Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

Your company uses Azure Purview for data governance. You need to ensure that sensitive data in Azure Data Lake Storage Gen2 is automatically detected and classified. What should you configure in Purview?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a scan rule set that includes built-in classification rules for sensitive data types.

In Microsoft Purview, you can create scan rule sets that include built-in classification rules to automatically detect sensitive data types during scanning. Option A is incorrect because sensitivity labels are applied after classification, not for detection. Option B is incorrect because Microsoft Defender for Cloud's data sensitivity discovery is a different feature; Purview itself handles classification. Option C is incorrect because Azure Policy enforces compliance rules, not data classification at the file level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply sensitivity labels to the storage account using Microsoft Purview Information Protection.

    Why it's wrong here

    Microsoft Purview Information Protection sensitivity labels are applied manually or via client auto-labelling to documents and emails; they do not scan Data Lake Storage Gen2 or populate the Purview data map. It tempts because both share the Purview brand, but automated classification requires a Purview scan with classification rules.

  • ✗

    Enable Microsoft Defender for Cloud's data sensitivity discovery.

    Why it's wrong here

    Defender for Cloud scans resources for security posture and threat detection; it does not register assets into a Purview collection or apply Purview classification rules. It tempts because it also surfaces sensitive-data findings, but automated classification in Purview requires a scan with a registered data source and a custom or system classification rule set.

  • ✗

    Use Azure Policy to enforce tagging of resources containing sensitive data.

    Why it's wrong here

    Azure Policy enforces resource properties such as tags or allowed SKUs; it cannot inspect file contents in Data Lake Storage Gen2 or assign Purview classifications. It is tempting because tagging sensitive resources sounds like governance, but Purview classification needs a scan using classification rules against a registered data source.

  • ✓

    Create a scan rule set that includes built-in classification rules for sensitive data types.

    Why this is correct

    A scan rule set containing built-in classification rules tells Purview which sensitive data types to detect during scans of Data Lake Storage Gen2. Classification then applies automatically, satisfying the requirement for automatic detection and classification of sensitive data.

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.