A governance review asks, for each hosting option in use, who is responsible for patching the guest operating system. Which statement is accurate?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct On App Service and Azure Functions Microsoft maintains the underlying platform, while on an Azure virtual machine the guest operating system remains the customer's responsibility

Correct. That boundary moves with the service type, and the guest operating system is the clearest example of where it moves.

Not correct Microsoft patches the guest operating system of every Azure virtual machine automatically, so nobody needs to plan for it

Wrong. Azure offers automatic guest patching as a feature you enable and then verify. Responsibility for the guest operating system still sits with the customer, whether or not they use the feature.

Not correct On App Service the customer patches the underlying instance by connecting to it over remote desktop or SSH

Wrong — you do not get that access, and that is the bargain rather than a limitation. Giving up the box is precisely what buys you a platform somebody else maintains.

Not correct Patching responsibility is identical across the service types because the hardware is Microsoft's either way

Wrong, and it is the misconception the shared responsibility model exists to correct. The physical datacentre is always Microsoft's; what sits above it changes hands depending on the service type.

Why

Draw the stack once and the answers fall out: physical hosts and datacentre are always the provider's; identities, data and access control are always the customer's; operating system, runtime and middleware move between them as you go from infrastructure to platform to software as a service. Choosing a hosting option is therefore also choosing how much of that middle you are volunteering to own.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.compute-and-networking

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services