Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You are configuring security for an Azure Data Lake Storage Gen2 account that stores sensitive data. You need to ensure that all data access is logged and that you can audit who accessed the data and when. You also need to retain the logs for 90 days. What should you do?

⚠ Common exam trap

A common mix-up: candidates confuse threat detection with access logging; Azure Defender alerts on suspicious activity but does not provide a full audit trail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure diagnostic settings to send logs to a Log Analytics workspace.

Diagnostic settings in Azure allow you to export resource logs to a Log Analytics workspace, where you can analyze and retain them for up to 90 days (or longer with custom retention). This provides the necessary auditing capability for Data Lake Storage Gen2 access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure diagnostic settings to send logs to a Log Analytics workspace.

    Why this is correct

    Configuring diagnostic settings for Azure Data Lake Storage Gen2 allows you to stream resource logs, such as StorageRead and StorageWrite, to a Log Analytics workspace. These logs capture details about each access, including the identity, operation, and timestamp. You can then query and retain the logs in Log Analytics for 90 days (or more) to meet auditing requirements.

  • ✗

    Enable soft delete for blobs.

    Why it's wrong here

    Soft delete protects against accidental deletion by retaining deleted blobs for a specified retention period. It does not log access events or provide auditing capabilities. It is a data protection feature, not a monitoring or auditing feature.

  • ✗

    Use Azure Storage Analytics logging to a storage account.

    Why it's wrong here

    Azure Storage Analytics logging is a legacy feature that logs requests to blobs, queues, and tables. However, for Data Lake Storage Gen2, it is recommended to use diagnostic settings instead, as Storage Analytics logs are being deprecated. Additionally, configuring retention for 90 days requires setting retention policies on the logs, which is less flexible than Log Analytics.

  • ✗

    Enable Azure Defender for Storage.

    Why it's wrong here

    Azure Defender for Storage provides threat detection and security alerts for storage accounts, but it does not provide detailed access logs for auditing who accessed data. It focuses on anomalous activity and potential threats, not on comprehensive access logging. For auditing, you need diagnostic logs.

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.