DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Your organization uses Azure Purview for data governance. You need to automatically scan an Azure Data Lake Storage Gen2 account and classify sensitive data such as credit card numbers and social security numbers. What should you configure?
⚠ Common exam trap
DP-203 often tests the confusion between data governance tools (Purview) and security tools (Defender for Cloud, Azure Policy), so candidates must know that Purview is the service for data classification and scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A new scan rule set in Purview with classification rules for sensitive data types
In Azure Purview, to automatically scan and classify sensitive data, you create a scan rule set that includes classification rules for the specific sensitive data types (e.g., credit card numbers, SSNs). The scan rule set is applied to the scan of the Azure Data Lake Storage Gen2 account, and Purview uses built-in or custom classification rules to identify and tag sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Information Protection (AIP) scanner
Why it's wrong here
The AIP scanner discovers and labels files on on-premises file shares and SharePoint, not Azure Data Lake Storage Gen2, and it does not feed Purview's classification catalogue. AIP suits labelling sensitive on-premises content; Purview's own scan rulesets classify credit card and SSN patterns in ADLS Gen2.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Defender for Cloud assesses security posture and raises alerts across Azure resources; it does not run Purview scans or write classifications into the Purview data map. It suits threat detection and regulatory compliance dashboards, whereas Purview scanning is required to classify sensitive data in ADLS Gen2.
- ✓
A new scan rule set in Purview with classification rules for sensitive data types
Why this is correct
Purview scan rule sets bind classification rules to a scan, so credit card and social security patterns are detected and labelled during the Data Lake Storage Gen2 scan. Without a rule set, the scan runs only system classifications, so the required sensitive data types would not be identified.
- ✗
Azure Policy with built-in guest configuration
Why it's wrong here
Azure Policy with guest configuration audits settings inside virtual machines against compliance rules; it neither reads ADLS Gen2 file contents nor applies Purview sensitive-information types. It suits VM configuration drift enforcement, while Purview scan rulesets detect credit card and SSN patterns in storage.
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.