DP-203 Develop data processing Practice Question
Your team runs Azure Data Factory pipelines that must copy files from an on-premises file share to Azure Data Lake Storage Gen2 on a nightly schedule. The on-premises network blocks inbound connections and the data must not be exposed to the public internet. You need to enable connectivity without opening firewall ports. What should you deploy?
⚠ Common exam trap
The trap here is assuming that any private network connection such as a VPN or ExpressRoute also provides the execution host, when the runtime itself is what reads the on-premises file share.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A self-hosted integration runtime installed on a machine in the on-premises network.
A self-hosted integration runtime is installed inside the on-premises network and opens only outbound connections to Azure, so the firewall needs no inbound rules. It executes the copy from the file share and writes to Data Lake Storage Gen2, giving Data Factory a reachable execution host without exposing the internal share to the internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A self-hosted integration runtime installed on a machine in the on-premises network.
Why this is correct
A self-hosted integration runtime runs inside the on-premises network and initiates outbound connections to Azure over HTTPS, so no inbound firewall ports are required. It performs the copy from the file share and transfers data to Data Lake Storage Gen2, satisfying the connectivity and exposure constraints. Data Factory dispatches activities to this runtime rather than reaching the share directly.
- ✗
An Azure ExpressRoute circuit provisioned through a connectivity provider.
Why it's wrong here
ExpressRoute provides private, high-bandwidth connectivity but is a significant network investment and still requires the on-premises edge to permit the circuit traffic. It does not supply the runtime component that reads an SMB file share on behalf of Data Factory, so the copy activity would have no execution host inside the network.
- ✗
An Azure VPN Gateway with a site-to-site connection to the on-premises network.
Why it's wrong here
A site-to-site VPN establishes network-level connectivity but still requires the on-premises firewall to allow outbound and inbound tunnel traffic, and it exposes a broader network path than the copy operation needs. It also does not by itself register a machine that Data Factory can use to read the file share, so the copy activity would lack a reachable runtime.
- ✗
An Azure integration runtime with a managed virtual network enabled.
Why it's wrong here
A managed virtual network integration runtime secures outbound traffic from Azure-side runtimes and supports private endpoints, but it runs in Azure and cannot reach an on-premises file share that blocks inbound connections. It is designed for cloud data stores and managed private endpoints, not for reading SMB shares inside a corporate network.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.