DP-900 RBAC Scope Practice Question
A retail company uses Azure Data Lake Storage Gen2 as a data lake and Azure Databricks for ETL. They notice that a Spark job reading Parquet files from the data lake fails with an 'Access Denied' error when the job runs as a service principal. The service principal has Storage Blob Data Contributor role on the storage account. What is the most likely cause?
⚠ Common exam trap
Candidates may incorrectly believe that ADLS Gen2 RBAC roles must be assigned at the container level and are not inherited from the storage account. In reality, Azure RBAC assignments at the storage account scope apply to all containers. When a service principal already has Storage Blob Data Contributor at the account level, an 'Access Denied' error is more likely caused by network/firewall restrictions blocking the Databricks cluster.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The storage account has a firewall enabled that blocks the Databricks cluster IP.
Azure RBAC role assignments are inherited down the resource hierarchy. If a service principal has Storage Blob Data Contributor at the storage account scope, that permission applies to all containers (file systems) in the account, including access through the ADLS Gen2 DFS endpoint (dfs.core.windows.net). Therefore, the account-level assignment in the scenario would not by itself cause an 'Access Denied' error. The most likely cause is that the storage account firewall or network restrictions are blocking the Databricks cluster's IP address, which produces an access/authorization failure when the Spark job attempts to read the Parquet files. Storage Blob Data Owner is not required, and the role does not need to be re-assigned at the container level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The service principal needs the Storage Blob Data Owner role instead.
Why it's wrong here
Incorrect. Storage Blob Data Owner is an elevated role that includes full access, but Data Contributor is sufficient if assigned at the correct scope. The issue is not the role level but the scope of the assignment.
- ✗
The service principal lacks the necessary permissions on the Data Lake Storage Gen2 endpoint (dfs.core.windows.net).
Why it's wrong here
Misleading. The Storage Blob Data Contributor role, when assigned at the storage account level, does grant access to both the blob and DFS endpoints. The 'Access Denied' error in this scenario is not due to a separate permission on the DFS endpoint but rather the role not being propagated to the container level.
- ✓
The storage account has a firewall enabled that blocks the Databricks cluster IP.
Why this is correct
Incorrect. A firewall would block all traffic from the Databricks cluster IP, but the error message 'Access Denied' typically indicates an authentication/authorization issue rather than a network block. Moreover, the error is specific to the service principal, not a general connection failure.
- ✗
The service principal does not have the Storage Blob Data Contributor role assigned at the container level.
Why it's wrong here
Correct. Azure Data Lake Storage Gen2 requires RBAC roles to be assigned at the container level (or via ACLs) for the hierarchical namespace. The service principal likely has the Storage Blob Data Contributor role at the storage account level but not at the specific container where the Parquet files reside, leading to the 'Access Denied' error.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Databricks Notebooks and Clusters
Key term
Data lake
A data lake is a centralized storage repository that holds vast amounts of raw data in its native format until it is needed for analysis.
Key term
Data Lake Storage Gen2
Data Lake Storage Gen2 is a cloud-based storage service that combines a scalable data lake with enterprise-grade file system capabilities for big data analytics.
About these practice questions
Courseiva writes every DP-900 question from scratch — 851 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-900 exam.