Courseiva

DP-203 Private endpoint Practice Question

You have an Azure Data Lake Storage Gen2 account that stores sensitive customer data. You need to prevent data exfiltration to unauthorized external IP addresses. Which TWO actions should you take?

⚠ Common exam trap

DP-203 often tests whether candidates confuse identity-based controls like SAS with network-based controls, leading them to select SAS when the requirement is specifically to block exfiltration to unauthorized external IP addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use private endpoints for the storage account

Option A is correct because private endpoints assign the storage account a private IP address inside your virtual network via Azure Private Link, so traffic to the account never traverses the public internet and cannot be reached from unauthorized external IP addresses. Option D is correct because configuring the storage account firewall (network rules) to allow only specific virtual networks restricts access to those trusted VNets and blocks all other public IPs, directly preventing exfiltration to unauthorized external addresses. Option B is incorrect because Azure Firewall is a network security service deployed in a virtual network or hub, not a feature you enable on a storage account. Option C is incorrect because SAS tokens grant scoped access to data but do not by themselves block outbound exfiltration to arbitrary external IP addresses. Option E is incorrect because geo-redundant storage only replicates data across regions for durability and availability, and has no role in controlling network access or preventing exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use private endpoints for the storage account

    Why this is correct

    Private endpoints assign a private IP from your virtual network, so storage traffic never traverses public internet addresses. This blocks exfiltration to unauthorised external IPs, satisfying the constraint, provided public network access is also disabled on the account.

  • ✗

    Enable Azure Firewall on the storage account

    Why it's wrong here

    Azure Firewall is a separate virtual network appliance; it cannot be enabled on a storage account, which instead offers network rules and private endpoints for IP restriction. It is tempting because firewall terminology implies egress control, and would be correct when securing traffic across an Azure virtual network subnet.

  • ✗

    Use shared access signatures (SAS) with limited permissions

    Why it's wrong here

    SAS tokens delegate time-bound, scoped access to specific resources but do not evaluate the caller's source IP, so a leaked token still permits exfiltration from anywhere. It is tempting because SAS restricts permissions, and would be correct when the requirement is least-privilege delegated access rather than network-origin filtering.

  • ✓

    Configure storage firewall to allow only specific virtual networks

    Why this is correct

    The storage firewall restricts network access to approved virtual networks and IP ranges, blocking connections from unauthorised external addresses. This directly satisfies the requirement to prevent data exfiltration to unauthorised external IPs at the network layer of the storage account.

  • ✗

    Enable geo-redundant storage (GRS)

    Why it's wrong here

    GRS replicates data to a secondary region for durability; it does not restrict outbound traffic to external IP addresses. It is tempting as a security-sounding storage setting, but exfiltration prevention requires network rules and private endpoints, not redundancy configuration.

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.