Designing an Azure Data Solution Free Sample Questions

12 free sample questions74 in the full practice test Other versions: DP-700(167),DP-203(61)

Try simulator

DP-201 Sample Questions

  1. Question 1

    Your company wants to setup an Azure SQL data warehouse. Data would be loaded weekly from an Azure SQL database instance.

    You have to advise on recommendations based on the following security requirements for the data warehouse:

    • You have to ensure data engineers can only connect from their on-premise workstations

    • You have to ensure the right authentication and authorization measures are put in place

    • You have to ensure the data is encrypted at rest

    Which of the following would you recommend for the requirement?

    “You have to ensure the data is encrypted at rest”

    Answer and explanation

    Correct answer: B

    Explanation:
    You can use Transparent Data Encryption to encrypt the data at rest The Microsoft documentation mentions the following:
    Encryption
    Azure SQL Data Warehouse Transparent Data Encryption (TDE) helps protect against the threat of malicious activity by encrypting and decrypting your data at rest. When you encrypt your database, associated backups and transaction log files are encrypted without requiring any changes to your applications. TDE encrypts the storage of an entire database by using a symmetric key called the database encryption key.
    In SQL Database, the database encryption key is protected by a built-in server certificate. The built-in server certificate is unique for each SQL Database server. Microsoft automatically rotates these certificates at least every 90 days. The encryption algorithm used by SQL Data Warehouse is AES-256. For a general description of TDE, see Transparent Data Encryption.
    You can encrypt your database using the Azure portal or T-SQL.
    Since this is clearly mentioned in the Microsoft documentation, all other options are incorrect -- Reference:
    https://docs.microsoft.com/en-us/azure/sql-data-warehouse/sql-data-warehouse-overview- manage-security

  2. Question 2

    A company has an Azure Data Lake Storage Gen 2 account that is used to store data used by data engineers. The data engineers would query the data by using notebooks from Azure Databricks. The folders in the Data Lake storage account would be secured by ensuring that users only have access for the folders they require.

    Which of the following would you use as the authentication method for Azure Databricks?

    Answer and explanation

    Correct answer: C

    Explanation:
    To authenticate, you can use personal access tokens.
    The Microsoft documentation mentions the following:
    Authentication To authenticate and access Databricks REST APIs, you use personal access tokens. Tokens are similar to passwords; you should treat them with care. Tokens expire and can be revoked.
    Requirements
    Token-based authentication is enabled by default for all Azure Databricks accounts launched after January 2018. If it is disabled, your administrator must enable it before you can perform the tasks described in this article. See Enable Token-based Authentication.
    Since this is clearly mentioned in the Microsoft documentation, all other options are incorrect -- Reference:
    https://docs.microsoft.com/en-us/azure/databricks/dev-tools/api/latest/authentication

  3. Question 3

    A company has an Azure Data Lake Storage Gen 2 account that is used to store data used by data engineers. The data engineers would query the data by using notebooks from Azure databricks. The folders in the Data Lake storage account would be secured by ensuring that users only have access for the folders they require.

    Which of the following would you use as the authentication method for Data Lake storage?

    Answer and explanation

    Correct answer: A

    Explanation:
    You can authenticate to Azure Data Lake from Azure Databricks using Azure AD credentials The Microsoft documentation mentions the following: Authenticate to Azure Data Lake Storage using Azure Active Directory Credentials You can authenticate automatically to Azure Data Lake Storage Gen1 and Azure Data Lake Storage Gen2 from Azure Databricks clusters using the same Azure Active Directory (Azure AD) identity that you use to log into Azure Databricks. When you enable your cluster for Azure Data Lake Storage credential passthrough, commands that you run on that cluster can read and write data in Azure Data Lake Storage without requiring you to configure service principal credentials for access to storage.
    Since this is clearly mentioned in the Microsoft documentation, all other options are incorrect -- Reference:
    https://docs.microsoft.com/en-us/azure/databricks/data/data-sources/azure/adls-passthrough

  4. Question 4

    A company is planning on setting up an Azure SQL database. The database will be used to store sensitive data. Below are the requirements for the data store:

    • Only the application accessing the data can perform the encryption

    • The client application must have the access keys for encrypting and decrypting the data

    • The data must not appear in plaintext in the database

    • The strongest encryption method must be used on the database

    • The application should be able to search on select data values

    Which of the following would you use as the encryption method for Searchable data?

    Answer and explanation

    Correct answer: B

    Explanation:
    The strongest encryption technique is to use Always Encrypted. This will encrypt the data at rest.
    If you need to perform a search on the data, you need to use deterministic encryption The Microsoft documentation mentions the following: Selecting Deterministic or Randomized Encryption The Database Engine never operates on plaintext data stored in encrypted columns, but it still supports some queries on encrypted data, depending on the encryption type for the column.
    Always Encrypted supports two types of encryption: randomized encryption and deterministic encryption.
    • Deterministic encryption always generates the same encrypted value for any given plain text value. Using deterministic encryption allows point lookups, equality joins, grouping and indexing on encrypted columns. However, it may also allow unauthorized users to guess information about encrypted values by examining patterns in the encrypted column, especially if there's a small set of possible encrypted values, such as True/False, or North/South/East/West region. Deterministic encryption must use a column collation with a binary2 sort order for character columns. • Randomized encryption uses a method that encrypts data in a less predictable manner.
    Randomized encryption is more secure, but prevents searching, grouping, indexing, and joining on encrypted columns.
    Since this is clearly mentioned in the Microsoft documentation, all other options are incorrect -- Reference:
    https://docs.microsoft.com/en-us/sql/relational-databases/security/encryption/always-encrypted- database-engine?view=sql-server-ver15

  5. Question 5

    A company is planning on setting up an Azure SQL database. The database will be used to store sensitive data. Below are the requirements for the data store:

    • Only the application accessing the data can perform the encryption

    • The client application must have the access keys for encrypting and decrypting the data

    • The data must not appear in plaintext in the database

    • The strongest encryption method must be used on the database

    • The application should be able to search on select data values

    Which of the following would you use as the encryption method for Non-Searchable data?

    Answer and explanation

    Correct answer: A

    Explanation:
    The strongest encryption technique is to use Always Encrypted. This will encrypt the data at rest.
    For non-searchable data, you can make use of randomized encryption for the strongest possible encryption:
    Selecting Deterministic or Randomized Encryption The Database Engine never operates on plaintext data stored in encrypted columns, but it still supports some queries on encrypted data, depending on the encryption type for the column.
    Always Encrypted supports two types of encryption: randomized encryption and deterministic encryption.
    • Deterministic encryption always generates the same encrypted value for any given plain text value. Using deterministic encryption allows point lookups, equality joins, grouping and indexing on encrypted columns. However, it may also allow unauthorized users to guess information about encrypted values by examining patterns in the encrypted column, especially if there's a small set of possible encrypted values, such as True/False, or North/South/East/West region. Deterministic encryption must use a column collation with a binary2 sort order for character columns. • Randomized encryption uses a method that encrypts data in a less predictable manner.
    Randomized encryption is more secure, but prevents searching, grouping, indexing, and joining on encrypted columns.
    Since this is clearly mentioned in the Microsoft documentation, all other options are incorrect -- Reference: https://docs.microsoft.com/en-us/sql/relational-databases/security/encryption/always-encrypted- database-engine?view=sql-server-ver15

  6. Question 6

    A company is planning on building a solution that would contain the below layers:

    You have to decide on which services will be used for each layer.

    Which of the following would you choose as the service to use Service A?

    Question 6 image
    Answer and explanation

    Correct answer: B

    B

Register free to unlock 6 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 302 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon