DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You manage an Azure Data Lake Storage Gen2 account that stores sensitive financial data. The data must be encrypted at rest, and access must be audited. You need to ensure that encryption keys are managed by your organization and that all access attempts are logged. Which TWO actions should you take? (Choose two.)
⚠ Common exam trap
Candidates often confuse threat detection with audit logging; Azure Defender for Storage alerts on anomalies but does not provide a complete access log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable diagnostic logging for the storage account and send logs to Azure Monitor.
To meet the requirements, you need customer-managed keys for organizational control over encryption keys, and diagnostic logging to audit all access attempts. Customer-managed keys are configured in Azure Key Vault and used by the storage account for encryption at rest. Diagnostic logs capture detailed access information and can be routed to Azure Monitor for analysis and retention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Azure Storage Service Encryption with Microsoft-managed keys.
Why it's wrong here
Azure Storage Service Encryption with Microsoft-managed keys encrypts data at rest by default, but the keys are managed by Microsoft, not your organization. The requirement specifies that keys must be managed by your organization. Therefore, this option does not meet the key management requirement, although it does provide encryption.
- ✓
Enable diagnostic logging for the storage account and send logs to Azure Monitor.
Why this is correct
Diagnostic logging captures read, write, and delete operations on the storage account, which can be sent to Azure Monitor, Log Analytics, or a storage account for auditing. This satisfies the requirement to log all access attempts. It provides detailed audit trails for compliance and security investigations.
- ✓
Configure customer-managed keys in Azure Key Vault for the storage account.
Why this is correct
Customer-managed keys allow your organization to manage the encryption keys in Azure Key Vault, satisfying the requirement for organizational key control. This also enables encryption at rest for the storage account. It is the correct approach when you need to own and rotate keys, and it integrates with Azure Policy for compliance.
- ✗
Use Azure Private Link to restrict access to the storage account.
Why it's wrong here
Azure Private Link restricts network access to the storage account by using a private endpoint, enhancing security. However, it does not manage encryption keys or log access attempts. It addresses network isolation, not the key management or auditing requirements. Therefore, it does not meet the specified needs.
- ✗
Enable Azure Defender for Storage.
Why it's wrong here
Azure Defender for Storage provides threat detection and security alerts for anomalous access, but it does not log all access attempts for auditing purposes. It is a security monitoring tool, not an audit logging solution. While valuable, it does not fulfill the requirement to log all access attempts to the data lake.
Go deeper
Related to this question
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.