DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Which TWO Azure services can be used to audit data access and changes in Azure Data Lake Storage Gen2? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Storage account diagnostic settings.
Options C and D are correct. Storage account diagnostic settings enable logging of read, write, and delete operations to Azure Data Lake Storage Gen2, which can be used for auditing. Azure Monitor collects these logs and integrates with Microsoft Sentinel for advanced security monitoring and threat detection. Option A is incorrect because Microsoft Entra ID sign-in logs track user authentication, not data access at the storage level. Option B is incorrect because Azure Backup reports focus on backup status, not auditing data changes. Option E is incorrect because Azure Policy enforces compliance rules but does not audit data access or modification events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID sign-in logs.
Why it's wrong here
Entra ID logs authentication, not data access.
- ✗
Azure Backup reports.
Why it's wrong here
Backup reports track backup operations, not data access.
- ✓
Storage account diagnostic settings.
Why this is correct
Diagnostic settings log read/write operations.
- ✓
Azure Monitor and Microsoft Sentinel.
Why this is correct
Azure Monitor collects logs, and Sentinel provides security analytics.
- ✗
Azure Policy.
Why it's wrong here
Azure Policy enforces rules, does not audit data access.
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 760-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DP-203
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO features can be used to audit access to data in Azure Storage? (Choose two.)
medium- ✓ A.Azure Monitor diagnostic settings
- ✓ B.Azure Storage analytics logs
- C.Azure RBAC role assignments
- D.Azure Policy
- E.Microsoft Defender for Cloud
Why A: Options A and B are correct. Option A: Azure Monitor diagnostic settings can be configured to send resource logs (including storage audit logs) to Log Analytics, Storage, or Event Hubs for auditing. Option B: Storage Analytics logs provide detailed information about successful and failed requests to a storage account, which can be used for auditing. Option C is incorrect because Azure RBAC role assignments are for access control, not auditing. Option D is incorrect because Azure Policy enforces compliance rules, not auditing. Option E is incorrect because Microsoft Defender for Cloud provides security alerts and threat protection, but not detailed access auditing.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.