Courseiva
mediumMultiple Select

DP-203 Practice Question: Which TWO actions should you take when monitoring…

Which TWO actions should you take when monitoring Azure Data Lake Storage Gen2 to detect security threats?

⚠ Common exam trap

Watch out — candidates often confuse data protection features (like soft delete) or network controls (like firewalls) with active threat detection, overlooking that only dedicated security monitoring tools (Azure Security Center/Defender and Sentinel) can identify and alert on security threats in real time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure Security Center and Azure Defender for Storage.

Option A is correct because Azure Security Center (now Microsoft Defender for Cloud) with Azure Defender for Storage provides threat detection specifically for storage accounts, including anomalous access patterns, suspicious IP addresses, and unusual data exfiltration attempts against Data Lake Storage Gen2. Option B is correct because enabling diagnostic settings on the storage account and streaming the logs (such as StorageRead, StorageWrite, and StorageDelete) to Azure Sentinel allows security teams to correlate events, build analytics rules, and detect threats across the environment. Option C is incorrect because soft delete is a data protection and recovery feature for accidental deletion, not a security threat detection mechanism. Option D is incorrect because firewall and virtual network service endpoints restrict network access to the storage account, which is a preventive control rather than a monitoring or detection action. Option E is incorrect because alerting on the 'Transactions' metric only tracks volume and availability of requests, not security-relevant behavior or threat indicators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Azure Security Center and Azure Defender for Storage.

    Why this is correct

    Microsoft Defender for Storage surfaces anomalous access and upload activity on Data Lake Storage Gen2 accounts, while Azure Security Center centralises those alerts for investigation. Together they satisfy the requirement to detect security threats against the storage account.

  • ✓

    Enable diagnostic settings for the storage account and send logs to Azure Sentinel.

    Why this is correct

    Diagnostic settings stream control-plane and data-plane logs to Microsoft Sentinel, enabling correlation and threat detection. This satisfies the requirement to detect security threats, since Sentinel's analytics rules and incident workflows surface suspicious access patterns that raw metrics alone cannot reveal.

  • ✗

    Enable soft delete for blobs to recover from accidental deletions.

    Why it's wrong here

    Soft delete preserves deleted blobs for a retention period so they can be restored; it responds to data loss after the fact and generates no signal about malicious access. It is tempting because it protects against accidental or ransomware deletion, which is the correct control when the requirement is recoverability rather than detecting security threats.

  • ✗

    Configure firewall and virtual network service endpoints.

    Why it's wrong here

    Firewall and virtual network service endpoints restrict which networks may reach the storage account, blocking traffic rather than recording or alerting on suspicious activity. It is tempting because network isolation is a genuine security control, and it is the right choice when the requirement is to prevent access from unauthorised networks.

  • ✗

    Set up alerting on the 'Transactions' metric.

    Why it's wrong here

    The Transactions metric counts API operations and their success or failure, revealing nothing about who accessed data or from where, so it cannot surface suspicious access patterns. It is tempting because volume spikes can indicate denial-of-service or throttling, making it useful for performance and availability monitoring rather than threat detection.

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.