Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You store sensitive data in Azure Data Lake Storage Gen2. You need to ensure that only members of a specific security group can read the data, while other users in the organization must not have access, even if they have the Storage Blob Data Reader role at the storage account level. What should you use?

⚠ Common exam trap

The trap here is assuming that account-level RBAC roles or network controls like Private Link can restrict access to a specific group, when only POSIX-style ACLs on directories or files provide that granularity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access control lists (ACLs) on the directory or file, with entries for the security group and a mask.

Access control lists in Azure Data Lake Storage Gen2 provide file and directory-level permissions that can be assigned to Microsoft Entra ID security groups. By granting read access to the specific group and using a mask, you ensure that only group members can read the data. RBAC roles at the account level are too broad and cannot restrict access to a subset of users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Private Link with a private endpoint for the storage account.

    Why it's wrong here

    Azure Private Link restricts network access to the storage account but does not control which users can read data. Anyone with network access and appropriate credentials or roles could still read the data. It is a network isolation feature, not an identity-based authorization mechanism, so it does not satisfy the group-based access requirement.

  • ✓

    Access control lists (ACLs) on the directory or file, with entries for the security group and a mask.

    Why this is correct

    ACLs in Azure Data Lake Storage Gen2 allow you to grant permissions to specific Microsoft Entra ID security groups at the directory or file level. By setting an ACL entry for the group and a mask, you can ensure that only members of that group have read access, even if others have broader RBAC roles. ACLs are evaluated together with RBAC to determine effective permissions.

  • ✗

    Shared access signatures (SAS) scoped to the container.

    Why it's wrong here

    A SAS token grants access to anyone who possesses it, regardless of their identity or group membership. It cannot enforce that only a specific security group can read the data. SAS tokens are also shared secrets, which increases the risk of unintended access if leaked. This approach does not meet the requirement for group-based access control.

  • ✗

    Azure role-based access control (RBAC) at the storage account level.

    Why it's wrong here

    Storage account-level RBAC roles such as Storage Blob Data Reader grant access to all containers in the account to anyone assigned the role. It cannot restrict access to only a specific security group while denying others who also have the role. To achieve finer-grained control, you need ACLs at the file or directory level, not just account-level RBAC.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.