Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You use Azure Data Lake Storage Gen2 with a hierarchical namespace. You need to delegate permissions to a group of data scientists so they can create folders and upload files only within a specific directory path. What is the best way to achieve this?

⚠ Common exam trap

Many exam-takers confuse SAS tokens with ACLs. Many candidates think SAS is the go-to for granular access, but in ADLS Gen2 with hierarchical namespace, ACLs are the native and recommended method for directory-level permissions. Also, some might choose the broad role assignment for simplicity, ignoring the least privilege requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set ACL entries on the specific directory path granting read, write, and execute permissions to the users.

Azure Data Lake Storage Gen2 with hierarchical namespace supports POSIX-like ACLs at the directory and file level. To delegate permissions to a group of data scientists so they can create folders and upload files only within a specific directory path, you set ACL entries on that directory granting the necessary permissions (read, write, execute) to the group. This allows granular access control without granting broader permissions at the storage account level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a stored access policy to grant permissions to the directory.

    Why it's wrong here

    A stored access policy is defined on a container and scopes permissions to that container or its blobs; it cannot grant directory-level access within a hierarchical namespace. POSIX access control lists on the directory path are required. Stored access policies suit time-bound container-scoped SAS revocation, not per-directory delegation.

  • ✓

    Set ACL entries on the specific directory path granting read, write, and execute permissions to the users.

    Why this is correct

    POSIX ACLs on the target directory grant read, write and execute to the scientists, scoping access to that path only. This satisfies the constraint of limiting folder creation and uploads to a specific directory, which RBAC roles cannot do at path level.

  • ✗

    Generate a shared access signature (SAS) with permissions scoped to the specific directory.

    Why it's wrong here

    A SAS grants access to a container or blob path, but Data Lake Storage Gen2 directory-level authorisation for creating folders and uploading files relies on POSIX access control lists. SAS tokens bypass ACL evaluation and cannot express directory-scoped permissions. SAS would be correct for time-limited delegated access to a container.

  • ✗

    Assign the Storage Blob Data Contributor role to the users at the storage account level.

    Why it's wrong here

    The Storage Blob Data Contributor role is an RBAC role that, when assigned at the storage account level, grants permissions to the entire storage account or container, which is too broad for the requirement of restricting to a specific directory path.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on DP-203

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Azure Data Lake Storage Gen2 with hierarchical namespace enabled. You need to grant a service principal read and write access to a specific directory without granting access to the parent directories. What should you use?

hard
  • A.Assign the Storage Blob Data Contributor role at the directory level using RBAC.
  • B.Use a managed identity and assign it to the directory.
  • C.Create a stored access policy on the directory.
  • ✓ D.Set ACLs on the directory with default ACLs for the service principal.

Why D: Azure RBAC roles for Azure Storage cannot be scoped to a directory or file; they are assigned at the storage account or container level. To grant a service principal read and write access to a specific directory in an Azure Data Lake Storage Gen2 account with hierarchical namespace enabled, use access control lists (ACLs) on that directory. Default ACLs on the directory will be inherited by newly created child items. Option A is incorrect because the Storage Blob Data Contributor role cannot be assigned at the directory level. Option B is incorrect because a managed identity is an identity, not a permission mechanism. Option C is incorrect because stored access policies are used for shared access signatures (SAS), not for granting directory access.

Variation 2. Your organization uses Azure Data Lake Storage Gen2 with hierarchical namespace enabled. You need to implement a security strategy that allows users to read only specific folders within a container. Which authorization method should you use?

hard
  • A.Storage account shared key
  • B.Azure RBAC roles (e.g., Storage Blob Data Contributor) at the container level
  • C.Shared access signatures (SAS) with folder-level permissions
  • ✓ D.Access control lists (ACLs) on the folder

Why D: ACLs (Access Control Lists) in Azure Data Lake Storage Gen2 can be applied to individual folders, enabling granular read permissions. Option A is incorrect because a storage account shared key grants full access to the entire account. Option B is incorrect because Azure RBAC roles like Storage Blob Data Contributor apply at the container level, affecting all folders within. Option C is incorrect because shared access signatures (SAS) can be scoped to a container or a file, but not to a specific folder within a container.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.