Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

Your organization uses Azure Data Lake Storage Gen2 with hierarchical namespace enabled. You need to implement a monitoring strategy to detect and alert on unusual access patterns that could indicate a security breach. Which THREE services or features should you use? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Defender for Storage to get security alerts about unusual access patterns.

Option A is correct because Microsoft Defender for Storage analyzes data-plane telemetry on the storage account and raises security alerts for suspicious activity such as unusual access patterns, anomalous data exfiltration, or access from unusual locations, which directly addresses breach detection. Option C is correct because Microsoft Sentinel can ingest storage logs and use analytics rules (including built-in anomaly and threat-detection templates) to correlate events and alert on anomalous access patterns across the environment. Option D is correct because enabling diagnostic settings on the storage account is the prerequisite that exports read, write, and delete data-plane logs (the StorageRead/StorageWrite/StorageDelete categories) to a Log Analytics workspace, Event Hub, or storage account, providing the raw telemetry that Sentinel and Defender for Storage rely on for anomaly detection. Option B does not belong because Azure Policy enforces configuration and compliance (for example, requiring encryption or HTTPS), but it does not detect or alert on unusual access patterns. Option E does not belong because Azure Monitor Metrics provides aggregate numeric time-series data such as transaction counts, latency, and availability, not per-request access detail needed to identify anomalous access patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Microsoft Defender for Storage to get security alerts about unusual access patterns.

    Why this is correct

    Microsoft Defender for Storage continuously analyses data-plane telemetry and raises security alerts for anomalous access, such as unusual locations or suspicious enumeration. This directly satisfies the requirement to detect and alert on access patterns indicating a possible breach in the hierarchical-namespace account.

  • ✗

    Apply Azure Policy to enforce encryption and access policies.

    Why it's wrong here

    Azure Policy enforces configuration such as encryption and access settings at deployment; it audits compliance rather than detecting anomalous runtime access. It is tempting because it governs access controls, but breach detection needs activity logging and alerting on actual data-plane operations.

  • ✓

    Ingest the logs into Microsoft Sentinel and create analytics rules for anomalous patterns.

    Why this is correct

    Microsoft Sentinel ingests storage diagnostic logs and applies analytics rules and machine learning to surface anomalous access patterns, generating alerts and incidents. This satisfies the requirement to detect unusual access indicative of a breach, rather than merely retaining logs for later manual review.

  • ✓

    Enable diagnostic settings on the storage account to collect read, write, and delete logs.

    Why this is correct

    Diagnostic settings stream read, write and delete logs from the storage account to a destination such as Log Analytics or a storage account. This supplies the access telemetry that anomaly detection depends on, satisfying the requirement to capture the data needed to identify unusual access patterns.

  • ✗

    Use Azure Monitor Metrics to track storage account transactions and latency.

    Why it's wrong here

    Azure Monitor Metrics captures aggregate transaction counts and latency, not per-identity access patterns, so it cannot flag anomalous reads. It is tempting because metrics underpin alerting generally, but detecting unusual access requires diagnostic logs and Microsoft Entra ID sign-in analysis instead.

About these practice questions

This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.