Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesHard

A financial institution is deploying a highly sensitive application to Azure. They require a dedicated, isolated compute environment that provides the highest level of security and compliance, ensuring that their application's data and code are completely isolated from other customers' data. Which Azure compute offering is most appropriate for this scenario?

  1. AAzure Virtual Machines
  2. BAzure App Service
  3. CAzure Dedicated Host
  4. DAzure Functions
Show answer & explanation

Correct answer: C. Azure Dedicated Host

Azure Dedicated Host provides single-tenant physical servers to host your Azure Virtual Machines. This offers hardware isolation at the server level, ensuring that your VMs are the only ones running on that server, meeting the highest security and compliance requirements for isolation.

Why the other options are wrong

  • A. Azure Virtual Machines typically run on multi-tenant servers, meaning your VMs share physical hardware with other customers, which doesn't meet 'completely isolated from other customers' data'.
  • B. Azure App Service is a multi-tenant PaaS offering, where underlying infrastructure is shared, not providing dedicated physical server isolation.
  • D. Azure Functions is a serverless, multi-tenant service, where your code runs on shared infrastructure, not offering dedicated physical server isolation.

Azure Dedicated Host

A service that provides physical servers dedicated to a single customer, allowing for hardware isolation for Azure Virtual Machines.

  • Provides single-tenant physical servers for VMs.
  • Offers the highest level of hardware isolation and control.
  • Useful for strict compliance and regulatory requirements.

Memory trick: Dedicated Host is the 'Do Not Disturb' server.

More Describe Azure architecture and services questions