Courseiva

DP-900 Practice Question: Describe considerations for working with non-relational data on Azure

Exhibit

{
  "dataLakeStoreGen2": {
    "hierarchicalNamespace": {
      "enabled": true
    }
  },
  "encryption": {
    "keySource": "Microsoft.Storage"
  }
}

Refer to the exhibit. You are reviewing an ARM template snippet for an Azure storage account. You need to ensure that the storage account supports POSIX-like permissions for data lake workloads. Which property must be enabled?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

"hierarchicalNamespace": {"enabled": true}

The correct option is B, "hierarchicalNamespace": {"enabled": true}, because enabling a hierarchical namespace on an Azure Storage account is what upgrades it to Data Lake Storage Gen2 capabilities, including POSIX-like access control lists (ACLs) and directory-level permissions required for data lake workloads. Without this property set to enabled, the account remains a flat Blob Storage namespace and cannot apply POSIX-style permissions. Option A (allowBlobPublicAccess: false) only restricts anonymous public read access and has no bearing on POSIX permissions. Option C (kind: DataLakeStorageGen2) is not a valid value for the kind property in ARM templates; the valid kind is StorageV2 (or BlockBlobStorage/BlobStorage/FileStorage), and Data Lake behavior is enabled via the hierarchical namespace flag. Option D (keySource: Microsoft.Storage) only specifies that encryption keys are managed by Microsoft, which is unrelated to POSIX-like permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    "allowBlobPublicAccess": false

    Why it's wrong here

    This controls public access, not POSIX permissions.

  • ✓

    "hierarchicalNamespace": {"enabled": true}

    Why this is correct

    Enabling hierarchicalNamespace converts the storage account to Data Lake Storage Gen2, which replaces flat blob naming with a true directory hierarchy. Only this namespace structure supports POSIX-style access control lists (ACLs) at file and directory level, satisfying the stem's data lake permission requirement.

  • ✗

    "kind": "DataLakeStorageGen2"

    Why it's wrong here

    The kind property selects the account type, not hierarchical namespace; POSIX-like ACLs require isHnsEnabled set to true. It is tempting because DataLakeStorageGen2 is the account kind associated with data lake workloads, so it appears to be the enabling switch, yet it alone grants no POSIX permissions.

  • ✗

    "keySource": "Microsoft.Storage"

    Why it's wrong here

    keySource selects the encryption key management mode, such as Microsoft-managed versus Key Vault keys; it does not enable hierarchical namespace or POSIX ACLs. It is tempting because encryption configuration appears in every storage template and would be the right property when the requirement concerns customer-managed keys.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every DP-900 question from scratch — 851 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-900 exam.