DP-203 Access Control Lists (ACLs) Practice Question
Which TWO actions should you take to secure sensitive data in Azure Data Lake Storage Gen2? (Choose two.)
⚠ Common exam trap
DP-203 often tests the misconception that 'ease of use' options like public access or anonymous sharing are acceptable security choices, when they are exactly the anti-patterns the exam wants you to reject.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use access control lists (ACLs) to restrict access to specific directories
Option B is correct because Azure Data Lake Storage Gen2 supports POSIX-style access control lists (ACLs) that let you grant or deny read/write/execute permissions at the directory and file level, which is essential for least-privilege access to sensitive data. Option E is correct because enabling encryption at rest with customer-managed keys stored in Azure Key Vault gives you control over the key lifecycle and satisfies compliance requirements for protecting sensitive data at rest. Option A is wrong because enabling public network access from all networks exposes the storage account to the internet and increases attack surface. Option C is wrong because allowing anonymous access permits unauthenticated reads and is a security risk, not a protection measure. Option D is wrong because disabling soft delete removes a recovery safeguard and does nothing to secure sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable public network access from all networks for ease of use
Why it's wrong here
Enabling public network access exposes the storage account to the internet, contradicting the goal of securing sensitive data. Private endpoints plus firewall rules restrict traffic to approved networks. Public access is chosen when broad connectivity outweighs exposure, such as public datasets with no confidentiality requirement.
- ✓
Use access control lists (ACLs) to restrict access to specific directories
Why this is correct
ACLs apply POSIX-style permissions at directory and file level, letting you grant or deny access for specific Microsoft Entra ID principals without broad role assignments. This satisfies the requirement to secure sensitive data by restricting access to specific directories, complementing role-based access control at the container scope.
- ✗
Allow anonymous access to enable sharing
Why it's wrong here
Anonymous access lets unauthenticated callers read blobs, directly undermining confidentiality of sensitive data. Disabling anonymous access and requiring Microsoft Entra ID authorisation is the secure posture. Anonymous access is appropriate only for deliberately public content such as static website assets or open datasets.
- ✗
Disable soft delete to prevent accidental retention of deleted data
Why it's wrong here
Soft delete protects against accidental or malicious deletion by retaining recoverable blobs; disabling it removes that recovery path and weakens data protection. The secure action is enabling soft delete with a retention period. Disabling soft delete suits scenarios where regulatory rules forbid any retained copies.
- ✓
Enable encryption at rest using customer-managed keys in Azure Key Vault
Why this is correct
Customer-managed keys in Azure Key Vault satisfy the requirement to control encryption of data at rest, letting your organisation own and rotate the key protecting the storage account rather than relying on Microsoft-managed keys. This meets the stem's sensitive-data constraint by ensuring only holders of the Key Vault key can decrypt the Data Lake content.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.