Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsEasy

A financial institution needs to deploy a highly secure application with strict regulatory compliance requirements. The application must run on dedicated hardware, be isolated from other tenants, and provide direct control over the underlying operating system. Which Azure compute offering is most appropriate for this scenario?

  1. AAzure Container Instances
  2. BAzure Virtual Machines
  3. CAzure Functions
  4. DAzure App Service
Show answer & explanation

Correct answer: B. Azure Virtual Machines

Azure Virtual Machines (VMs) provide the highest level of control over the operating system and underlying infrastructure, allowing for custom security configurations and dedicated hardware (if using isolated VMs) to meet strict regulatory and isolation requirements.

Why the other options are wrong

  • A. Azure Container Instances are serverless containers, offering less control than VMs and not typically providing dedicated hardware isolation.
  • C. Azure Functions is a serverless compute service, offering minimal control over the underlying infrastructure.
  • D. Azure App Service is a PaaS offering, abstracting the OS and underlying infrastructure, which doesn't meet the 'direct control over OS' requirement.

Azure IaaS vs PaaS vs FaaS

Azure offers various compute models: Infrastructure as a Service (IaaS) for maximum control, Platform as a Service (PaaS) for managed platforms, and Function as a Service (FaaS) for event-driven, serverless execution.

  • IaaS (VMs): OS control, dedicated hardware options.
  • PaaS (App Service): Managed platform, less control.
  • FaaS (Functions): Serverless, event-driven, minimal control.

Memory trick: More control means more 'I' in IaaS.

More Design infrastructure solutions questions