DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You have an Azure Data Lake Storage Gen2 account that contains sensitive data. You need to implement a solution that enforces access control at the file and folder level, and also allows you to audit access. You want to minimize administrative effort. What should you do?
⚠ Common exam trap
The trap here is assuming that Azure RBAC or SAS tokens provide file-level access control, when they are either too coarse or not designed for persistent granular access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable hierarchical namespace and configure POSIX access control lists (ACLs) on files and folders, and enable Azure Storage logging to capture access.
To enforce access control at the file and folder level, you need to enable hierarchical namespace and use POSIX ACLs. This allows granular permissions on directories and files. To audit access, enable Azure Storage logging or integrate with Azure Monitor. This solution minimizes administrative effort because ACLs can be inherited and managed centrally. The other options either provide only coarse-grained access control or focus on network security rather than access auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use shared access signatures (SAS) with specific permissions and IP restrictions, and enable Azure Defender for Storage.
Why it's wrong here
SAS tokens provide delegated access but are not suitable for persistent file and folder level access control across many users. They are often used for temporary access and can be difficult to manage at scale. Azure Defender for Storage provides threat detection, not access auditing. This approach does not meet the granularity or auditing requirements efficiently.
- ✗
Configure Azure Private Endpoints and enable firewall rules to restrict access to the storage account.
Why it's wrong here
Private Endpoints and firewall rules restrict network access, which is a security measure, but they do not provide file and folder level access control or auditing of individual file access. They are complementary to identity-based access control but do not replace ACLs or logging for the stated requirements.
- ✓
Enable hierarchical namespace and configure POSIX access control lists (ACLs) on files and folders, and enable Azure Storage logging to capture access.
Why this is correct
Hierarchical namespace enables file and folder level ACLs, allowing granular permissions similar to a file system. Azure Storage logging (or Azure Monitor integration) can capture access details for auditing. This combination provides fine-grained access control and auditing with minimal administrative effort, as ACLs can be inherited and managed via tools like Azure Storage Explorer or scripts.
- ✗
Enable Azure role-based access control (RBAC) on the storage account and assign the Storage Blob Data Contributor role to users.
Why it's wrong here
Azure RBAC provides coarse-grained access control at the storage account or container level, not at the file and folder level. While it is useful for managing access to the entire container, it does not meet the requirement for file and folder level granularity. Additionally, RBAC alone does not provide detailed audit logs for individual file access.
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.