DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You store sensitive data in Azure Data Lake Storage Gen2. You need to ensure that only members of a specific security group can read the data, while other users in the organization must not have access, even if they have the Storage Blob Data Reader role at the storage account level. What should you use?
⚠ Common exam trap
The trap here is assuming that account-level RBAC roles or network controls like Private Link can restrict access to a specific group, when only POSIX-style ACLs on directories or files provide that granularity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access control lists (ACLs) on the directory or file, with entries for the security group and a mask.
Access control lists in Azure Data Lake Storage Gen2 provide file and directory-level permissions that can be assigned to Microsoft Entra ID security groups. By granting read access to the specific group and using a mask, you ensure that only group members can read the data. RBAC roles at the account level are too broad and cannot restrict access to a subset of users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Private Link with a private endpoint for the storage account.
Why it's wrong here
Azure Private Link restricts network access to the storage account but does not control which users can read data. Anyone with network access and appropriate credentials or roles could still read the data. It is a network isolation feature, not an identity-based authorization mechanism, so it does not satisfy the group-based access requirement.
- ✓
Access control lists (ACLs) on the directory or file, with entries for the security group and a mask.
Why this is correct
ACLs in Azure Data Lake Storage Gen2 allow you to grant permissions to specific Microsoft Entra ID security groups at the directory or file level. By setting an ACL entry for the group and a mask, you can ensure that only members of that group have read access, even if others have broader RBAC roles. ACLs are evaluated together with RBAC to determine effective permissions.
- ✗
Shared access signatures (SAS) scoped to the container.
Why it's wrong here
A SAS token grants access to anyone who possesses it, regardless of their identity or group membership. It cannot enforce that only a specific security group can read the data. SAS tokens are also shared secrets, which increases the risk of unintended access if leaked. This approach does not meet the requirement for group-based access control.
- ✗
Azure role-based access control (RBAC) at the storage account level.
Why it's wrong here
Storage account-level RBAC roles such as Storage Blob Data Reader grant access to all containers in the account to anyone assigned the role. It cannot restrict access to only a specific security group while denying others who also have the role. To achieve finer-grained control, you need ACLs at the file or directory level, not just account-level RBAC.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.