Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You are configuring security for an Azure Synapse Analytics workspace that uses a serverless SQL pool. The workspace is connected to Azure Data Lake Storage Gen2 via a managed identity. You need to ensure that only the Synapse workspace can access the storage account, and no other Azure service or user can access it directly. The storage account should not be accessible from the public internet. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a private endpoint for the storage account in the same virtual network as the Synapse workspace, and disable public network access.

Configure a private endpoint for the storage account in the same virtual network as the Synapse workspace, and disable public network access. This ensures that only the Synapse workspace, which is connected via the private endpoint, can access the storage account. The managed identity is used for authentication, but the private endpoint restricts network access. Option A is incorrect because public IP addresses can change and do not provide secure, private connectivity. Option B is incorrect because allowing trusted Microsoft services would permit other Azure services to access the storage account, not just the Synapse workspace. Option C is incorrect because RBAC alone does not restrict network access; the storage account would still be publicly accessible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure the storage account firewall to allow only the Synapse workspace's public IP address.

    Why it's wrong here

    Synapse workspace does not have a fixed public IP.

  • Enable 'Allow trusted Microsoft services to access this storage account' on the firewall.

    Why it's wrong here

    This allows many services, not just Synapse.

  • Use Azure RBAC to assign the Storage Blob Data Contributor role to the Synapse workspace managed identity.

    Why it's wrong here

    RBAC controls data plane access but does not restrict network access.

  • Configure a private endpoint for the storage account in the same virtual network as the Synapse workspace, and disable public network access.

    Why this is correct

    Private endpoint ensures private connectivity; disabling public access restricts others.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every DP-203 question from scratch — 760 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.