Courseiva

DP-203 Design and implement data storage Practice Question

A data engineer needs to store CSV files containing customer data in Azure Blob Storage. The files must be encrypted at rest using a customer-managed key stored in Azure Key Vault. What should they configure?

⚠ Common exam trap

It's easy for candidates to confuse Azure Disk Encryption (which encrypts VM disks) with Azure Storage Service Encryption (which encrypts blob data), leading candidates to select Option A when the requirement is for blob-level encryption with customer-managed keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Storage Service Encryption (SSE) with customer-managed keys

Azure Storage Service Encryption (SSE) for Blob Storage encrypts data at rest automatically. By choosing customer-managed keys (CMK) stored in Azure Key Vault, the customer retains control over the encryption keys, meeting the requirement for customer-managed key encryption at rest. SSE with CMK is the correct service for encrypting blobs with a key the customer manages.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Disk Encryption

    Why it's wrong here

    Azure Disk Encryption encrypts OS and data disks attached to virtual machines using BitLocker or DM-Crypt, and does not apply to Blob Storage objects. It is tempting as a familiar at-rest encryption control, and suits IaaS VM volumes requiring customer-managed keys.

  • ✗

    Azure Storage Firewall

    Why it's wrong here

    Storage Firewall filters network access by IP range and virtual network; it neither encrypts data nor references Key Vault keys, so it cannot satisfy the customer-managed key requirement. It is tempting because it hardens a storage account's public exposure, and would be correct when restricting access to selected networks.

  • ✓

    Azure Storage Service Encryption (SSE) with customer-managed keys

    Why this is correct

    Azure Storage Service Encryption with customer-managed keys wraps the account's data encryption key with a key held in Azure Key Vault, so blob data is encrypted at rest under organisational control. This meets the customer-managed key constraint for the CSV files.

  • ✗

    Azure Information Protection

    Why it's wrong here

    Azure Information Protection classifies and labels documents for encryption during sharing, not blob data at rest in a storage account. It is tempting because it is a Microsoft encryption feature, and suits protecting sensitive files across email and endpoints, not storage-account CMK configuration.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.