DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You are securing an Azure Data Lake Storage Gen2 account that contains sensitive data. Which TWO of the following should you implement to protect data from unauthorized access?
⚠ Common exam trap
DP-203 often tests the confusion between network-layer controls (private endpoints, firewall rules) and identity-layer controls (RBAC, ACLs) — candidates who pick CORS or large file shares mistake non-security features for access controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure ACLs to grant least privilege to users and groups
Option A is correct because Azure Data Lake Storage Gen2 uses POSIX-style access control lists (ACLs) at both the directory and file level, and configuring ACLs to grant least privilege ensures users and groups only receive the specific read/write/execute permissions they require, directly preventing unauthorized access to sensitive data. Option B is correct because private endpoints assign a private IP address from your virtual network to the storage account, removing exposure to the public internet and restricting access to only clients within the approved virtual network or connected networks. Option C is incorrect because setting a default ACL that allows read access to all authenticated users violates least privilege and would broaden, not restrict, access to sensitive data. Option D is incorrect because CORS rules only control which web origins can make cross-origin browser requests to the service; they do not authenticate users or prevent unauthorized direct access. Option E is incorrect because enabling large file shares only increases the maximum capacity and file size limits of the file share, and has no effect on access control or authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure ACLs to grant least privilege to users and groups
Why this is correct
POSIX-style ACLs on Data Lake Storage Gen2 apply at directory and file level, enforcing least-privilege access for individual users and groups independently of broad role assignments. This granular permission model directly prevents unauthorised reads by limiting each principal to only the paths they require.
- ✓
Use private endpoints to restrict access to the storage account
Why this is correct
Private endpoints assign a private IP from your virtual network to the storage account, removing exposure to the public internet. Traffic then traverses the Microsoft backbone via Azure Private Link, so unauthorised access from outside the approved network boundary is blocked at the network layer.
- ✗
Set the default ACL to allow read access for all authenticated users
Why it's wrong here
Granting read access to all authenticated users directly exposes the sensitive data to every identity in the tenant, which is the opposite of the required protection. It is tempting because default ACLs are the native POSIX-style permission mechanism in Data Lake Storage Gen2, and such a broad grant would suit a deliberately public, non-sensitive dataset.
- ✗
Enable CORS rules to allow only specific origins
Why it's wrong here
CORS governs which web browser origins may call the storage endpoint; it does not authenticate users or restrict data access, so it cannot prevent unauthorised reads. It is tempting because CORS rules do limit access by origin, but that mechanism suits browser-based cross-domain requests, not protecting sensitive files from unauthorised identities.
- ✗
Enable large file shares on the storage account
Why it's wrong here
Large file shares only raise the capacity and throughput limits for SMB and blob access; they change no authorisation behaviour, so unauthorised access remains possible. It is tempting because it is a storage account configuration setting, and it would be the right choice when a workload needs files larger than the default 5 TiB limit.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.