Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

Your Azure Data Lake Storage Gen2 account stores sensitive customer data. You need to ensure that data is encrypted at rest using customer-managed keys (CMK) and that access to the encryption key is logged. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure customer-managed keys in Azure Key Vault and enable Key Vault diagnostics logging.

Customer-managed keys (CMK) stored in Azure Key Vault allow you to control and audit key usage, and enabling Key Vault diagnostics logging captures access events. Option A is incorrect because infrastructure encryption uses platform-managed keys. Option B is incorrect because double encryption adds a second layer but does not directly provide logging of key access. Option D is incorrect because SSE with platform-managed keys does not give customer control or logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable infrastructure encryption on the storage account.

    Why it's wrong here

    Infrastructure encryption applies a second platform-managed layer beneath the existing key; it does not let you supply a customer-managed key or log key access. It is genuinely for defence-in-depth against compromised platform keys, and would be right when the requirement is double encryption rather than key custody.

  • ✗

    Enable double encryption using both platform-managed and customer-managed keys.

    Why it's wrong here

    Double encryption combines platform-managed and customer-managed keys, but the platform layer is Microsoft-controlled, and the requirement is specifically CMK with key-access logging. It is genuinely for layered protection against key compromise, and would be right when the requirement is two independent encryption layers.

  • ✓

    Configure customer-managed keys in Azure Key Vault and enable Key Vault diagnostics logging.

    Why this is correct

    Customer-managed keys stored in Azure Key Vault replace Microsoft-managed keys for encryption at rest, and Key Vault diagnostic logging records every key operation. This satisfies both the CMK requirement and the key-access logging requirement in the stem.

  • ✗

    Use Azure Storage Service Encryption (SSE) with platform-managed keys.

    Why it's wrong here

    Platform-managed keys are generated and rotated by Microsoft, so you cannot supply or control your own key material, and key-access auditing against your own key vault is impossible. SSE with platform-managed keys suits workloads with no regulatory key-ownership requirement; customer-managed keys in Azure Key Vault are needed here.

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DP-203

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO actions should you take to secure sensitive data in Azure Data Lake Storage Gen2? (Choose two.)

medium
  • A.Enable public network access from all networks for ease of use
  • ✓ B.Use access control lists (ACLs) to restrict access to specific directories
  • C.Allow anonymous access to enable sharing
  • D.Disable soft delete to prevent accidental retention of deleted data
  • ✓ E.Enable encryption at rest using customer-managed keys in Azure Key Vault

Why B: Option B is correct because Azure Data Lake Storage Gen2 supports POSIX-style access control lists (ACLs) that let you grant or deny read/write/execute permissions at the directory and file level, which is essential for least-privilege access to sensitive data. Option E is correct because enabling encryption at rest with customer-managed keys stored in Azure Key Vault gives you control over the key lifecycle and satisfies compliance requirements for protecting sensitive data at rest. Option A is wrong because enabling public network access from all networks exposes the storage account to the internet and increases attack surface. Option C is wrong because allowing anonymous access permits unauthenticated reads and is a security risk, not a protection measure. Option D is wrong because disabling soft delete removes a recovery safeguard and does nothing to secure sensitive data.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.