DP-900 Practice Question: Describe considerations for working with non-relational data on Azure
Exhibit
{
"dataLakeStoreGen2": {
"hierarchicalNamespace": {
"enabled": true
}
},
"encryption": {
"keySource": "Microsoft.Storage"
}
}Refer to the exhibit. You are reviewing an ARM template snippet for an Azure storage account. You need to ensure that the storage account supports POSIX-like permissions for data lake workloads. Which property must be enabled?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
"hierarchicalNamespace": {"enabled": true}
The correct option is B, "hierarchicalNamespace": {"enabled": true}, because enabling a hierarchical namespace on an Azure Storage account is what upgrades it to Data Lake Storage Gen2 capabilities, including POSIX-like access control lists (ACLs) and directory-level permissions required for data lake workloads. Without this property set to enabled, the account remains a flat Blob Storage namespace and cannot apply POSIX-style permissions. Option A (allowBlobPublicAccess: false) only restricts anonymous public read access and has no bearing on POSIX permissions. Option C (kind: DataLakeStorageGen2) is not a valid value for the kind property in ARM templates; the valid kind is StorageV2 (or BlockBlobStorage/BlobStorage/FileStorage), and Data Lake behavior is enabled via the hierarchical namespace flag. Option D (keySource: Microsoft.Storage) only specifies that encryption keys are managed by Microsoft, which is unrelated to POSIX-like permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
"allowBlobPublicAccess": false
Why it's wrong here
This controls public access, not POSIX permissions.
- ✓
"hierarchicalNamespace": {"enabled": true}
Why this is correct
Enabling hierarchicalNamespace converts the storage account to Data Lake Storage Gen2, which replaces flat blob naming with a true directory hierarchy. Only this namespace structure supports POSIX-style access control lists (ACLs) at file and directory level, satisfying the stem's data lake permission requirement.
- ✗
"kind": "DataLakeStorageGen2"
Why it's wrong here
The kind property selects the account type, not hierarchical namespace; POSIX-like ACLs require isHnsEnabled set to true. It is tempting because DataLakeStorageGen2 is the account kind associated with data lake workloads, so it appears to be the enabling switch, yet it alone grants no POSIX permissions.
- ✗
"keySource": "Microsoft.Storage"
Why it's wrong here
keySource selects the encryption key management mode, such as Microsoft-managed versus Key Vault keys; it does not enable hierarchical namespace or POSIX ACLs. It is tempting because encryption configuration appears in every storage template and would be the right property when the requirement concerns customer-managed keys.
Visual reference
Go deeper
Related to this question
Learn chapter
Microsoft Purview Data Map and Scanning
Key term
Data lake
A data lake is a centralized storage repository that holds vast amounts of raw data in its native format until it is needed for analysis.
Key term
Azure Storage
Azure Storage is Microsoft's cloud-based service for storing data like files, messages, and backups with high durability and scalability.
About these practice questions
Courseiva writes every DP-900 question from scratch — 851 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-900 exam.