Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You are designing a data lake architecture using Azure Data Lake Storage Gen2. You need to implement a least-privilege security model. Which authorization mechanism should you use for granular control?

⚠ Common exam trap

DP-203 often tests the confusion between RBAC (coarse, management-plane, container-level) and ACLs (fine-grained, data-plane, file/directory-level) — candidates pick RBAC because it is the more familiar Azure authorization model, but it cannot deliver least-privilege at the file level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use POSIX-like access control lists (ACLs).

POSIX-like access control lists (ACLs) in Azure Data Lake Storage Gen2 provide file- and directory-level granular permissions, enabling least-privilege access down to individual users or groups. They are the recommended mechanism when you need fine-grained control beyond what Azure RBAC roles at the container or storage account level can provide. ACLs support both access ACLs (for current access) and default ACLs (inherited by new child items).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use storage account keys for access.

    Why it's wrong here

    Storage account keys grant full administrative access to the entire account, so they cannot express per-container or per-directory least privilege. POSIX ACLs on Data Lake Storage Gen2 provide that granular, path-level authorisation, which is the intended mechanism.

  • ✗

    Use Azure RBAC roles at the storage account level.

    Why it's wrong here

    Storage-account-level Azure RBAC roles grant control-plane permissions across every container and blob, so they cannot scope access to individual directories or files. They are intended for coarse administrative delegation, such as letting an operator manage a whole account, which is why they are tempting here.

  • ✓

    Use POSIX-like access control lists (ACLs).

    Why this is correct

    POSIX-like ACLs grant per-file and per-directory permissions to individual security principals, exceeding what coarse role assignments allow. This satisfies the least-privilege requirement by scoping read, write and execute rights at the folder or file level within Azure Data Lake Storage Gen2.

  • ✗

    Use shared access signatures (SAS) with stored access policies.

    Why it's wrong here

    A SAS with a stored access policy delegates access to a container or blob, but it cannot enforce POSIX-style ACLs on individual directories and files. It suits time-limited external sharing of specific objects, which is why it appears plausible for least privilege.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.