easyMultiple Choice
DP-203 Practice Question: Designing data security for Azure Data Lake…
You are designing data security for Azure Data Lake Storage Gen2. The requirement is to prevent data from being accessed by anyone outside the corporate network. Which feature should you enable?
⚠ Common exam trap
Test-takers frequently confuse network-level security (Private Endpoint) with access control (RBAC) or data protection (encryption), thinking that denying RBAC roles or enabling encryption alone can prevent external access, when only network isolation truly blocks traffic from outside the corporate network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure Private Endpoint or service endpoint with a VNet.
Azure Private Endpoint or service endpoint with a VNet ensures that all traffic to the storage account stays within the corporate network and never traverses the public internet. Private Endpoint assigns a private IP from the VNet to the storage account, effectively isolating it from public access. This meets the requirement to prevent access from outside the corporate network by enforcing network-level isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Azure Private Endpoint or service endpoint with a VNet.
Why this is correct
A private endpoint assigns a private IP from your VNet to the storage account, so traffic never traverses the public internet and access is restricted to the corporate network. Service endpoints similarly limit access to specified subnets, satisfying the requirement to block external access.
- ✗
Assign RBAC roles to deny access to all except corporate users.
Why it's wrong here
RBAC assigns permissions to identities, not network locations; corporate users connecting from outside the network would still be permitted. RBAC is tempting because it governs who may access data, and it would be correct when the requirement is least-privilege authorisation per user or group.
- ✗
Configure IP firewall rules to allow only corporate IP ranges.
Why it's wrong here
IP firewall rules restrict access by source address, not by corporate network membership; a corporate user on a home connection is blocked while a spoofed or shared range may pass. Firewall rules suit restricting access to known public endpoints, not enforcing network-boundary membership.
- ✗
Enable encryption at rest using customer-managed keys.
Why it's wrong here
Customer-managed keys control who holds the encryption key, not who can reach the data; an external principal with valid credentials still reads it. CMK is tempting because it strengthens key custody, and it would be correct when the requirement is regulatory control over key rotation and revocation.
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.