DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Which TWO Azure features can be used to encrypt data at rest in Azure Blob Storage? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer-managed keys in Azure Key Vault
Option C (Customer-managed keys in Azure Key Vault) is correct because Azure Blob Storage supports server-side encryption with customer-managed keys (CMK), where the key encryption key is stored in Azure Key Vault and used to wrap the account's data encryption key, providing control over the encryption of data at rest. Option D (Storage Service Encryption, SSE) is correct because SSE is the built-in Azure Storage feature that automatically encrypts blob data at rest using AES-256 before it is persisted to disk, and it is enabled by default for all storage accounts. Option A (Azure Disk Encryption) is not correct because it encrypts OS and data disks attached to Azure VMs (using BitLocker/DM-Crypt), not blobs in a storage account. Option B (Azure Information Protection) is not correct because it classifies and protects files at the application/document level rather than providing storage-account-level encryption at rest for blobs. Option E (Transport Layer Security) is not correct because TLS protects data in transit over the network, not data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Disk Encryption
Why it's wrong here
Azure Disk Encryption encrypts OS and data disks attached to IaaS virtual machines, not blob objects in a storage account. It is tempting because it protects data at rest, but its scope is VM volumes; the correct choices are Storage Service Encryption and customer-managed keys in Key Vault.
- ✗
Azure Information Protection
Why it's wrong here
Azure Information Protection classifies and labels documents for protection as they travel, but it does not encrypt blob data at rest in a storage account. It is tempting because it applies encryption to files, yet that protection follows the document, not the storage platform's at-rest layer.
- ✓
Customer-managed keys in Azure Key Vault
Why this is correct
Customer-managed keys in Azure Key Vault satisfy the at-rest encryption requirement by letting you supply your own RSA key that wraps the account's data encryption key, rather than relying on Microsoft-managed keys. This gives you control over rotation and revocation, meeting the stem's demand for a Blob Storage encryption feature.
- ✓
Storage Service Encryption (SSE)
Why this is correct
Storage Service Encryption provides transparent, server-side AES-256 encryption of blob data at rest, applied automatically by the Azure platform before data is written to disk. It satisfies the stem's at-rest requirement without application changes, covering all blobs in every storage account by default.
- ✗
Transport Layer Security (TLS)
Why it's wrong here
TLS secures data in transit between client and storage endpoint, so it never encrypts bytes sitting on disk. It is tempting because TLS appears throughout Azure Storage security documentation, and it is the correct control when the requirement is protecting data moving across the network rather than at rest.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DP-203
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your company uses Azure Blob Storage to store backups. You need to ensure that data is encrypted at rest using a customer-managed key stored in Azure Key Vault. Which feature should you enable?
easy- A.Azure Purview
- B.Azure Disk Encryption
- ✓ C.Azure Storage Service Encryption with customer-managed keys
- D.Azure Information Protection
Why C: Azure Storage Service Encryption (SSE) encrypts data at rest and supports customer-managed keys stored in Azure Key Vault. Option A is incorrect because Azure Purview is a data governance service, not for encryption. Option B is incorrect because Azure Disk Encryption is used for virtual machine disks, not Blob Storage. Option D is incorrect because Azure Information Protection is for classification and labeling. Therefore, option C is correct.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.