Courseiva

DP-203 Design and implement data storage Practice Question

A financial services firm stores trade records in an Azure Data Lake Storage Gen2 account. Regulatory requirements mandate that all data at rest be encrypted with a customer-managed key (CMK) stored in Azure Key Vault, and that the key be rotated every 90 days without re-uploading any data. The storage account currently uses Microsoft-managed keys. What should you do to meet these requirements with the least administrative effort?

⚠ Common exam trap

The trap here is assuming that key rotation requires re-encrypting or migrating data, when Azure Storage automatically uses the latest key version once customer-managed keys are configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the storage account to use customer-managed keys stored in Azure Key Vault, and create a new key version in Key Vault every 90 days.

Customer-managed keys in Azure Key Vault allow the storage account to use an encryption key controlled by the organization. Rotating the key is achieved by creating a new key version in Key Vault; Azure Storage automatically picks up the latest version, so no data re-upload or re-encryption job is needed. This satisfies both the CMK mandate and the 90-day rotation requirement with minimal administrative effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the storage account to use customer-managed keys stored in Azure Key Vault, and create a new key version in Key Vault every 90 days.

    Why this is correct

    Configuring customer-managed keys for the storage account links encryption at rest to a key in Azure Key Vault. Creating a new key version every 90 days rotates the key without requiring any data re-upload, because Azure Storage automatically uses the latest key version. This directly satisfies both the CMK mandate and the rotation requirement with minimal ongoing effort.

  • ✗

    Deploy Azure Disk Encryption on the storage account and schedule a Key Vault key rotation task using Azure Automation.

    Why it's wrong here

    Azure Disk Encryption applies to virtual machine disks, not to Azure Storage accounts or Data Lake Storage Gen2. It cannot encrypt blobs or files in a storage account. Even if rotation were automated, the encryption would not cover the trade records stored in the lake. This option misapplies a VM-focused feature to a storage service, making it incorrect.

  • ✗

    Create a new storage account with customer-managed keys and migrate all trade records using Azure Data Factory, then delete the original account.

    Why it's wrong here

    Creating a new storage account and migrating data would meet the CMK requirement eventually, but it involves significant administrative effort, data movement, and potential downtime. It also does not inherently solve key rotation without additional Key Vault configuration. The scenario explicitly asks for the least administrative effort, so this approach is unnecessarily complex and therefore wrong.

  • ✗

    Enable Azure Storage Service Encryption with Microsoft-managed keys and configure a lifecycle management policy to re-encrypt blobs every 90 days.

    Why it's wrong here

    Microsoft-managed keys do not satisfy the requirement for customer-managed keys, and Azure Storage Service Encryption does not expose a lifecycle policy that re-encrypts blobs. Lifecycle management policies only transition or delete blobs based on age; they never perform cryptographic re-encryption. This approach neither meets the CMK mandate nor the rotation requirement, so it is incorrect for this scenario.

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.