DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You need to ensure that data stored in Azure Data Lake Storage Gen2 is encrypted at rest using customer-managed keys. Which Azure service should you use to manage the keys?
⚠ Common exam trap
DP-203 often tests the distinction between key management (Key Vault) and governance (Purview); candidates who pick Purview confuse data cataloging with encryption key storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Key Vault
Azure Key Vault is the service used to store and manage customer-managed keys (CMK) for Azure Storage encryption at rest. You create a key in Key Vault (or Managed HSM) and configure the storage account to use that key via the encryption settings, enabling CMK.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Key Vault
Why this is correct
Azure Key Vault stores and controls the customer-managed keys used by Data Lake Storage Gen2 server-side encryption. It provides the key management plane the scenario requires, letting you supply and rotate your own keys rather than relying on Microsoft-managed keys.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview catalogues, classifies and governs data assets; it does not store or manage the encryption keys used for storage accounts. It is tempting because it addresses data security and compliance broadly, but customer-managed keys for Data Lake Storage Gen2 must reside in Azure Key Vault.
- ✗
Azure Confidential Computing
Why it's wrong here
Azure Confidential Computing protects data in use within hardware-based trusted execution environments; it does not hold the customer-managed keys that encrypt Data Lake Storage Gen2 at rest. It is tempting when the workload requires enclave-protected processing, but key storage and rotation belong in Azure Key Vault.
- ✗
Microsoft Entra ID
Why it's wrong here
Microsoft Entra ID handles identity, authentication and access tokens, not cryptographic key material, so it cannot store or wrap the keys encrypting Data Lake Gen2 data. It is tempting because it governs access to storage accounts, and would be the right choice for controlling who may read the data, not for managing encryption keys.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.