DP-900 Practice Question: Describe considerations for working with non-relational data on Azure
Which THREE of the following are features of Azure Data Lake Storage Gen2?
⚠ Common exam trap
DP-900 often tests the confusion between general Azure Storage features (GRS, LRS) and ADLS Gen2-specific capabilities — candidates pick GRS thinking it is a data-lake feature when it is just a redundancy option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integration with Microsoft Entra ID (Microsoft Entra ID)
Option A is correct because Azure Data Lake Storage Gen2 is built on Azure Blob Storage and integrates natively with Microsoft Entra ID (Microsoft Entra ID) for identity-based authentication and role-based access control (RBAC), allowing fine-grained authorization at the storage account, container, and file level. Option C is correct because ADLS Gen2 supports POSIX-style access control lists (ACLs) on directories and files, enabling granular read/write/execute permissions for users and groups in addition to RBAC role assignments. Option D is correct because ADLS Gen2 provides atomic directory rename operations, a hierarchical namespace capability that lets a directory be renamed in a single metadata operation rather than copying and deleting each blob, which is essential for big-data analytics workloads. Option B is not a distinguishing feature of ADLS Gen2 because geo-redundant storage (GRS) is a general Azure Storage redundancy option available to Blob Storage, Files, Tables, and Queues, not something specific to ADLS Gen2. Option E is incorrect because ADLS Gen2 is object storage with a hierarchical namespace built on Blob Storage, not fixed-size block storage; fixed-size block storage describes services like Azure Managed Disks or Azure NetApp Files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Integration with Microsoft Entra ID (Microsoft Entra ID)
Why this is correct
Integration with Microsoft Entra ID (Microsoft Entra ID) is a hallmark of Azure Data Lake Storage Gen2. It uses Entra ID for OAuth 2.0 authentication, allowing users, service principals, and managed identities to be verified before accessing the storage. Authorization is then layered via Role-Based Access Control (RBAC) at the account/container scope plus POSIX ACLs at the file/directory level, giving a unified identity control plane. This is a native feature of the Data Lake Storage Gen2 account model, not an optional extra.
- ✗
Geo-redundant storage (GRS)
Why it's wrong here
Geo-redundant storage (GRS) is a data-replication setting available to any Azure Storage account, including standard Blob Storage and Data Lake Storage Gen2, so it is not a distinguishing feature. GRS copies data synchronously within a primary region and asynchronously to a secondary region to protect against regional outages, but this redundancy is independent of the hierarchical namespace. Marking it as a Data Lake feature confuses an infrastructure-replication option with the file-system-specific capabilities that make Data Lake Storage Gen2 unique.
- ✓
POSIX-compliant access control lists (ACLs)
Why this is correct
POSIX-compliant access control lists (ACLs) are a core feature of Azure Data Lake Storage Gen2, enabling fine-grained, Unix-style permissions on directories and files. Each object has an owning user, owning group, and a mask, plus ACL entries for named users, groups, and default ACLs inherited by children. Unlike simple blob containers that only support container-level permissions, these ACLs work with the hierarchical namespace to control access down to the file level, which is essential for secure big data analytics.
- ✓
Atomic rename of directories
Why this is correct
Atomic rename of directories is possible in Azure Data Lake Storage Gen2 because the hierarchical namespace stores directory metadata directly, so a rename operation updates the metadata entry in a single transaction. In a flat blob store, renaming a 'directory' would require enumerating and copying every object, then deleting the originals, which is neither atomic nor scalable. The Gen2 design ensures that no client ever sees a partial state during the rename, making this a distinguishing performance and consistency feature.
- ✗
Fixed-size block storage
Why it's wrong here
Fixed-size block storage is not a feature of Azure Data Lake Storage Gen2; it describes a storage-account tier for virtual machine disks (Azure managed disks or page blobs) that is optimized for low-latency I/O. Data Lake Storage Gen2, in contrast, is built on Blob Storage and organizes data using a hierarchical namespace with ACLs and directory semantics, not fixed-size blocks. Additionally, Gen2 blob writes are append- or block-based depending on blob type, but they never rely on fixed-size block allocation as a file-system feature.
Visual reference
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
Learn chapter
Microsoft Fabric Overview
Key term
RBAC
RBAC is a method of restricting network access based on the roles of individual users within an organization, where permissions are assigned to roles rather than to individuals directly.
Key term
Data lake
A data lake is a centralized storage repository that holds vast amounts of raw data in its native format until it is needed for analysis.
About these practice questions
Courseiva writes every DP-900 question from scratch — 851 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-900 exam.