Courseiva

DP-900 RBAC Scope Practice Question

A retail company uses Azure Data Lake Storage Gen2 as a data lake and Azure Databricks for ETL. They notice that a Spark job reading Parquet files from the data lake fails with an 'Access Denied' error when the job runs as a service principal. The service principal has Storage Blob Data Contributor role on the storage account. What is the most likely cause?

⚠ Common exam trap

Candidates may incorrectly believe that ADLS Gen2 RBAC roles must be assigned at the container level and are not inherited from the storage account. In reality, Azure RBAC assignments at the storage account scope apply to all containers. When a service principal already has Storage Blob Data Contributor at the account level, an 'Access Denied' error is more likely caused by network/firewall restrictions blocking the Databricks cluster.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The storage account has a firewall enabled that blocks the Databricks cluster IP.

Azure RBAC role assignments are inherited down the resource hierarchy. If a service principal has Storage Blob Data Contributor at the storage account scope, that permission applies to all containers (file systems) in the account, including access through the ADLS Gen2 DFS endpoint (dfs.core.windows.net). Therefore, the account-level assignment in the scenario would not by itself cause an 'Access Denied' error. The most likely cause is that the storage account firewall or network restrictions are blocking the Databricks cluster's IP address, which produces an access/authorization failure when the Spark job attempts to read the Parquet files. Storage Blob Data Owner is not required, and the role does not need to be re-assigned at the container level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The service principal needs the Storage Blob Data Owner role instead.

    Why it's wrong here

    Incorrect. Storage Blob Data Owner is an elevated role that includes full access, but Data Contributor is sufficient if assigned at the correct scope. The issue is not the role level but the scope of the assignment.

  • ✗

    The service principal lacks the necessary permissions on the Data Lake Storage Gen2 endpoint (dfs.core.windows.net).

    Why it's wrong here

    Misleading. The Storage Blob Data Contributor role, when assigned at the storage account level, does grant access to both the blob and DFS endpoints. The 'Access Denied' error in this scenario is not due to a separate permission on the DFS endpoint but rather the role not being propagated to the container level.

  • ✓

    The storage account has a firewall enabled that blocks the Databricks cluster IP.

    Why this is correct

    Incorrect. A firewall would block all traffic from the Databricks cluster IP, but the error message 'Access Denied' typically indicates an authentication/authorization issue rather than a network block. Moreover, the error is specific to the service principal, not a general connection failure.

  • ✗

    The service principal does not have the Storage Blob Data Contributor role assigned at the container level.

    Why it's wrong here

    Correct. Azure Data Lake Storage Gen2 requires RBAC roles to be assigned at the container level (or via ACLs) for the hierarchical namespace. The service principal likely has the Storage Blob Data Contributor role at the storage account level but not at the specific container where the Parquet files reside, leading to the 'Access Denied' error.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every DP-900 question from scratch — 851 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-900 exam.