DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You have an Azure Databricks workspace that processes sensitive data. The security team requires that all access to the workspace be authenticated using Microsoft Entra ID and that all API calls be audited. Which configuration should you implement?
⚠ Common exam trap
The trap is focusing on network security (Private Link, VNet injection) when the question explicitly asks for authentication and auditing; candidates may overlook the need for diagnostic settings to capture API calls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure workspace to use Microsoft Entra ID authentication and enable diagnostic settings for audit logs.
To meet both requirements—Microsoft Entra ID authentication and audited API calls—you must configure the workspace to use Entra ID authentication and enable diagnostic settings to send audit logs to a destination like Log Analytics. This combination ensures identity-based access and a record of API activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure workspace to use Microsoft Entra ID authentication and enable diagnostic settings for audit logs.
Why this is correct
Configuring the workspace for Microsoft Entra ID authentication enforces identity-based access, while diagnostic settings stream audit logs to a Log Analytics workspace or storage account. Together these satisfy both constraints: Entra ID authentication for all access and auditable API calls.
- ✗
Enable VNet injection and configure network security groups.
Why it's wrong here
VNet injection and NSGs control network traffic paths, not authentication or API audit trails, so neither requirement is met. It is tempting because VNet injection genuinely isolates Databricks clusters within your own virtual network, which is the right choice when the requirement is network-level isolation or restricting egress to specific endpoints.
- ✗
Deploy Azure Private Link and disable public access.
Why it's wrong here
Private Link removes public network exposure but does not authenticate users through Microsoft Entra ID nor record API calls, so both stated requirements remain unmet. It is tempting because Private Link is the correct choice when the requirement is private connectivity from on-premises or peered networks to the workspace endpoints.
- ✗
Configure personal access tokens for API access and enable cluster logs.
Why it's wrong here
Personal access tokens are a separate credential store, bypassing Microsoft Entra ID authentication, and cluster logs capture Spark driver and worker activity rather than API audit records. It is tempting because PATs are the correct choice when non-interactive automation must call the Databricks REST API without interactive sign-in.
Go deeper
Related to this question
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.