing Calculator is the right foundational tool for prospective cost estimation. Cost Management analyzes and manages actual/forecast spend after resources exist.

An Azure cost mindset starts by matching the cost tool to the timing and business question.

Scenario eight: engineers need to know whether Azure has a service incident

Azure Service Health is designed to communicate relevant Azure service issues and maintenance. Azure Monitor observes resource/application telemetry, while Advisor provides recommendations.

Do not choose the broadest monitoring name when the question is specifically about Azure platform health.

Scenario nine: developers need application performance telemetry

Application Insights inside Azure Monitor is a strong match for application-level observability. Log Analytics is a broader log-query workspace capability, and Advisor is not an application-performance tracing service.

The Application Insights example helps distinguish workload telemetry from platform advisories.

Scenario ten: hybrid resources outside Azure need centralized management

Azure Arc extends Azure management/governance concepts to supported resources outside native Azure environments. The scenario should not push you toward migration automatically if the requirement is centralized management rather than moving the workload.

Scenario eleven: the organization wants to prevent accidental deletion of a critical resource. A delete lock is the direct governance feature. RBAC determines who can act and Policy evaluates standards, but a lock is specifically designed to block certain management operations even from authorized users until the lock is removed.

Scenario twelve: leadership wants every resource to include an Environment tag. Azure Policy can audit or enforce the tagging standard at scale. Manually adding tags fixes only current resources; the policy creates ongoing governance.

Scenario thirteen: a partner needs access to selected applications using their existing external identity. Microsoft Entra external identities are relevant. Creating a shared internal account would weaken accountability, while RBAC alone does not establish the external identity relationship.

Scenario fourteen: administrators want centralized Azure-style management for on-premises servers that cannot yet migrate. Azure Arc is the foundational answer. Azure Migrate is more appropriate when the objective is assessing/moving workloads into Azure.

Scenario fifteen: a company must move tens of terabytes where the WAN connection is too slow for practical transfer. Azure Data Box is designed for large offline data movement. AzCopy is an online transfer tool and File Sync is a synchronization/hybrid-files concept.

Scenario sixteen: developers need a hosted web application without managing the underlying VM OS. A platform/web-app service fits better than ordinary IaaS VMs. The scenario tests the desired management abstraction rather than which compute service is “more powerful.”

Scenario seventeen: a workload needs event-driven code that runs only when triggered. Azure Functions/serverless is the foundational pattern. A VM can run the code too, but it creates unnecessary infrastructure management when the question emphasizes event-driven serverless execution.

Scenario eighteen: a company needs a dedicated private connection from its datacenter to Azure. ExpressRoute is the relevant service concept. VPN Gateway uses encrypted tunnels, typically over internet connectivity, while peering connects Azure VNets.

Scenario nineteen: the organization needs to know whether a deployed Azure resource violates an allowed-region standard. Azure Policy fits. Microsoft Purview addresses data governance/compliance contexts; a resource lock does not evaluate allowed regions.

Scenario twenty: management wants recommendations about improving cost, security, reliability and performance of Azure resources. Azure Advisor is the foundational service. Service Health reports Azure service issues; Monitor collects operational telemetry.

Scenario twenty-one: operators need to query logs collected from several Azure resources. Log Analytics inside Azure Monitor is a strong match. Application Insights focuses on application observability, while Service Health reports platform incidents.

Scenario twenty-two: a company wants to minimize passwords for users. Passwordless authentication methods in Entra are relevant, potentially combined with other identity controls. SSO reduces repeated sign-in experiences but does not necessarily eliminate the original credential method by itself.

Scenario twenty-three: a user should manage virtual machines but not assign Azure roles. RBAC should grant only the necessary resource actions. Least privilege is the principle; selecting a role with broader identity-management permissions would exceed the requirement.

Scenario twenty-four: an organization needs better understanding and governance of enterprise data. Microsoft Purview is the relevant family. Azure Policy governs Azure resource configurations, while Defender for Cloud focuses on security posture/protection.

Scenario twenty-five: a storage workload is rarely accessed and cost is more important than immediate frequent retrieval. A cooler or archive-oriented storage tier may fit. The question is about access pattern and economics, not choosing a different cloud provider or region automatically.

Scenario twenty-six: an organization needs a Windows desktop/application experience delivered centrally from Azure. Azure Virtual Desktop is the recognizable service. One ordinary VM with RDP is not equivalent to a managed virtual desktop service.

Scenario twenty-seven: a company wants infrastructure deployments to be repeatable and reviewable. Infrastructure as code with ARM templates is the conceptual answer. The portal can deploy resources, but manual clicks are not the strongest fit when repeatability is explicitly required.

Scenario twenty-eight: users report a web application is slow but Azure platform health is normal. Application Insights/Azure Monitor telemetry is more relevant than Service Health. The evidence needed is application behavior, not Microsoft service status.

Scenario twenty-nine: a company wants management boundaries above multiple subscriptions. Management groups provide the hierarchy for organizing subscriptions and applying governance at scale. Resource groups are below subscriptions and cannot contain subscriptions.

Scenario thirty: a team wants the simplest exam-level way to decide between two plausible answers. Identify whether the question is asking about business benefit, location, compute, network, storage, identity, governance, deployment or monitoring. The category usually eliminates unrelated Azure services immediately.

Scenario thirty-one: a company needs a managed domain for legacy applications that expect traditional domain-join and LDAP/Kerberos-style capabilities without deploying domain controllers. Microsoft Entra Domain Services is the relevant conceptual service, while Entra ID remains the broader cloud identity platform.

Scenario thirty-two: developers want to inspect a resource through a command line available from the browser without installing local tooling. Azure Cloud Shell is the straightforward fundamentals answer because it provides shell access with Azure tools from the portal/web experience.

Scenario thirty-three: an organization wants to standardize deployments using declarative files checked into source control. ARM templates and Resource Manager support this infrastructure-as-code requirement better than relying only on manual portal creation.

Scenario thirty-four: a company needs to know which Azure resources are generating the greatest current spend. Cost Management is more appropriate than Pricing Calculator, which estimates proposed resources before or outside actual consumption.

Scenario thirty-five: a team wants a graphical utility to browse and transfer files in Azure Storage from a workstation. Azure Storage Explorer is the likely tool. AzCopy is command-line oriented, while File Sync addresses hybrid file synchronization.

Scenario thirty-six: a company needs to synchronize on-premises Windows file-server content with Azure Files. Azure File Sync matches the hybrid file-synchronization requirement better than Data Box or ordinary one-time upload tools.

Scenario thirty-seven: a security team wants security-posture recommendations for cloud resources. Microsoft Defender for Cloud is relevant. Azure Advisor can make broader recommendations, but the scenario’s security-posture wording points specifically to the security service.

Scenario thirty-eight: an organization wants a resource to remain undeletable during a critical period even by users who normally have management permissions. A resource lock addresses accidental or unauthorized management changes at that resource scope.

Scenario thirty-nine: a company needs recommendations for underutilized resources and possible reliability improvements. Azure Advisor is appropriate because the need is optimization guidance. Cost Management can show spend and Azure Monitor can show telemetry, but neither is primarily a recommendation engine across those categories.

Scenario forty: a company wants to know why a recent application request failed even though the Azure service itself is healthy. Application Insights or Azure Monitor telemetry is the better evidence source than Service Health. The scenario distinguishes application behavior from provider platform status.

The current AZ-900 scope includes Arc specifically, making it an important example of how Azure management reaches beyond resources hosted directly in Azure.