DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You manage an Azure Data Lake Storage Gen2 account used by an Azure Synapse Analytics workspace. You need to ensure that only authorized users can access data, and that all access attempts are logged for auditing. You configure Microsoft Entra ID (Azure AD) authentication and role-based access control (RBAC). Which additional feature should you enable to capture detailed access logs for compliance?
⚠ Common exam trap
Many candidates confuse security monitoring features like Azure Defender with auditing features that provide a complete access log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Monitor diagnostic settings for the storage account
Azure Monitor diagnostic settings capture resource logs for Data Lake Storage Gen2, including operations like GetBlob, PutBlob, and DeleteBlob, along with the caller's identity. These logs can be sent to Log Analytics for querying and retention, enabling comprehensive auditing. This is the correct feature to enable for detailed access logging in a compliance scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storage account firewall and virtual network rules
Why it's wrong here
Firewall and virtual network rules restrict network access to the storage account, but they do not log access attempts. They are preventive controls, not detective controls. Enabling them would not provide the detailed audit logs required for compliance. They are part of a defense-in-depth strategy but do not satisfy the logging requirement.
- ✗
Azure Defender for Storage
Why it's wrong here
Azure Defender for Storage provides threat detection and security alerts for anomalous access patterns, but it does not provide a complete audit log of all access attempts. It is a security monitoring tool, not an auditing solution. While it can complement auditing, it does not fulfill the requirement to log every access attempt for compliance.
- ✓
Azure Monitor diagnostic settings for the storage account
Why this is correct
Azure Monitor diagnostic settings allow you to stream resource logs from the storage account to destinations like Log Analytics, Event Hubs, or a storage account. For Data Lake Storage Gen2, these logs include detailed information about read, write, and delete operations, including the identity of the requester. This meets the requirement for auditing access attempts.
- ✗
Azure Storage analytics logging
Why it's wrong here
Storage analytics logging is a legacy feature that provides logging for Blob, Queue, and Table storage, but it is not designed for hierarchical namespace operations in Data Lake Storage Gen2. It does not capture fine-grained access details for directories and files, and it has been largely superseded by Azure Monitor diagnostic settings.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.