DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You are designing a security strategy for an Azure Data Lake Storage Gen2 account that stores sensitive financial data. The data must be encrypted at rest using customer-managed keys stored in Azure Key Vault. You also need to ensure that only specific Azure services can access the storage account. What should you do?
⚠ Common exam trap
Watch out — candidates often confuse network-level security features like private endpoints or Azure Defender with the requirement for customer-managed encryption keys and service-specific access, which are configured separately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a customer-managed key for encryption and set the storage firewall to allow access from selected Azure services.
Customer-managed keys in Azure Key Vault enable encryption at rest with keys controlled by the organization. Configuring the storage firewall to allow access from selected Azure services ensures that only trusted services can reach the data. Together, these settings satisfy the encryption and access restriction requirements. Other options address network isolation or threat detection but not the specific encryption and service-level access controls needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Azure Private Link and enable soft delete.
Why it's wrong here
Azure Private Link provides private connectivity from a virtual network to the storage account, and soft delete protects against accidental deletion. Neither feature provides customer-managed key encryption at rest, nor do they restrict access to specific Azure services. Private Link restricts network paths but does not differentiate between Azure services; any service within the allowed network could access the account.
- ✗
Enable infrastructure encryption and use shared access signatures (SAS) for access.
Why it's wrong here
Infrastructure encryption adds a second layer of encryption but still uses Microsoft-managed keys by default; it does not provide customer-managed keys. SAS tokens grant delegated access but are not a mechanism to restrict access to specific Azure services; they can be shared broadly. Thus, this option fails to meet the customer-managed key requirement and does not provide service-level access control.
- ✓
Configure a customer-managed key for encryption and set the storage firewall to allow access from selected Azure services.
Why this is correct
Using a customer-managed key stored in Azure Key Vault satisfies the encryption at rest requirement with customer control. Configuring the storage account firewall to allow access from selected Azure services, such as Azure Synapse Analytics or Azure Data Factory, restricts access to only those services. This combination directly meets both the encryption and service-level access requirements without overcomplicating the solution.
- ✗
Enable Azure Defender for Storage and configure a private endpoint.
Why it's wrong here
Azure Defender for Storage provides threat detection and alerts for suspicious activity, and private endpoints restrict network access to a virtual network. However, neither feature enforces customer-managed key encryption at rest nor restricts access to specific Azure services via service endpoints. They address network and threat detection, not the encryption and service-level access requirements stated in the scenario.
Go deeper
Related to this question
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.