DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You are configuring Azure Data Lake Storage Gen2 for a new data lake. You need to ensure that all data written to the 'raw' container is automatically encrypted at rest. Which feature should you enable?
⚠ Common exam trap
DP-203 often tests the confusion between SSE (automatic encryption at rest for storage) and Azure Disk Encryption (VM disk encryption) — candidates may pick Disk Encryption when the question is about ADLS Gen2 storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Storage Service Encryption (SSE)
Azure Storage Service Encryption (SSE) is the feature that automatically encrypts data at rest in Azure Storage, including ADLS Gen2. It is enabled by default for all storage accounts and uses 256-bit AES encryption, ensuring that all data written to the 'raw' container is encrypted without any application changes. This directly satisfies the requirement for automatic encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Key Vault
Why it's wrong here
Azure Key Vault stores and manages keys, secrets and certificates; it performs no encryption of data written to the container. It is tempting because encryption keys must live somewhere, and Key Vault would be correct when the requirement is centralised key management for customer-managed keys.
- ✗
Azure Disk Encryption
Why it's wrong here
Azure Disk Encryption encrypts virtual machine OS and data disks, not objects within a Data Lake Storage Gen2 container. It is tempting because it is a genuine at-rest encryption feature, and it would be correct when protecting the volumes backing Azure virtual machines.
- ✓
Azure Storage Service Encryption (SSE)
Why this is correct
Azure Storage Service Encryption automatically encrypts all data at rest in Data Lake Storage Gen2 using 256-bit AES, with no configuration needed per container. Enabling it ensures every object written to the raw container is encrypted transparently at rest.
- ✗
Azure Purview
Why it's wrong here
Microsoft Purview catalogues, classifies and governs data across sources; it does not encrypt data at rest in a storage container. It is tempting because it addresses data protection broadly, and Purview would be correct when the requirement is data discovery, lineage and compliance classification.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.