Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You are a data engineer at a healthcare company. Your Azure Data Factory pipeline ingests sensitive patient records from an on-premises SQL Server into an Azure Data Lake Storage Gen2 account. The compliance team requires that all data be encrypted at rest with a customer-managed key (CMK) and that key rotation be audited. You need to configure the storage account to meet these requirements. What should you do?

⚠ Common exam trap

Watch out — candidates often confuse encryption of the source database or compute resources with encryption of the data lake storage account itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Azure Key Vault, generate a customer-managed key, and configure the storage account to use that key for encryption. Enable Key Vault logging and diagnostic settings to audit key rotation.

To encrypt data at rest in Azure Data Lake Storage Gen2 with a customer-managed key, you must use Azure Key Vault to store and manage the key, then associate that key with the storage account. Auditing key rotation requires enabling logging on Key Vault. This ensures both encryption control and compliance auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an Azure Key Vault, generate a customer-managed key, and configure the storage account to use that key for encryption. Enable Key Vault logging and diagnostic settings to audit key rotation.

    Why this is correct

    Using Azure Key Vault to store a customer-managed key and configuring the storage account to use that key satisfies the encryption-at-rest requirement. Enabling Key Vault logging and diagnostic settings captures key rotation events, providing the required audit trail. This combination directly meets both compliance needs.

  • ✗

    Enable Azure Disk Encryption on the virtual machines that run the self-hosted integration runtime, and use BitLocker to encrypt the data before it is uploaded.

    Why it's wrong here

    Azure Disk Encryption protects data on the VM's OS and data disks, not the data at rest in the Azure Data Lake Storage Gen2 account. Encrypting before upload does not satisfy the requirement for customer-managed keys on the storage account itself, and it does not provide auditable key rotation for the storage service.

  • ✗

    Enable Azure Storage Service Encryption with Microsoft-managed keys and configure Azure Monitor to log key rotation events.

    Why it's wrong here

    Microsoft-managed keys do not give you control over the key lifecycle or rotation, and Azure Monitor does not log key rotation for Microsoft-managed keys because you do not manage them. This option fails the requirement for customer-managed keys and auditable rotation, so it is incorrect for this scenario.

  • ✗

    Configure Azure SQL Database Transparent Data Encryption (TDE) with a customer-managed key and use Azure SQL Auditing to track key rotations.

    Why it's wrong here

    Transparent Data Encryption applies to Azure SQL Database, not to Azure Data Lake Storage Gen2. The scenario requires encryption of data stored in the data lake, so TDE on the source SQL Server does not meet the requirement. Auditing TDE key rotations also does not cover the storage account's encryption keys.

Go deeper

Related to this question

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.