DP-203 · domain
Secure, monitor, and optimize data storage and data processing
This domain covers securing, monitoring, and tuning Azure data platforms: Synapse Analytics, Databricks, Data Lake Storage, and Data Factory. Questions present operational scenarios—slow queries, unauthorized access, failing jobs—and ask you to pick the right Azure service, authentication method, or optimization technique. Expect both design choices and hands-on configuration reasoning.
Focused practice
Practice Secure, monitor, and optimize data storage and data processing questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Secure, monitor, and optimize data storage and data processing
Be able to select the correct Azure service for monitoring and alerting, secure Synapse and Databricks access with Microsoft Entra ID, and reduce serverless SQL cost by pruning partitions and files. The single most important thing: match the security or monitoring requirement to the native Azure feature, not a workaround.
Choosing Azure Monitor and Log Analytics for Spark job metrics and failure alerts
Securing serverless SQL pools with Microsoft Entra ID authentication and role assignments
Optimizing OPENROWSET queries against Parquet files via partition pruning and file pruning
Using dynamic data masking, row-level security, and column encryption in Synapse
Watch out for
Common Secure, monitor, and optimize data storage and data processing exam traps
- ▸Assuming Azure Databricks job alerts require a third-party tool instead of Azure Monitor integration and diagnostic logging
- ▸Ignoring partition elimination in OPENROWSET, so queries scan every folder under the data lake path
- ▸Granting SQL logins instead of Microsoft Entra ID for serverless SQL pool access, breaking centralized identity control
Question index
All Secure, monitor, and optimize data storage and data processing questions (159)
Click any question to see the full explanation, or start a practice session above.
You are securing an Azure Data Lake Storage Gen2 account that contains sensitive data. Which TWO of the following should you implement to protect data from unauthorized access?
Medium2Your company uses Azure Data Lake Storage Gen2 and needs to implement a data retention policy that automatically deletes files older than 90 days in a specific container. What should you use?
Medium3You are a data engineer at a financial services company. You have an Azure Data Lake Storage Gen2 account named finlake that stores sensitive transaction data in Parquet files. You need to ensure that data is encrypted at rest using a customer-managed key stored in Azure Key Vault, and that the key is automatically rotated every 90 days. You also need to be able to revoke access to the data immediately if the key is compromised. What should you do?
Medium4You need to secure data at rest for an Azure Data Lake Storage Gen2 account that contains sensitive financial data. Which configuration should you enable to ensure that data is encrypted using a customer-managed key stored in Azure Key Vault, and that access to the key is logged?
Easy5Your organization uses Azure Data Lake Storage Gen2 for a data lake. You need to prevent accidental deletion of data by enabling a soft delete policy. Which configuration is required?
Medium6You store sensitive data in Azure Data Lake Storage Gen2. You need to ensure that only members of a specific security group can read the data, while other users in the organization must not have access, even if they have the Storage Blob Data Reader role at the storage account level. What should you use?
Easy7You manage an Azure Data Lake Storage Gen2 account containing a large volume of JSON files. Users report that direct read operations from the data lake are slow, and you observe high egress costs. You need to optimize read performance and reduce cost for analytical queries that frequently filter on a specific timestamp column and select a subset of columns. What should you do?
Medium8Your team uses Azure Databricks for data processing. You need to implement a cost-control strategy that automatically terminates idle clusters after 30 minutes of inactivity, but allows users to override this policy for specific workloads that require long-running clusters. What is the most efficient approach?
Hard9You have an Azure Databricks workspace that processes sensitive data. The security team requires that all access to the workspace be authenticated using Microsoft Entra ID and that all API calls be audited. Which configuration should you implement?
Medium10Your organization uses Azure Data Factory to orchestrate data pipelines. You need to ensure that sensitive data is not exposed in pipeline logs. What should you configure?
Easy11Your company uses Azure Purview for data governance. You need to ensure that sensitive data in Azure Data Lake Storage Gen2 is automatically detected and classified. What should you configure in Purview?
Medium12You are monitoring an Azure Synapse Analytics dedicated SQL pool and notice that queries against a large fact table are slow. The table is distributed using hash distribution on a column that has a high number of nulls. You need to improve query performance. What should you do?
Hard13You need to grant a data analyst read access to a specific folder in an Azure Data Lake Storage Gen2 account. The analyst must not be able to read other folders in the same container. You want to follow the principle of least privilege. What should you use?
Easy14You are designing a data processing solution using Azure Databricks. The solution must use Delta Lake for ACID transactions and must optimize storage costs by automatically compacting small files. Which feature should you enable?
Hard15You need to monitor the performance of your Azure Synapse Analytics dedicated SQL pool. Which metric should you use to identify queued queries due to concurrency limits?
Easy16Which TWO Azure services can be used to monitor and analyze query performance in Azure Synapse Analytics dedicated SQL pool?
Medium17You are designing a data lake architecture using Azure Data Lake Storage Gen2. You need to implement a least-privilege security model. Which authorization mechanism should you use for granular control?
Medium18Which THREE best practices should be followed when designing a data lake in Azure Data Lake Storage Gen2 for optimal performance?
Easy19You are configuring security for an Azure Data Lake Storage Gen2 account. You need to ensure that users can only access files and folders for which they have explicit permissions, and that permissions are enforced at the file and folder level. What should you enable?
Easy20You are running an Azure Stream Analytics job that reads from an Event Hub and writes to a Power BI dataset. The job is falling behind and processing latency is increasing. What should you do to improve performance?
Easy21You need to ensure that data in an Azure Data Lake Storage Gen2 account is encrypted at rest using a customer-managed key. Which feature should you configure?
Easy22Your organization uses Azure Data Lake Storage Gen2 and needs to prevent accidental deletion of data by enabling soft delete. You also need to ensure that deleted blobs are recoverable for 30 days. What should you configure?
Easy23Which THREE security features are available in Azure Data Lake Storage Gen2 to protect data at rest and in transit? (Choose three.)
Hard24Which THREE metrics should you monitor for an Azure Synapse Analytics dedicated SQL pool to ensure optimal performance?
Hard25Your organization uses Azure Data Lake Storage Gen2 with hierarchical namespace enabled. You need to implement a security strategy that allows users to read only specific folders within a container. Which authorization method should you use?
Hard26You have an Azure Synapse Analytics dedicated SQL pool that contains a large fact table named FactSales. The table is partitioned by date and has a clustered columnstore index. You notice that queries filtering on a specific date range are slow. You need to improve query performance for these queries. What should you do?
Medium27You need to monitor the performance of an Azure Stream Analytics job in real time. Which Azure service should you use to track the job's resource utilization (e.g., SU % utilization) and set up alerts when the job is approaching its capacity?
Easy28Which TWO Azure services can be used to monitor Azure Data Factory pipeline runs and set up alerts?
Medium29You have an Azure Synapse Analytics serverless SQL pool. You need to monitor the number of queries that are currently executing. Which dynamic management view should you query?
Easy30You have an Azure Data Lake Storage Gen2 account used by an Azure Synapse Analytics serverless SQL pool. Analysts run ad-hoc queries against CSV and Parquet files. You need to reduce the amount of data scanned by these queries without changing file contents. What should you do?
Medium31Which TWO Azure services can be used to audit data access and changes in Azure Data Lake Storage Gen2? (Choose two.)
Easy32Which TWO Azure services can be used to monitor data pipeline runs and set up alerts for failures in Azure Data Factory?
Hard33Which TWO Azure features can be used to encrypt data at rest in Azure Blob Storage? (Choose two.)
Easy34You need to ensure that an Azure Data Factory pipeline retries a failed activity up to three times with a 5-minute delay between retries. How should you configure the activity?
Easy35Your organization uses Azure Data Lake Storage Gen2 with hierarchical namespace enabled. You need to implement a monitoring strategy to detect and alert on unusual access patterns that could indicate a security breach. Which THREE services or features should you use? (Choose three.)
Hard36You use Azure Data Lake Storage Gen2 with a hierarchical namespace. You need to delegate permissions to a group of data scientists so they can create folders and upload files only within a specific directory path. What is the best way to achieve this?
Easy37You are configuring security for an Azure Data Lake Storage Gen2 account that stores sensitive data. You need to ensure that all data access is logged and that you can audit who accessed the data and when. You also need to retain the logs for 90 days. What should you do?
Easy38Your company uses Azure Data Lake Storage Gen2. You need to ensure that data at rest is encrypted using a customer-managed key stored in Azure Key Vault. What should you configure?
Easy39You manage an Azure Data Factory pipeline that copies data from an on-premises SQL Server to Azure Data Lake Storage Gen2. The pipeline runs daily and completes successfully. You need to be alerted when the pipeline duration exceeds 60 minutes. You want to minimize administrative effort. What should you do?
Medium40You are responsible for securing an Azure Synapse Analytics workspace that contains sensitive data. You need to ensure that data is encrypted at rest using a customer-managed key stored in Azure Key Vault. What should you configure?
Easy41You are designing a data lake in Azure Data Lake Storage Gen2 for a large enterprise. You need to ensure that only authorized users can access the data, and you must implement the principle of least privilege. Which security mechanism should you use to grant fine-grained access to specific directories and files without modifying the underlying storage account firewall settings?
Hard42You have an Azure Data Lake Storage Gen2 account that contains sensitive data. You need to ensure that data is encrypted at rest and that you control the encryption keys. You also need to be able to audit key usage. What should you implement?
Easy43Your Azure Synapse Analytics dedicated SQL pool is experiencing performance degradation. You notice that some queries are being queued due to resource class conflicts. What should you implement to optimize performance and reduce queuing?
Medium44You have an Azure Data Factory pipeline that copies data from an FTP server to Azure Blob Storage. The pipeline runs successfully most of the time, but occasionally fails with a 'FTP server connection refused' error during peak hours. You need to minimize these failures with minimal cost. What should you do?
Easy45You are designing a data processing solution using Azure Synapse Analytics serverless SQL pool. The solution will query data stored in Parquet files in Azure Data Lake Storage Gen2. You need to ensure that the queries are optimized for performance. Which action should you take?
Hard46You are a data engineer at a healthcare company. Your Azure Synapse Analytics workspace contains a dedicated SQL pool that holds patient records. A new compliance rule requires that all queries against the dedicated SQL pool be audited, and that any attempt to access data from an unauthorized IP address be logged. You need to configure auditing for the dedicated SQL pool. What should you do?
Medium47You are a data engineer at a healthcare company. You have an Azure Data Lake Storage Gen2 account named sthealthcare with a container named records. The container holds sensitive patient data in Parquet files. You need to ensure that only users who are members of the Azure AD group named ClinicalResearchers can read the data, while users in the group DataEngineers can read and write. Access must be managed at the directory level and must not affect other containers in the storage account. What should you do?
Medium48Your organization uses Azure Purview for data governance. You need to ensure that sensitive data is properly classified and that access to it is monitored. Which THREE actions should you take? (Choose three.)
Hard49You need to monitor the performance of an Azure Data Factory pipeline that copies data from an on-premises SQL Server to Azure Blob Storage. The pipeline runs on a self-hosted integration runtime. Which metric is most important to monitor to ensure the self-hosted IR is not a bottleneck?
Easy50An organization is using Azure Synapse Analytics and wants to implement column-level security to restrict access to sensitive columns. Which feature should they use?
Easy51You have an Azure Data Factory pipeline that copies data from an on-premises SQL Server to Azure Data Lake Storage Gen2. The pipeline uses a self-hosted integration runtime. You need to ensure that data is encrypted in transit and that the integration runtime authenticates to the on-premises SQL Server using Windows authentication. What should you configure?
Hard52You manage an Azure Synapse Analytics workspace. A dedicated SQL pool contains a table with a column named CustomerEmail that stores email addresses. You need to ensure that users who are not members of the DataPrivacy role see only a masked version of the email addresses when they query the table, while members of DataPrivacy see the actual values. The solution must minimize administrative effort. What should you do?
Medium53You are reviewing a script to create an external data source in Azure Synapse Analytics serverless SQL pool. Based on the exhibit, what is the purpose of the SAS token?
Medium54You need to monitor the performance of an Azure Stream Analytics job that processes real-time IoT data. Which metric indicates the number of events that are being dropped or delayed due to insufficient processing capacity?
Easy55Which THREE metrics should you monitor to evaluate the performance of an Azure Stream Analytics job?
Hard56You are designing a data processing solution in Azure Synapse Analytics. The solution must ensure that sensitive columns containing personally identifiable information (PII) are masked at query time for users without explicit permissions. Which Azure Synapse Analytics feature should you use?
Medium57You are designing a security strategy for an Azure Data Lake Storage Gen2 account that stores sensitive data. You need to ensure that data is encrypted at rest using customer-managed keys. What should you configure?
Easy58Your team has deployed an Azure Stream Analytics job that writes output to Azure Cosmos DB. You need to monitor the job for data latency and ensure it meets a service-level agreement (SLA) of under 10 seconds from input to output. Which metric should you track in Azure Monitor?
Easy59Your organization uses Microsoft Purview to catalog data assets. You need to ensure that sensitive data such as credit card numbers are automatically detected and labeled. Which Purview feature should you configure?
Easy60Your organization uses Azure Data Lake Storage Gen2 with hierarchical namespace enabled. You need to grant a service principal read and write access to a specific directory without granting access to the parent directories. What should you use?
Hard61You are monitoring an Azure Data Factory pipeline that copies data from an on-premises SQL Server to Azure Data Lake Storage Gen2. The pipeline runs daily and has recently started taking longer than expected. You need to identify the cause of the performance degradation. Which two actions should you perform? (Choose two.)
Medium62You are monitoring an Azure Data Factory pipeline that runs hourly. The pipeline executes a stored procedure in an Azure SQL Database. Recently, you have observed that the pipeline occasionally fails with a 'Deadlock' error when the stored procedure runs. The Azure SQL Database is configured with the 'Read Committed Snapshot' isolation level enabled. You need to resolve the deadlock issue with minimal impact on performance. The stored procedure updates multiple tables in a single transaction and is critical for reporting. What should you do?
Easy63You are implementing dynamic data masking on an Azure Synapse Analytics dedicated SQL pool. A table named Customers contains columns: CustomerID (int), Email (varchar), Phone (varchar), and CreditCard (varchar). You need to mask the Email and Phone columns so that users without elevated permissions see only the last four characters of the Email and Phone, while users with elevated permissions see the full values. You also need to ensure that the masking does not affect the storage size of the columns. What should you do?
Hard64Which TWO methods can you use to optimize the cost of storing data in Azure Data Lake Storage Gen2?
Easy65A company uses Azure Databricks for data processing. They want to monitor the performance of Spark jobs and set up alerts for job failures. Which Azure service should they use?
Medium66You need to monitor the health of your Azure Data Lake Storage Gen2 account. Which metric should you use to track the number of successful and failed requests?
Easy67You manage an Azure Data Lake Storage Gen2 account containing a large volume of JSON logs. Users frequently query only the last seven days of data, but each query scans the entire dataset, causing high costs and slow response times. You need to reduce the amount of data scanned by queries without changing the data format or moving the data. What should you do?
Medium68Your organization needs to ensure that all data stored in Azure Data Lake Storage Gen2 is encrypted at rest using Microsoft-managed keys. What is the default encryption method?
Easy69Your organization uses Azure Synapse Analytics dedicated SQL pool. You need to ensure that all data at rest in the SQL pool is encrypted using a customer-managed key stored in Azure Key Vault. What should you configure?
Medium70You have an Azure Data Lake Storage Gen2 account that contains sensitive data. You need to implement a solution that enforces access control at the file and folder level, and also allows you to audit access. You want to minimize administrative effort. What should you do?
Hard71You have an Azure Synapse Analytics dedicated SQL pool that handles both high-priority real-time queries and low-priority batch jobs. You need to ensure that high-priority queries always get the resources they need, while batch jobs do not starve. What should you configure?
Medium72You are a data engineer at a large retail company. Your team uses an Azure Synapse Analytics workspace with a dedicated SQL pool. You need to implement row-level security (RLS) so that sales representatives can see only data for their own region. You must ensure that the security predicate is evaluated at query time and that users cannot bypass it by using different tools. What should you do?
Medium73Your team is using Azure Synapse Analytics to process sensitive customer data. You need to ensure that column-level security is applied to a specific table so that only users with a certain role can view certain columns. Which feature should you use?
Medium74You are optimizing an Azure Synapse Analytics dedicated SQL pool that stores a large fact table. Queries frequently join the fact table to a small dimension table on a non-distributed column, causing data movement. You need to reduce data movement and improve query performance. (Choose two.)
Medium75You are a data engineer at a logistics company. You have an Azure Data Lake Storage Gen2 account that stores JSON logs from IoT devices. The logs are written continuously and are stored in a folder structure of /logs/{year}/{month}/{day}/{hour}/. You need to optimize the storage for cost and performance. The data is accessed frequently for the first 30 days, then occasionally for the next 60 days, and rarely after that. You need to minimize storage costs while ensuring that data remains available. What should you do?
Medium76You are designing a data pipeline in Azure Data Factory that copies data from Azure Blob Storage to Azure SQL Database. The data contains personally identifiable information (PII). What should you use to protect the data during transit?
Easy77Your company uses Azure Databricks for data processing. You need to ensure that spark jobs cannot access certain storage accounts. What is the most secure approach?
Easy78You are responsible for securing an Azure Synapse Analytics workspace. You need to ensure that only authorized users can query the serverless SQL pool. Which authentication method should you use?
Medium79You are monitoring an Azure Data Factory pipeline that copies data from an on-premises SQL Server to Azure Synapse Analytics using a self-hosted integration runtime. You notice that the pipeline runs are taking longer than expected, and you suspect performance bottlenecks. You need to identify the cause and optimize the copy performance. What should you do first?
Hard80You have an Azure Data Factory pipeline that uses a Self-Hosted Integration Runtime (SHIR) to copy data from an on-premises Oracle database to Azure Blob Storage. The pipeline is failing with a connectivity error. You have verified that the SHIR is running and the network firewall allows outbound traffic to Azure. What is the most likely cause of the failure?
Medium81You have an Azure Synapse Analytics dedicated SQL pool that is used for reporting. You notice that the tempdb database is growing rapidly and causing queries to fail. Which two actions should you take to mitigate the issue? (Select two.)
Hard82You manage an Azure Synapse Analytics workspace with a dedicated SQL pool. The security team requires that all data stored in the dedicated SQL pool be encrypted with a customer-managed key (CMK) stored in Azure Key Vault. You need to configure transparent data encryption (TDE) to use the CMK. What should you do first?
Medium83You are a data engineer at a healthcare company. Your Azure Data Factory pipeline ingests sensitive patient records from an on-premises SQL Server into an Azure Data Lake Storage Gen2 account. The compliance team requires that all data be encrypted at rest with a customer-managed key (CMK) and that key rotation be audited. You need to configure the storage account to meet these requirements. What should you do?
Medium84Which TWO actions should you take to secure sensitive data in Azure Data Lake Storage Gen2? (Choose two.)
Medium85You are optimizing an Azure Synapse Analytics dedicated SQL pool that experiences performance degradation during peak hours. You need to reduce query execution time by improving data distribution and reducing data movement. Which two actions should you take? (Choose two.)
Medium86You are monitoring an Azure Data Factory pipeline that copies data from Azure SQL Database to Azure Synapse Analytics. The pipeline occasionally fails with transient errors such as 'Cannot connect to SQL Database' during peak hours. You need to make the pipeline more resilient without manual intervention. What should you configure?
Hard87Which TWO actions should you take to secure data in Azure Synapse Analytics dedicated SQL pool? (Choose two.)
Medium88Your Azure Synapse Analytics workspace uses serverless SQL pools for ad-hoc querying. Users report that queries are slow. You examine the execution plan and see that the query scans multiple partitions in the openrowset. What is the best way to improve performance?
Hard89You need to monitor resource utilization for an Azure Synapse Analytics dedicated SQL pool. Which Azure Monitor metric shows the percentage of allocated DWU being used?
Easy90You are monitoring an Azure Synapse Analytics dedicated SQL pool and notice that some queries are experiencing high wait times due to concurrency slots being exhausted. You need to optimize the workload to reduce contention. Which three actions should you take? (Select three.)
Medium91You have an Azure Data Lake Storage Gen2 account that stores sensitive customer data. You need to prevent data exfiltration to unauthorized external IP addresses. Which TWO actions should you take?
Medium92Your team is troubleshooting slow query performance on a dedicated SQL pool in Azure Synapse Analytics. The query uses a hash-distributed fact table with 60 distributions. After reviewing the execution plan, you notice a high number of data moves. Which action would most likely reduce data movement?
Medium93You are configuring Azure Data Lake Storage Gen2 for a new data lake. You need to ensure that all data written to the 'raw' container is automatically encrypted at rest. Which feature should you enable?
Easy94You have an Azure Data Factory pipeline that loads data from an on-premises SQL Server to Azure Synapse Analytics. The pipeline fails intermittently with network connectivity errors. You need to ensure reliable data transfer with minimal latency. Which solution should you recommend?
Hard95You are monitoring an Azure Data Factory pipeline that runs hourly. You notice that the pipeline has been failing intermittently with an error indicating 'Activity timeout'. Which Azure Monitor metric should you set an alert on to proactively detect such failures?
Easy96You are monitoring an Azure Synapse Analytics dedicated SQL pool. You notice that queries are occasionally queued due to concurrency limits. You need to reduce the impact of concurrency limits on query performance. What should you do?
Hard97You are monitoring an Azure Data Factory pipeline that copies data from an on-premises SQL Server to Azure Data Lake Storage Gen2. The pipeline uses a self-hosted integration runtime. You notice that the copy activity sometimes takes much longer than expected, and you suspect network bottlenecks. You need to optimize the copy performance by adjusting the degree of parallelism. Which setting should you modify?
Medium98You need to ensure that sensitive data stored in Azure SQL Database is encrypted at rest. Which feature should you enable?
Easy99You have an Azure Data Lake Storage Gen2 account that stores log files. You need to implement a data retention policy so that logs older than 90 days are automatically deleted. What should you use?
Easy100You are designing a security strategy for Azure Synapse Analytics. The solution must prevent users from accessing sensitive columns in a dedicated SQL pool, such as Social Security numbers, unless they have explicit permission. Which feature should you use?
Medium101Refer to the exhibit. You are reviewing the workload classifier configuration for an Azure Synapse Analytics dedicated SQL pool. You notice that the 'HeavyLoader' classifier has a queryExecutionTimeoutSeconds of 0. What is the implication of this setting?
Hard102You are a data engineer for a retail company that stores sales data in an Azure Synapse Analytics dedicated SQL pool. You need to optimize query performance for a large fact table that is frequently joined with a much smaller dimension table. The queries often filter on a date column and aggregate sales amounts. Which technique should you implement to improve query performance?
Easy103You need to ensure that data stored in Azure Data Lake Storage Gen2 is encrypted at rest using customer-managed keys. Which Azure service should you use to manage the keys?
Easy104Your organization has an Azure Synapse Analytics dedicated SQL pool that stores sensitive customer data. You need to ensure that only authorized users can access the data, and auditing must be enabled to track all access attempts. What should you do first?
Medium105You are monitoring Azure Stream Analytics job performance. The job is falling behind in processing real-time data. You notice that the SU (Streaming Unit) utilization is consistently at 90% or higher. What is the most appropriate action to improve throughput?
Easy106You need to monitor the performance of Azure Synapse Analytics dedicated SQL pool queries. Which Azure service should you use to identify long-running queries and resource bottlenecks?
Easy107You have an Azure Databricks workspace that uses a managed resource group. The security team requires that all cluster nodes use no public IP addresses and that all outbound traffic goes through a firewall. What should you configure?
Medium108You are optimizing an Azure Synapse Analytics dedicated SQL pool. You need to reduce query execution time for large fact tables that are frequently joined with dimension tables. Which two actions should you perform? (Choose two.)
Hard109You have an Azure Data Lake Storage Gen2 account that contains a container named raw. The container has a folder hierarchy with millions of small files. You need to optimize read performance for an Azure Databricks job that reads these files. You also need to minimize storage costs. What should you do?
Hard110You are a data engineer for a retail company that uses Azure Synapse Analytics. You have a dedicated SQL pool that contains a large fact table named SalesFact. Queries on SalesFact often filter by TransactionDate and join to a dimension table named Product. You notice that these queries perform poorly and sometimes spill to tempdb. You need to optimize the table design to improve query performance and reduce tempdb usage. What should you do?
Hard111You are reviewing an Azure PowerShell script that sets permissions on a directory in Azure Data Lake Storage Gen2. The script sets a default ACL for a user on the path 'sales/2024/01/'. What is the effect of the -DefaultScope parameter?
Hard112You are troubleshooting an Azure Databricks job that writes data to Azure Data Lake Storage Gen2. The job fails with '403 Forbidden' error. The Databricks workspace uses a managed identity (system-assigned) for authentication. What should you verify?
Easy113You manage an Azure Data Lake Storage Gen2 account that stores sensitive financial data. The data must be encrypted at rest, and access must be audited. You need to ensure that encryption keys are managed by your organization and that all access attempts are logged. Which TWO actions should you take? (Choose two.)
Hard114You are optimizing an Azure Synapse Analytics dedicated SQL pool that contains a large fact table with over 1 billion rows. Queries frequently join this fact table with smaller dimension tables on a distribution key. You notice that many queries perform poorly due to data movement. You need to reduce data movement and improve query performance. Which two actions should you take? (Choose two.)
Hard115You manage an Azure Synapse Analytics dedicated SQL pool. A nightly ELT job loads a large fact table and then runs UPDATE statements on many rows. You observe that tempdb usage grows until the load fails. You need to reduce tempdb pressure during the update phase. What should you do?
Hard116An organization is using Azure Data Factory to ingest data from multiple on-premises SQL Server databases into Azure Synapse Analytics. They need to ensure that sensitive data is masked during ingestion before landing in the staging area. What is the best approach?
Hard117You are monitoring an Azure Data Lake Storage Gen2 account using Azure Monitor. You need to be alerted when the number of storage account requests exceeds 20,000 per hour. What is the most efficient way to set up this alert?
Medium118You are a data engineer for a healthcare company. You have an Azure Data Lake Storage Gen2 account that stores sensitive patient data. You need to ensure that all access to the data is logged and that you can audit who accessed which files and when. You also need to minimize administrative effort. Which solution should you implement?
Medium119Your Azure Data Lake Storage Gen2 account stores sensitive data. You need to audit who accesses the data and when, and you want to send the audit logs to a Log Analytics workspace for analysis. What should you configure?
Easy120Your company uses Azure Data Factory to orchestrate data movement. You need to monitor pipeline runs across multiple factories and create a dashboard that shows success and failure rates over the past 30 days. What is the most efficient approach?
Medium121You have an Azure Data Factory pipeline that copies data from an on-premises SQL Server to Azure Blob Storage. The pipeline is failing with a 'Gateway is offline' error. What is the most likely cause?
Easy122You are optimizing an Azure Synapse Analytics dedicated SQL pool. You need to reduce the amount of data read from storage during queries that filter on a date column. The fact table is partitioned by month on the date column. What should you do to improve query performance?
Easy123You are optimizing an Azure Synapse Analytics dedicated SQL pool that contains a fact table with 10 billion rows. Queries frequently join this fact table to a dimension table on a column that is not the distribution column of either table. You need to reduce data movement during these joins. Which two actions should you take? (Choose two.)
Hard124You have an Azure Synapse Analytics dedicated SQL pool. You notice that some queries are taking longer than expected due to excessive data movement operations. You need to minimize data movement without changing the distribution columns. Which table design approach should you recommend?
Hard125You are using Azure Data Factory to copy data from an on-premises Oracle database to Azure Data Lake Storage Gen2. You need to ensure the copy activity can connect to the Oracle database without storing credentials in the pipeline JSON. What should you configure?
Medium126You are using Azure Purview to scan an Azure Data Lake Storage Gen2 account. After scanning, you notice that some files are not classified. What is the most likely reason?
Medium127You are designing a data processing solution in Azure Synapse Analytics. The solution must prevent unauthorized access to data at rest and in transit. Which combination of features should you implement?
Medium128You deploy the Azure Security Center automation shown in the exhibit. What is the purpose of this automation?
Hard129You have an Azure Data Lake Storage Gen2 account that contains a container named raw with millions of small JSON files, each under 1 MB. A daily Azure Data Factory pipeline reads these files and writes them to a curated container as Parquet files. You notice that the pipeline runs slowly and you want to optimize read performance. What should you do first?
Hard130A company uses Azure Stream Analytics to process real-time data from IoT devices. They need to ensure that the output to Azure Synapse Analytics is optimized for high throughput and low latency. What should they configure in the Stream Analytics job?
Hard131You are monitoring an Azure Synapse Analytics dedicated SQL pool. You need to identify queries that are currently running and consuming the most resources. Which dynamic management view (DMV) should you query?
Medium132You have an Azure Data Lake Storage Gen2 account that stores parquet files. You need to ensure that files containing personally identifiable information (PII) are automatically classified and tagged. Which Azure service should you integrate?
Medium133Which TWO configurations are recommended to secure data processing in Azure Synapse Pipelines?
Easy134Your organization uses Azure SQL Database with Active Geo-Replication for disaster recovery. You need to ensure that all connections to the database use Microsoft Entra ID authentication and that access is audited. You also want to minimize the attack surface by disabling SQL authentication. What should you do?
Easy135You need to monitor an Azure Data Factory pipeline for failures and send an email notification when a pipeline run fails. Which Azure service should you use to create an alert based on the pipeline run metrics?
Easy136You need to monitor the performance of an Azure Synapse Analytics dedicated SQL pool. Which DMV should you query to find queries that are currently running and their execution status?
Easy137Your company uses Azure Blob Storage to store backups. You need to ensure that data is encrypted at rest using a customer-managed key stored in Azure Key Vault. Which feature should you enable?
Easy138Your team is running a critical Azure Stream Analytics job that writes results to Azure SQL Database. Recently, the job has been failing with high latency and occasional data loss. You need to monitor the job's performance and set up alerts for when the watermark delay exceeds a threshold. What should you use?
Hard139Your Azure Data Lake Storage Gen2 account stores sensitive customer data. You need to ensure that data is encrypted at rest using customer-managed keys (CMK) and that access to the encryption key is logged. What should you do?
Hard140Refer to the exhibit. You are deploying an Azure Synapse Analytics workspace using an ARM template. The exhibit shows the encryption configuration. What is the effect of setting infrastructureEncryption to Enabled?
Medium141You are responsible for managing an Azure Data Lake Storage Gen2 account that stores parquet files for analytics. You need to implement a data retention policy that automatically deletes files older than 90 days in the 'logs' container. Additionally, you need to ensure that no data is lost due to accidental deletion; you want to be able to recover deleted files within 30 days. You also need to monitor the storage account for unusual access patterns. The solution must minimize administrative effort. What should you do?
Medium142You are reviewing the ARM template snippet for an Azure Data Lake Storage Gen2 account. The template fails to deploy with an error that the encryption key cannot be accessed. What is the most likely cause?
Medium143Refer to the exhibit. You are reviewing an ARM template for an Azure Data Lake Storage Gen2 account. Which of the following security best practices is violated in this template?
Hard144Refer to the exhibit. You are reviewing a Data Factory JSON definition. The factory has a user-assigned managed identity configured. However, the linked service to Azure Storage uses an account key. What security improvement should you recommend?
Medium145You need to implement column-level security in Azure Synapse Analytics to restrict access to salary information. Only users with the 'HRManager' role should see salary columns. Which feature should you use?
Easy146You manage an Azure Data Lake Storage Gen2 account used by an Azure Synapse Analytics workspace. You need to ensure that only authorized users can access data, and that all access attempts are logged for auditing. You configure Azure Active Directory (Azure AD) authentication and role-based access control (RBAC). Which additional feature should you enable to capture detailed access logs for compliance?
Hard147You are designing a disaster recovery plan for an Azure Synapse Analytics dedicated SQL pool. The primary region becomes unavailable. You need to fail over to a secondary region with minimal data loss. The recovery point objective (RPO) is 1 hour. What should you configure?
Hard148Your organization uses Azure Synapse Analytics serverless SQL pools to query data in Azure Data Lake Storage Gen2. You need to ensure that only users with specific Microsoft Entra ID roles can query the data. What should you configure?
Medium149Your organization uses Azure Purview for data governance. You need to automatically scan an Azure Data Lake Storage Gen2 account and classify sensitive data such as credit card numbers and social security numbers. What should you configure?
Medium150You are designing a data processing solution in Azure Synapse Analytics. The solution must ensure that data at rest in a dedicated SQL pool is encrypted using customer-managed keys (CMK) stored in Azure Key Vault. The encryption should be enabled at the database level. What should you configure?
Medium151You have an Azure Synapse Analytics serverless SQL pool that queries data in Azure Data Lake Storage Gen2. You need to ensure that only users with specific Microsoft Entra ID groups can access the data through the serverless SQL pool. What should you configure?
Medium152You are monitoring an Azure Data Factory pipeline that copies data from an on-premises SQL Server to Azure Blob Storage. The pipeline occasionally fails with a timeout error. You need to identify the cause of the failures and receive proactive alerts when similar issues occur. What should you do?
Easy153Your Azure Synapse Analytics dedicated SQL pool is experiencing performance degradation. Queries that previously completed in seconds now take minutes. You notice high queue wait times in sys.dm_pdw_exec_requests. What is the most likely cause?
Medium154Which THREE measures should you implement to monitor and optimize the performance of Azure Data Lake Storage Gen2?
Hard155You are monitoring an Azure Data Factory pipeline that copies data from an Azure SQL Database to an Azure Data Lake Storage Gen2 account. The pipeline runs hourly. You notice that the copy activity sometimes takes much longer than expected. You need to identify the cause of the performance variability. Which action should you take first?
Medium156A company uses Azure Data Lake Storage Gen2 with hierarchical namespace enabled. They need to restrict a specific application's access to only write files in a particular directory without being able to read or list files. Which type of permission should be assigned?
Easy157Which THREE components are valid parts of the Microsoft Purview Data Map? (Choose THREE)
Hard158You have an Azure Synapse Analytics dedicated SQL pool that contains a large fact table. You need to minimize data movement during query execution for joins between the fact table and smaller dimension tables. What should you do?
Easy159You are designing a security strategy for an Azure Data Lake Storage Gen2 account that stores sensitive financial data. The data must be encrypted at rest using customer-managed keys stored in Azure Key Vault. You also need to ensure that only specific Azure services can access the storage account. What should you do?
MediumOther domains
All DP-203 exam domains
Frequently asked questions
- What does the Secure, monitor, and optimize data storage and data processing domain cover on the DP-203 exam?
- Be able to select the correct Azure service for monitoring and alerting, secure Synapse and Databricks access with Microsoft Entra ID, and reduce serverless SQL cost by pruning partitions and files. The single most important thing: match the security or monitoring requirement to the native Azure feature, not a workaround.
- How many questions are in this domain?
- This page lists all 159 Secure, monitor, and optimize data storage and data processing questions in the DP-203 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Secure, monitor, and optimize data storage and data processing questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.