DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Your organization needs to ensure that all data stored in Azure Data Lake Storage Gen2 is encrypted at rest using Microsoft-managed keys. What is the default encryption method?
⚠ Common exam trap
DP-203 often tests the default encryption method for storage services, and candidates may confuse TDE (for databases) or client-side encryption with the default SSE, leading to incorrect answers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Storage Service Encryption (SSE) with Microsoft-managed keys.
Azure Data Lake Storage Gen2 is built on Azure Blob Storage, which automatically encrypts all data at rest using Storage Service Encryption (SSE) with Microsoft-managed keys by default. This encryption is always enabled and cannot be disabled. Microsoft-managed keys are used unless you choose to use customer-managed keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Storage Service Encryption (SSE) with Microsoft-managed keys.
Why this is correct
Storage Service Encryption is enabled by default on every Azure Data Lake Storage Gen2 account, encrypting data at rest with Microsoft-managed keys automatically. No configuration is required, satisfying the requirement for Microsoft-managed key encryption without customer key setup.
- ✗
Transparent Data Encryption (TDE) on the storage account.
Why it's wrong here
TDE encrypts data and log files inside Azure SQL Database, Synapse and SQL Managed Instance, not Data Lake Storage Gen2 blobs. Storage accounts already apply AES-256 encryption at rest automatically with Microsoft-managed keys, which is the default this scenario requires.
- ✗
Client-side encryption with keys stored in Azure Key Vault.
Why it's wrong here
Client-side encryption means the application encrypts data before uploading, with keys held in Azure Key Vault; Microsoft then cannot decrypt it. The scenario specifies Microsoft-managed keys, so service-side storage encryption is required instead of customer-controlled client-side encryption.
- ✗
Azure Disk Encryption on the storage nodes.
Why it's wrong here
Azure Disk Encryption uses BitLocker or DM-Crypt to encrypt OS and data disks attached to VMs, protecting the virtual hard disks rather than objects in a storage account. Data Lake Storage Gen2 blobs are encrypted at rest by the storage service itself, not through disk-level encryption.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.