Courseiva

ADLS Gen2 vs Blob Storage — Hierarchical Namespace & POSIX ACLs

Which TWO features are available in Azure Data Lake Storage Gen2 but not in Azure Blob Storage? (Choose two.)

Quick Answer

Hierarchical namespace is the foundational feature that everything else about ADLS Gen2's advantage over plain Blob Storage builds on. Standard Blob Storage uses a flat namespace, meaning what look like folders are really just prefixes baked into blob names, with no real directory structure underneath, so an operation like renaming or deleting a folder actually means touching every blob whose name starts with that prefix, one at a time. Hierarchical namespace changes this by organizing data into an actual directory tree, so operations like renaming or deleting a directory happen as a single, near-instant metadata operation rather than a blob-by-blob sweep. That structural change is also what makes the second distinguishing feature possible: POSIX-compliant access control lists, which let you assign read, write, and execute permissions at the level of an individual directory or file, the way a traditional file system would. Blob Storage's flat namespace has no concept of a directory to attach permissions to, so it is limited to broader container-level access policies instead. Both features trace back to the same underlying design decision to layer a real file-system hierarchy on top of blob storage. When a question asks what ADLS Gen2 offers that plain Blob Storage does not, hierarchical namespace and the directory-level ACLs it enables are the two features to reach for.

⚠ Common exam trap

Test-takers frequently assume features like soft delete or lifecycle management are exclusive to ADLS Gen2, when in fact they are shared with Blob Storage, while the hierarchical namespace and POSIX ACLs are the true differentiators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hierarchical namespace

Azure Data Lake Storage Gen2 is built on top of Blob Storage but adds a hierarchical namespace (option A), which organizes objects into true directories and enables atomic directory operations and efficient rename/delete semantics that flat Blob Storage cannot provide. It also supports POSIX-compliant access control lists (option E), allowing fine-grained, file- and directory-level permissions (read/write/execute) that map to Hadoop and POSIX-style security models, which plain Blob Storage does not offer. The other options are not unique to ADLS Gen2: immutable storage (option B) is a Blob Storage feature (time-based retention and legal holds), soft delete for blobs (option C) is a Blob Storage data-protection feature, and lifecycle management policies (option D) are available for Blob Storage to transition or expire data across hot/cool/archive tiers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Hierarchical namespace

    Why this is correct

    A hierarchical namespace arranges objects into true directories, so operations like atomic directory renames and POSIX-style access control lists become possible. Flat Blob Storage merely simulates folders through naming conventions, meaning renames require copying every blob individually — the specific capability the stem demands.

  • ✗

    Immutable storage

    Why it's wrong here

    Immutable storage (WORM policies) is available in Azure Blob Storage generally, including accounts without a hierarchical namespace, so it is not exclusive to Azure Data Lake Storage Gen2. It is tempting because compliance retention sounds like a data-lake feature, yet immutability is a blob-level capability in both services.

  • ✗

    Soft delete for blobs

    Why it's wrong here

    Soft delete for blobs exists in both Azure Blob Storage and Azure Data Lake Storage Gen2, so it cannot be a Gen2-only feature. It is tempting because data protection feels like a hierarchical-namespace capability, but soft delete is a blob service feature available regardless of whether hierarchical namespace is enabled.

  • ✗

    Lifecycle management policies

    Why it's wrong here

    Lifecycle management policies operate on blob storage accounts generally, so they are not a Gen2-exclusive feature. It is tempting because tiering and expiry feel tied to analytics workloads, but lifecycle rules apply to block blobs in standard Azure Blob Storage too, independent of hierarchical namespace.

  • ✓

    POSIX-compliant access control lists

    Why this is correct

    POSIX-compliant ACLs are exclusive to Azure Data Lake Storage Gen2, satisfying the stem's requirement for a feature absent from Blob Storage. Gen2 layers a hierarchical namespace over Blob Storage, enabling file-level POSIX permissions alongside role-based access control. Plain Blob Storage offers only coarse container-level access, so this capability genuinely distinguishes the two services.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DP-203

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which Azure storage solution is best suited for storing large volumes of unstructured data, such as log files and media files, and supports both hierarchical namespace and POSIX-like access control lists?

easy
  • A.Azure Blob Storage
  • ✓ B.Azure Data Lake Storage Gen2
  • C.Azure Files
  • D.Azure SQL Database

Why B: Azure Data Lake Storage Gen2 (ADLS Gen2) combines a hierarchical namespace with POSIX-like access control lists (ACLs) on top of Azure Blob Storage. This makes it ideal for storing large volumes of unstructured data (e.g., log files, media files) while supporting fine-grained, POSIX-compliant permissions and directory-level operations that are essential for big data analytics workloads.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.