Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You manage an Azure Data Lake Storage Gen2 account used by an Azure Synapse Analytics workspace. You need to ensure that only authorized users can access data, and that all access attempts are logged for auditing. You configure Microsoft Entra ID (Azure AD) authentication and role-based access control (RBAC). Which additional feature should you enable to capture detailed access logs for compliance?

⚠ Common exam trap

Many candidates confuse security monitoring features like Azure Defender with auditing features that provide a complete access log.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Monitor diagnostic settings for the storage account

Azure Monitor diagnostic settings capture resource logs for Data Lake Storage Gen2, including operations like GetBlob, PutBlob, and DeleteBlob, along with the caller's identity. These logs can be sent to Log Analytics for querying and retention, enabling comprehensive auditing. This is the correct feature to enable for detailed access logging in a compliance scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Storage account firewall and virtual network rules

    Why it's wrong here

    Firewall and virtual network rules restrict network access to the storage account, but they do not log access attempts. They are preventive controls, not detective controls. Enabling them would not provide the detailed audit logs required for compliance. They are part of a defense-in-depth strategy but do not satisfy the logging requirement.

  • ✗

    Azure Defender for Storage

    Why it's wrong here

    Azure Defender for Storage provides threat detection and security alerts for anomalous access patterns, but it does not provide a complete audit log of all access attempts. It is a security monitoring tool, not an auditing solution. While it can complement auditing, it does not fulfill the requirement to log every access attempt for compliance.

  • ✓

    Azure Monitor diagnostic settings for the storage account

    Why this is correct

    Azure Monitor diagnostic settings allow you to stream resource logs from the storage account to destinations like Log Analytics, Event Hubs, or a storage account. For Data Lake Storage Gen2, these logs include detailed information about read, write, and delete operations, including the identity of the requester. This meets the requirement for auditing access attempts.

  • ✗

    Azure Storage analytics logging

    Why it's wrong here

    Storage analytics logging is a legacy feature that provides logging for Blob, Queue, and Table storage, but it is not designed for hierarchical namespace operations in Data Lake Storage Gen2. It does not capture fine-grained access details for directories and files, and it has been largely superseded by Azure Monitor diagnostic settings.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.