Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You are configuring Azure Data Lake Storage Gen2 for a new data lake. You need to ensure that all data written to the 'raw' container is automatically encrypted at rest. Which feature should you enable?

⚠ Common exam trap

DP-203 often tests the confusion between SSE (automatic encryption at rest for storage) and Azure Disk Encryption (VM disk encryption) — candidates may pick Disk Encryption when the question is about ADLS Gen2 storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Storage Service Encryption (SSE)

Azure Storage Service Encryption (SSE) is the feature that automatically encrypts data at rest in Azure Storage, including ADLS Gen2. It is enabled by default for all storage accounts and uses 256-bit AES encryption, ensuring that all data written to the 'raw' container is encrypted without any application changes. This directly satisfies the requirement for automatic encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Key Vault

    Why it's wrong here

    Azure Key Vault stores and manages keys, secrets and certificates; it performs no encryption of data written to the container. It is tempting because encryption keys must live somewhere, and Key Vault would be correct when the requirement is centralised key management for customer-managed keys.

  • ✗

    Azure Disk Encryption

    Why it's wrong here

    Azure Disk Encryption encrypts virtual machine OS and data disks, not objects within a Data Lake Storage Gen2 container. It is tempting because it is a genuine at-rest encryption feature, and it would be correct when protecting the volumes backing Azure virtual machines.

  • ✓

    Azure Storage Service Encryption (SSE)

    Why this is correct

    Azure Storage Service Encryption automatically encrypts all data at rest in Data Lake Storage Gen2 using 256-bit AES, with no configuration needed per container. Enabling it ensures every object written to the raw container is encrypted transparently at rest.

  • ✗

    Azure Purview

    Why it's wrong here

    Microsoft Purview catalogues, classifies and governs data across sources; it does not encrypt data at rest in a storage container. It is tempting because it addresses data protection broadly, and Purview would be correct when the requirement is data discovery, lineage and compliance classification.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.