Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You are configuring security for an Azure Data Lake Storage Gen2 account. You need to ensure that users can only access files and folders for which they have explicit permissions, and that permissions are enforced at the file and folder level. What should you enable?

⚠ Common exam trap

The trap here is thinking that ACLs alone or RBAC alone can provide complete file-level security, when in fact they are complementary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure RBAC and access control lists (ACLs)

Azure Data Lake Storage Gen2 uses a combination of Azure RBAC and POSIX-like ACLs to secure data. RBAC controls access at the management and container level, while ACLs provide fine-grained permissions at the file and folder level. To ensure users can only access files and folders for which they have explicit permissions, both must be configured. RBAC alone is too coarse, ACLs alone lack the authentication context, and SAS tokens are not identity-based for per-user permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Access control lists (ACLs) only

    Why it's wrong here

    ACLs alone can enforce file and folder level permissions, but they are not sufficient for complete security because Azure RBAC is still required to authorize the user to access the storage account. Without RBAC, users cannot even authenticate to the storage account to use ACLs. Therefore, ACLs alone do not satisfy the requirement for explicit permissions enforcement in a secure manner.

  • ✗

    Shared access signatures (SAS) only

    Why it's wrong here

    Shared access signatures provide delegated access to resources in the storage account, but they do not enforce file and folder level permissions based on user identity. SAS tokens grant access to specific resources for a limited time, but they are not integrated with ACLs for per-user permission enforcement. They are suitable for granting temporary access, but not for the requirement of explicit per-user file and folder permissions.

  • ✓

    Azure RBAC and access control lists (ACLs)

    Why this is correct

    To enforce file and folder level permissions in Azure Data Lake Storage Gen2, you must use both Azure RBAC and ACLs. RBAC grants the user or service principal access to the storage account or container, while ACLs provide fine-grained permissions on individual files and folders. This combination ensures that users can only access the data for which they have explicit permissions, meeting the requirement.

  • ✗

    Azure role-based access control (Azure RBAC) only

    Why it's wrong here

    Azure RBAC provides coarse-grained access control at the storage account or container level, but it does not enforce permissions at the file and folder level. While RBAC roles can grant access to the entire container, they do not provide the granularity required for individual files and folders. To enforce file-level permissions, you need POSIX-like ACLs in addition to RBAC.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.