Azure Fundamentals AZ-900 Sign in Try 10 free questions

Azure compliance, the Trust Portal and data residency

The trust-and-compliance names that quietly earn points in the Management & Governance domain — where you fetch Microsoft's audit paperwork, how you score your own compliance, and where your data physically lives. AZ-900, 2026 edition.

Here are 7 typical compliance-and-trust questions in the exam's own style — free, each answer explained, no sign-up.

Straight to the 7 free questions ↓

Trust and compliance is where the Management & Governance domain gets its easy points — if you know a handful of names cold. This is pure vocabulary, not architecture: the exam wants to know whether you can tell Microsoft’s published paperwork apart from your own compliance posture, and whether you understand where data physically lives. The diagram above lays the topic out as three blocks — read it left to right and the whole subject falls into place.

Three places, three jobs

The single most tested distinction here is who is being assessed — Microsoft, or you.

  • Service Trust Portal — Microsoft’s download library. It publishes the platform’s own audit reports and certifications: SOC 1/2/3, ISO 27001, GDPR-related documentation, and more. When someone needs the actual PDF — a SOC report, an ISO certificate — this is where you fetch it. It is Microsoft’s paperwork about Microsoft’s platform.
  • Microsoft Purview Compliance Manager — your assessment tool. It measures how well your environment meets a standard, gives you a compliance score, and lists improvement actions to raise it. The word “score” is the tell, the same way “Secure Score” flags Microsoft Defender for Cloud.
  • Trust Center — the front door. It explains Microsoft’s privacy, security, and compliance commitments and links to the Microsoft Privacy Statement, the authoritative document on what personal data Microsoft collects and how it is used.

Keep the verbs straight: you download from the Service Trust Portal, you assess and score in Compliance Manager, you read about commitments in the Trust Center.

Breadth is a selling point

Expect a question that simply checks you know Azure’s compliance coverage is huge. Microsoft maintains one of the broadest compliance portfolios in the industry — global standards (ISO 27001, SOC), regional and national ones, and industry-specific ones such as HIPAA for healthcare. You inherit those certifications by building on the platform; you remain responsible for configuring your workloads correctly on top. That shared split is the mental model to carry in.

Residency vs sovereignty — don’t blur them

This pair trips people up, so learn both:

  • Data residency = where data is stored at rest. In Azure you control it by choosing the region — regions are grouped into geographies drawn along country and compliance boundaries — so a customer who must keep data inside one country simply deploys into a region in that geography.
  • Data sovereignty = whose law applies to that data, i.e. the legal jurisdiction of the country where it resides. It is a legal concept, not just a location.

Residency is where the bytes sit; sovereignty is whose law reaches them. The exam loves pairing the two to see if you can separate them.

Azure Policy closes the loop

Finally, compliance is not only paperwork — it is enforced continuously. Azure Policy ships built-in regulatory compliance initiatives (grouped policy sets mapped to standards) that continuously audit your resources against a standard and flag or block anything non-compliant, no manual audit required. Certifications prove the platform is compliant; Azure Policy keeps your resources compliant.

The real AZ-900 mixes multiple-choice, true/false, and drag-and-drop formats; the seven questions below are standard multiple-choice, and every explanation carries a “why not the others” so the three wrong options teach you as much as the right one.

A three-block map of Azure trust and compliance. On the left, the Service Trust Portal is drawn as a document library holding downloadable audit reports and certifications — SOC, ISO 27001, GDPR — the paperwork Microsoft publishes about its own platform. In the centre, Microsoft Purview Compliance Manager is drawn as an assessment dashboard that produces a compliance score and a list of improvement actions, the tool you use to assess and manage your own organisation's compliance. On the right, Data residency and sovereignty is drawn as a globe split into Azure geographies and regions, showing where customer data is physically stored and which country's laws govern it. A caption underneath separates the two ideas: residency is where the bytes sit, sovereignty is whose law applies. A note reminds the reader that Azure Policy continuously audits resources against regulatory standards to keep them compliant.

7 free AZ-900 practice questions

Answers and explanations — no email wall
AZ-900 Question 1 of 7

An internal auditor asks you to download the most recent SOC 2 Type 2 attestation and the current ISO 27001 certificate for the Azure services your company runs on, so they can attach the PDFs to an audit file. From which Microsoft resource do you retrieve these documents directly?

Answer: A — The Service Trust Portal.

The Service Trust Portal is Microsoft's download library for the platform's own audit reports and certifications — SOC 1/2/3, ISO 27001, and similar attestation documents are published there as downloadable files. Why not the others: Compliance Manager assesses your organisation's compliance and produces a score, but it is not where you fetch Microsoft's raw attestation PDFs. The Azure Policy compliance dashboard reports whether your resources satisfy your policies — your state, not Microsoft's platform certifications. The Microsoft Privacy Statement is a document about how Microsoft handles personal data, not a certificate repository. Pro tip: if the ask is 'download the actual report/certificate,' the answer is the Service Trust Portal.

AZ-900 Question 2 of 7

Your compliance officer wants a running, quantified view of how well your Azure environment meets a standard such as ISO 27001 — a single compliance score plus a prioritised list of improvement actions to raise it. Which tool is built for this?

Answer: A — Microsoft Purview Compliance Manager.

Compliance Manager, part of Microsoft Purview, assesses your environment against regulations and standards and expresses the result as a compliance score, backed by improvement actions you can work through to raise it. Why not the others: the Service Trust Portal hands you Microsoft's audit documents to read — it does not measure or score your organisation. Azure Monitor collects metrics and logs; it has no notion of a compliance standard. Azure Advisor gives reliability, security, cost, and performance recommendations for your resources, not a scored assessment against a named regulation. Pro tip: 'compliance score' points to Compliance Manager, the way 'Secure Score' points to Microsoft Defender for Cloud.

AZ-900 Question 3 of 7

A healthcare startup wants to confirm before migrating that Microsoft Azure already holds the certifications and offerings their industry and regions demand — things like HIPAA, ISO 27001, SOC, GDPR alignment, and country-specific standards. How is Azure's compliance coverage best described?

Answer: A — Azure maintains one of the broadest compliance portfolios in the industry, spanning global, regional, and industry-specific standards.

Microsoft Azure carries a very large set of compliance offerings covering global standards (ISO 27001, SOC), regional and national ones, and industry-specific ones (such as HIPAA for healthcare) — breadth is one of its selling points, and the catalogue is published for customers to check. Why not the others: coverage is global and industry-wide, not United States federal only. The platform is independently audited and certified — customers inherit those certifications rather than commissioning their own platform audit. And certifications very much apply to Azure's cloud services, which is the whole point. Pro tip: remember the model as a shared one — Microsoft certifies the platform; you remain responsible for how you configure and use it on top.

AZ-900 Question 4 of 7

A privacy lead needs Microsoft's official explanation of what personal data Microsoft collects, how it is used, and the rights people have over it — the authoritative reference document, not a tool or a dashboard. Which resource is this?

Answer: A — The Microsoft Privacy Statement, reached through the Trust Center.

The Microsoft Privacy Statement is the published document describing what personal data Microsoft collects and how it is used and shared; the Trust Center is the front door that links to it along with Microsoft's wider privacy, security, and compliance information. Why not the others: the Azure Policy definitions library is a catalogue of technical rules for resources, not a privacy document. Compliance Manager is an assessment tool that scores your compliance, not a statement of Microsoft's own data practices. Cost Management tracks spend and is unrelated. Pro tip: Trust Center = the hub that explains and links Microsoft's privacy and trust commitments; Service Trust Portal = where you download the audit reports behind them.

AZ-900 Question 5 of 7

A German public-sector customer must guarantee that the data their application stores stays physically within a specific country's borders. Which Azure concept determines where that customer data is stored at rest?

Answer: A — The Azure region (within an Azure geography) that you select when you deploy the resource.

Data residency — where data is stored at rest — is governed by the Azure region you deploy into, and regions are grouped into geographies drawn along country or compliance boundaries so customers can keep data inside a given jurisdiction. Choose a region inside the required geography and the data stays there. Why not the others: a tenant's language setting is cosmetic and has nothing to do with storage location. An RBAC role controls who may act on the resource, not where its bytes live. The pricing tier affects features and cost, not physical location. Pro tip: residency questions are answered by region and geography choice at deployment time — that is the lever.

AZ-900 Question 6 of 7

During a review, a stakeholder distinguishes 'data residency' from 'data sovereignty' and asks which term captures the idea that the data is subject to the laws and legal jurisdiction of the country in which it is located. Which term is that?

Answer: A — Data sovereignty.

Data sovereignty is the principle that data is subject to the laws and legal jurisdiction of the country where it physically resides — a legal concept, distinct from the purely geographic question of location. Why not the others: data residency is only where the data is stored, without the legal-jurisdiction dimension. Data redundancy is about keeping copies for durability and availability (as in Azure Storage replication), not law. Data classification is about labelling data by sensitivity. Pro tip: residency = where the bytes sit; sovereignty = whose law reaches them. The exam likes to pair these two and test whether you can separate them.

AZ-900 Question 7 of 7

A regulated bank wants Azure to continuously check its running resources against a recognised regulatory standard and flag anything non-compliant — for example every storage account that is not encrypting data in transit — without manual audits. Which Azure capability delivers this ongoing compliance assessment of resources?

Answer: A — Azure Policy, using its built-in regulatory compliance initiatives.

Azure Policy continuously evaluates your resources against rules, and it ships built-in initiatives (grouped policy sets) mapped to regulatory standards, so it can audit and report your resources' compliance against a standard on an ongoing basis and flag or block non-compliant ones. Why not the others: the Service Trust Portal is a document library for Microsoft's platform certifications — it does not inspect your resources. The Microsoft Privacy Statement is a reference document, not an enforcement engine. Advisor's cost recommendations are about spend, not regulatory compliance of configurations. Pro tip: continuous, automated compliance checking of your own resources = Azure Policy; the paperwork proving Microsoft's platform is compliant = Service Trust Portal.

That is exactly how every question in the course works — answer, explanation, why-not. The real set continues in the practice player: 10 free questions, no sign-up.

Continue with the 10 free questions →

Those 7 questions were the start.

The exam does not test whether you recognise a term — it tests whether you can rule out three plausible answers under time pressure. That is what the explanations above are for, and there are 300 more questions built exactly like them.

Collecting questions yourself

  • Scattered across forums, of unknown age
  • Answer keys without reasoning
  • No idea which domain you are weak in

Practising with a system

  • 300 questions in 6 full tests, AZ-900 (2026)
  • Every option explained — including the wrong ones
  • Readiness per exam domain, and drills for your weakest
Start free — 10 questions

Straight into the player. No account, no email.

Frequently asked questions

Where do I download Azure's audit reports and compliance certifications?
From the Service Trust Portal — Microsoft's published library of audit reports and certifications for its cloud platform, where documents such as SOC 1/2/3 attestations and the ISO 27001 certificate are available to download. That is the platform's own paperwork. It is separate from your organisation's compliance state, which you assess in Microsoft Purview Compliance Manager and enforce on your resources with Azure Policy.
What's the difference between the Service Trust Portal and Compliance Manager?
The Service Trust Portal is where you read and download Microsoft's audit reports and certifications about the Azure platform — you consume documents. Microsoft Purview Compliance Manager is where you assess and manage your own organisation's compliance against standards, getting a compliance score and improvement actions to work through. One is Microsoft's paperwork about the platform; the other measures and helps improve your posture. The exam rewards keeping those two roles straight.
Are these real exam questions?
No. They are our own questions, written in the style and difficulty of the AZ-900 — never copied from any question bank or the real exam. Reproducing live exam items violates Microsoft's certification agreement and can cost a candidate their certification, and a crammed answer teaches you nothing about the one you have not seen. Use these to learn the distinctions cold, then confirm the recall in the simulator.

Updated for AZ-900 (July 2026). The sample questions above are our own work in the style of the exam — not real exam items. The exam itself is set and marked by the certification body.