Courseiva

DP-203 Design and implement data storage Practice Question

A media company uses Azure Data Lake Storage Gen2 to store video files and metadata. They need to ensure that when a user is deleted from Microsoft Entra ID, their access to the data lake is immediately revoked. They also want to minimize administrative overhead. What should they do?

⚠ Common exam trap

The trap here is assuming that SAS tokens or direct ACLs can provide immediate revocation when a user is deleted, when only Microsoft Entra ID group-based access does so automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Microsoft Entra ID security groups and assign ACLs to the groups.

Using Microsoft Entra ID security groups to manage access to Data Lake Storage Gen2 ensures that when a user is deleted from Microsoft Entra ID, their group memberships are removed, and their access is revoked immediately. This approach centralizes permission management, reducing administrative overhead. Direct ACLs, SAS tokens, and storage account keys do not provide automatic revocation upon user deletion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign POSIX ACLs directly to each user.

    Why it's wrong here

    Assigning POSIX ACLs directly to each user requires manual updates whenever users change or leave. It does not automatically revoke access when a user is deleted from Microsoft Entra ID. This approach increases administrative overhead and does not meet the immediate revocation requirement.

  • ✗

    Generate a shared access signature (SAS) token for each user.

    Why it's wrong here

    SAS tokens are granted directly to users and are not automatically revoked when the user is deleted from Microsoft Entra ID. They remain valid until they expire or are explicitly revoked. Managing SAS tokens for many users also increases administrative overhead and does not provide immediate revocation upon user deletion.

  • ✓

    Use Microsoft Entra ID security groups and assign ACLs to the groups.

    Why this is correct

    Assigning ACLs to Microsoft Entra ID security groups means that access is managed through group membership. When a user is deleted from Microsoft Entra ID, they are automatically removed from all groups, and their access is revoked immediately. This minimizes administrative overhead because permissions are managed at the group level.

  • ✗

    Store the storage account key in Azure Key Vault and grant users access to the key.

    Why it's wrong here

    Granting users access to the storage account key gives them full control over the storage account, which is a security risk. It also does not provide immediate revocation when a user is deleted from Microsoft Entra ID, as the key remains valid. This approach lacks fine-grained access control and auditing.

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.