DP-203 Design and implement data storage Practice Question
A data engineer needs to store CSV files containing customer data in Azure Blob Storage. The files must be encrypted at rest using a customer-managed key stored in Azure Key Vault. What should they configure?
⚠ Common exam trap
It's easy for candidates to confuse Azure Disk Encryption (which encrypts VM disks) with Azure Storage Service Encryption (which encrypts blob data), leading candidates to select Option A when the requirement is for blob-level encryption with customer-managed keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Storage Service Encryption (SSE) with customer-managed keys
Azure Storage Service Encryption (SSE) for Blob Storage encrypts data at rest automatically. By choosing customer-managed keys (CMK) stored in Azure Key Vault, the customer retains control over the encryption keys, meeting the requirement for customer-managed key encryption at rest. SSE with CMK is the correct service for encrypting blobs with a key the customer manages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Disk Encryption
Why it's wrong here
Azure Disk Encryption encrypts OS and data disks attached to virtual machines using BitLocker or DM-Crypt, and does not apply to Blob Storage objects. It is tempting as a familiar at-rest encryption control, and suits IaaS VM volumes requiring customer-managed keys.
- ✗
Azure Storage Firewall
Why it's wrong here
Storage Firewall filters network access by IP range and virtual network; it neither encrypts data nor references Key Vault keys, so it cannot satisfy the customer-managed key requirement. It is tempting because it hardens a storage account's public exposure, and would be correct when restricting access to selected networks.
- ✓
Azure Storage Service Encryption (SSE) with customer-managed keys
Why this is correct
Azure Storage Service Encryption with customer-managed keys wraps the account's data encryption key with a key held in Azure Key Vault, so blob data is encrypted at rest under organisational control. This meets the customer-managed key constraint for the CSV files.
- ✗
Azure Information Protection
Why it's wrong here
Azure Information Protection classifies and labels documents for encryption during sharing, not blob data at rest in a storage account. It is tempting because it is a Microsoft encryption feature, and suits protecting sensitive files across email and endpoints, not storage-account CMK configuration.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.