DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Your organization uses Azure Data Lake Storage Gen2 with hierarchical namespace enabled. You need to implement a monitoring strategy to detect and alert on unusual access patterns that could indicate a security breach. Which THREE services or features should you use? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Defender for Storage to get security alerts about unusual access patterns.
Options A, C, and D are correct. A: Microsoft Defender for Storage provides security alerts for unusual access patterns. C: Ingesting logs into Microsoft Sentinel allows creation of analytics rules to detect anomalous patterns. D: Diagnostic settings on the storage account collect read, write, and delete logs necessary for analysis. Option B is incorrect because Azure Policy is used for governance and enforcement of policies, not for monitoring access patterns. Option E is incorrect because Azure Monitor Metrics track transaction counts and latency but do not include detailed access logs required for detecting unusual patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Microsoft Defender for Storage to get security alerts about unusual access patterns.
Why this is correct
Correct: Defender for Storage provides built-in threat detection for Azure Storage.
- ✗
Apply Azure Policy to enforce encryption and access policies.
Why it's wrong here
Incorrect: Azure Policy is for compliance and governance, not real-time monitoring or alerting.
- ✓
Ingest the logs into Microsoft Sentinel and create analytics rules for anomalous patterns.
Why this is correct
Correct: Microsoft Sentinel can analyze logs and generate alerts for suspicious activities.
- ✓
Enable diagnostic settings on the storage account to collect read, write, and delete logs.
Why this is correct
Correct: Diagnostic logs capture access operations and can be sent to Log Analytics for analysis.
- ✗
Use Azure Monitor Metrics to track storage account transactions and latency.
Why it's wrong here
Incorrect: Metrics are aggregated and do not provide per-request or user-level details needed for anomaly detection.
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 760-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.