Courseiva

DP-203 Access Control Lists (ACLs) Practice Question

Which TWO actions should you take to secure sensitive data in Azure Data Lake Storage Gen2? (Choose two.)

⚠ Common exam trap

Candidates may confuse access control methods or overlook that customer-managed keys add an extra security layer. They might also assume that disabling soft delete is a security measure, but it actually reduces data protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use access control lists (ACLs) to restrict access to specific directories

The correct answers are B and E. Option B: Using access control lists (ACLs) in Azure Data Lake Storage Gen2 allows granular permissions at the directory and file level, enabling you to restrict access to sensitive data. Option E: Enabling encryption at rest with customer-managed keys in Azure Key Vault provides an additional layer of security by allowing you to manage your own encryption keys. Option A is incorrect because public network access from all networks exposes data to potential threats; it should be restricted. Option C is incorrect as anonymous access should always be disabled for sensitive data. Option D is incorrect because soft delete should be enabled to protect against accidental data deletion or corruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable public network access from all networks for ease of use

    Why it's wrong here

    Increases attack surface

  • Use access control lists (ACLs) to restrict access to specific directories

    Why this is correct

    Granular permissions

  • Allow anonymous access to enable sharing

    Why it's wrong here

    Anonymous access is not secure

  • Disable soft delete to prevent accidental retention of deleted data

    Why it's wrong here

    Soft delete enhances security by allowing recovery

  • Enable encryption at rest using customer-managed keys in Azure Key Vault

    Why this is correct

    Encrypts data at rest

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every DP-203 question from scratch — 760 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.