DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You are a data engineer at a healthcare company. Your Azure Data Factory pipeline ingests sensitive patient records from an on-premises SQL Server into an Azure Data Lake Storage Gen2 account. The compliance team requires that all data be encrypted at rest with a customer-managed key (CMK) and that key rotation be audited. You need to configure the storage account to meet these requirements. What should you do?
⚠ Common exam trap
Watch out — candidates often confuse encryption of the source database or compute resources with encryption of the data lake storage account itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure Key Vault, generate a customer-managed key, and configure the storage account to use that key for encryption. Enable Key Vault logging and diagnostic settings to audit key rotation.
To encrypt data at rest in Azure Data Lake Storage Gen2 with a customer-managed key, you must use Azure Key Vault to store and manage the key, then associate that key with the storage account. Auditing key rotation requires enabling logging on Key Vault. This ensures both encryption control and compliance auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an Azure Key Vault, generate a customer-managed key, and configure the storage account to use that key for encryption. Enable Key Vault logging and diagnostic settings to audit key rotation.
Why this is correct
Using Azure Key Vault to store a customer-managed key and configuring the storage account to use that key satisfies the encryption-at-rest requirement. Enabling Key Vault logging and diagnostic settings captures key rotation events, providing the required audit trail. This combination directly meets both compliance needs.
- ✗
Enable Azure Disk Encryption on the virtual machines that run the self-hosted integration runtime, and use BitLocker to encrypt the data before it is uploaded.
Why it's wrong here
Azure Disk Encryption protects data on the VM's OS and data disks, not the data at rest in the Azure Data Lake Storage Gen2 account. Encrypting before upload does not satisfy the requirement for customer-managed keys on the storage account itself, and it does not provide auditable key rotation for the storage service.
- ✗
Enable Azure Storage Service Encryption with Microsoft-managed keys and configure Azure Monitor to log key rotation events.
Why it's wrong here
Microsoft-managed keys do not give you control over the key lifecycle or rotation, and Azure Monitor does not log key rotation for Microsoft-managed keys because you do not manage them. This option fails the requirement for customer-managed keys and auditable rotation, so it is incorrect for this scenario.
- ✗
Configure Azure SQL Database Transparent Data Encryption (TDE) with a customer-managed key and use Azure SQL Auditing to track key rotations.
Why it's wrong here
Transparent Data Encryption applies to Azure SQL Database, not to Azure Data Lake Storage Gen2. The scenario requires encryption of data stored in the data lake, so TDE on the source SQL Server does not meet the requirement. Auditing TDE key rotations also does not cover the storage account's encryption keys.
Go deeper
Related to this question
Learn chapter
Implement Data Encryption and Access Control
Key term
Azure Data Factory
Azure Data Factory is a cloud-based data integration service that lets you create, schedule, and orchestrate data pipelines to move and transform data from various sources to destinations.
Key term
Data Transformation Pipelines
Data transformation pipelines are automated sequences of steps that take raw data from a source, clean and reshape it into a usable format, and then load it into a destination for analysis or storage.
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.