Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You have an Azure Databricks workspace that processes sensitive data. The security team requires that all access to the workspace be authenticated using Microsoft Entra ID and that all API calls be audited. Which configuration should you implement?

⚠ Common exam trap

The trap is focusing on network security (Private Link, VNet injection) when the question explicitly asks for authentication and auditing; candidates may overlook the need for diagnostic settings to capture API calls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure workspace to use Microsoft Entra ID authentication and enable diagnostic settings for audit logs.

To meet both requirements—Microsoft Entra ID authentication and audited API calls—you must configure the workspace to use Entra ID authentication and enable diagnostic settings to send audit logs to a destination like Log Analytics. This combination ensures identity-based access and a record of API activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure workspace to use Microsoft Entra ID authentication and enable diagnostic settings for audit logs.

    Why this is correct

    Configuring the workspace for Microsoft Entra ID authentication enforces identity-based access, while diagnostic settings stream audit logs to a Log Analytics workspace or storage account. Together these satisfy both constraints: Entra ID authentication for all access and auditable API calls.

  • ✗

    Enable VNet injection and configure network security groups.

    Why it's wrong here

    VNet injection and NSGs control network traffic paths, not authentication or API audit trails, so neither requirement is met. It is tempting because VNet injection genuinely isolates Databricks clusters within your own virtual network, which is the right choice when the requirement is network-level isolation or restricting egress to specific endpoints.

  • ✗

    Deploy Azure Private Link and disable public access.

    Why it's wrong here

    Private Link removes public network exposure but does not authenticate users through Microsoft Entra ID nor record API calls, so both stated requirements remain unmet. It is tempting because Private Link is the correct choice when the requirement is private connectivity from on-premises or peered networks to the workspace endpoints.

  • ✗

    Configure personal access tokens for API access and enable cluster logs.

    Why it's wrong here

    Personal access tokens are a separate credential store, bypassing Microsoft Entra ID authentication, and cluster logs capture Spark driver and worker activity rather than API audit records. It is tempting because PATs are the correct choice when non-interactive automation must call the Databricks REST API without interactive sign-in.

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.