You are securing an Azure Data Lake Storage Gen2 account that contains sensitive data. Which TWO of the following should you implement to protect data from unauthorized access?
POSIX-style ACLs on Data Lake Storage Gen2 apply at directory and file level, enforcing least-privilege access for individual users and groups independently of broad role assignments. This granular permission model directly prevents unauthorised reads by limiting each principal to only the paths they require.
Why this answer
Option A is correct because Azure Data Lake Storage Gen2 uses POSIX-style access control lists (ACLs) at both the directory and file level, and configuring ACLs to grant least privilege ensures users and groups only receive the specific read/write/execute permissions they require, directly preventing unauthorized access to sensitive data. Option B is correct because private endpoints assign a private IP address from your virtual network to the storage account, removing exposure to the public internet and restricting access to only clients within the approved virtual network or connected networks. Option C is incorrect because setting a default ACL that allows read access to all authenticated users violates least privilege and would broaden, not restrict, access to sensitive data.
Option D is incorrect because CORS rules only control which web origins can make cross-origin browser requests to the service; they do not authenticate users or prevent unauthorized direct access. Option E is incorrect because enabling large file shares only increases the maximum capacity and file size limits of the file share, and has no effect on access control or authorization.
Exam trap
DP-203 often tests the confusion between network-layer controls (private endpoints, firewall rules) and identity-layer controls (RBAC, ACLs) — candidates who pick CORS or large file shares mistake non-security features for access controls.