DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You are configuring security for an Azure Data Lake Storage Gen2 account. You need to ensure that users can only access files and folders for which they have explicit permissions, and that permissions are enforced at the file and folder level. What should you enable?
⚠ Common exam trap
The trap here is thinking that ACLs alone or RBAC alone can provide complete file-level security, when in fact they are complementary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure RBAC and access control lists (ACLs)
Azure Data Lake Storage Gen2 uses a combination of Azure RBAC and POSIX-like ACLs to secure data. RBAC controls access at the management and container level, while ACLs provide fine-grained permissions at the file and folder level. To ensure users can only access files and folders for which they have explicit permissions, both must be configured. RBAC alone is too coarse, ACLs alone lack the authentication context, and SAS tokens are not identity-based for per-user permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Access control lists (ACLs) only
Why it's wrong here
ACLs alone can enforce file and folder level permissions, but they are not sufficient for complete security because Azure RBAC is still required to authorize the user to access the storage account. Without RBAC, users cannot even authenticate to the storage account to use ACLs. Therefore, ACLs alone do not satisfy the requirement for explicit permissions enforcement in a secure manner.
- ✗
Shared access signatures (SAS) only
Why it's wrong here
Shared access signatures provide delegated access to resources in the storage account, but they do not enforce file and folder level permissions based on user identity. SAS tokens grant access to specific resources for a limited time, but they are not integrated with ACLs for per-user permission enforcement. They are suitable for granting temporary access, but not for the requirement of explicit per-user file and folder permissions.
- ✓
Azure RBAC and access control lists (ACLs)
Why this is correct
To enforce file and folder level permissions in Azure Data Lake Storage Gen2, you must use both Azure RBAC and ACLs. RBAC grants the user or service principal access to the storage account or container, while ACLs provide fine-grained permissions on individual files and folders. This combination ensures that users can only access the data for which they have explicit permissions, meeting the requirement.
- ✗
Azure role-based access control (Azure RBAC) only
Why it's wrong here
Azure RBAC provides coarse-grained access control at the storage account or container level, but it does not enforce permissions at the file and folder level. While RBAC roles can grant access to the entire container, they do not provide the granularity required for individual files and folders. To enforce file-level permissions, you need POSIX-like ACLs in addition to RBAC.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.