DP-203 Develop data processing Practice Question
You are developing an Azure Data Factory pipeline that must call an external REST API, parse the JSON response, and load selected fields into an Azure SQL Database. The API requires a bearer token that expires every hour, so the pipeline must obtain a fresh token before each call. You need to implement the token acquisition and header injection without writing custom code in a data flow. What should you use?
⚠ Common exam trap
The trap here is reaching for managed identity for any REST authentication, when managed identity only works with services that accept Microsoft Entra ID tokens and cannot retrieve a third-party bearer token.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Web activity to fetch the token, followed by a Copy activity whose REST source uses the token in an Authorization header.
The pipeline needs to fetch a short-lived bearer token and attach it to an outgoing REST call. A Web activity can invoke the token endpoint and return the token value, which is then supplied as an Authorization header on the REST source of a Copy activity. This pattern is fully declarative, refreshes the token on every run, and satisfies the no-custom-code constraint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A Web activity to fetch the token, followed by a Copy activity whose REST source uses the token in an Authorization header.
Why this is correct
This approach uses a Web activity to call the token endpoint and capture the bearer token, then passes it as an Authorization header on the REST source of a Copy activity. It keeps everything declarative within the pipeline, refreshes the token per run, and avoids custom code, which matches the stated requirement.
- ✗
A REST linked service configured with a system-assigned managed identity.
Why it's wrong here
Managed identity authenticates to Azure resources that support Microsoft Entra ID tokens, but the external REST API expects its own bearer token issued by its token endpoint. A managed identity cannot obtain that third-party token, so the REST calls would fail authentication against the external service.
- ✗
A Web activity that calls the token endpoint and a Set variable activity to store the token.
Why it's wrong here
A Web activity can call the token endpoint, but storing the result in a pipeline variable and then manually referencing it in subsequent activities adds complexity and does not automatically attach the token to the REST request. It also does not integrate with the connector's authentication, so the header injection would be manual and error-prone.
- ✗
A Mapping Data Flow with a REST source and a derived column that generates the token.
Why it's wrong here
Data flows are not designed to perform OAuth token acquisition against an external endpoint, and derived columns cannot generate a valid signed bearer token. This approach would not reliably produce a usable token for each hourly refresh and adds unnecessary complexity to a task better handled by pipeline activities.
Go deeper
Related to this question
Learn chapter
Implement Azure Data Factory Pipelines
Key term
Data Transformation Pipelines
Data transformation pipelines are automated sequences of steps that take raw data from a source, clean and reshape it into a usable format, and then load it into a destination for analysis or storage.
Key term
Azure Data Factory
Azure Data Factory is a cloud-based data integration service that lets you create, schedule, and orchestrate data pipelines to move and transform data from various sources to destinations.
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.