Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You need to grant a data analyst read access to a specific folder in an Azure Data Lake Storage Gen2 account. The analyst must not be able to read other folders in the same container. You want to follow the principle of least privilege. What should you use?

⚠ Common exam trap

It's easy for candidates to confuse role-based access control, which is typically scoped at the account or container level, with directory-level POSIX ACLs that can isolate a single folder.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A POSIX access control list (ACL) on the target folder, with the analyst's Microsoft Entra ID identity granted read and execute.

POSIX ACLs in Data Lake Storage Gen2 allow permission entries at the directory and file level, so you can grant an identity read and execute on one folder while leaving sibling folders inaccessible. This is the native mechanism for fine-grained, least-privilege access. Broad role assignments and container-scoped SAS or policies grant access to the whole container and are therefore unsuitable here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Storage Blob Data Contributor role assigned at the storage account scope.

    Why it's wrong here

    The Storage Blob Data Contributor role grants read, write, and delete permissions across the entire storage account. Assigning it at the account scope gives the analyst far more access than required, including the ability to modify or delete data in other folders. This directly conflicts with the least privilege requirement in the scenario.

  • ✓

    A POSIX access control list (ACL) on the target folder, with the analyst's Microsoft Entra ID identity granted read and execute.

    Why this is correct

    Data Lake Storage Gen2 supports POSIX-style ACLs at the directory and file level. Granting the analyst's Microsoft Entra ID identity read and execute on the specific folder, without granting permissions on the parent or sibling folders, enforces least privilege. Execute permission on the parent directories is needed for traversal, but it does not grant read access to their contents.

  • ✗

    A storage account shared access signature scoped to the container.

    Why it's wrong here

    A container-scoped SAS grants access to the entire container, which exceeds the analyst's need and violates least privilege. While a SAS can be scoped to a specific blob or directory path in some cases, a container-level SAS would expose all folders. The scenario requires access limited to one folder, so this is too broad.

  • ✗

    A stored access policy on the container that allows read operations.

    Why it's wrong here

    Stored access policies are used with service or account SAS to manage their lifetimes and permissions, and they apply at the container level. They cannot restrict access to a single folder within a container. Using one here would still allow the analyst to read all blobs in the container, which is broader than the required scope.

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.