exam questions

Exam DP-203 All Questions

View all questions & answers for the DP-203 exam

Exam DP-203 topic 3 question 6 discussion

Actual exam question from Microsoft's DP-203
Question #: 6
Topic #: 3
[All DP-203 Questions]

You have an Azure Data Factory version 2 (V2) resource named Df1. Df1 contains a linked service.
You have an Azure Key vault named vault1 that contains an encryption key named key1.
You need to encrypt Df1 by using key1.
What should you do first?

  • A. Add a private endpoint connection to vault1.
  • B. Enable Azure role-based access control on vault1.
  • C. Remove the linked service from Df1.
  • D. Create a self-hosted integration runtime.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gnulf69
Highly Voted 2 years, 7 months ago
I believe this is correct, based on the question: What should you do FIRST? A DF needs to be empty to be encrypted: https://docs.microsoft.com/en-us/azure/data-factory/enable-customer-managed-key#post-factory-creation-in-data-factory-ui So FIRST we need to empty the DF - then we can move on.
upvoted 41 times
hanzocuk
1 year, 3 months ago
B!!! Enable Azure RBAC permissions on Key Vault: https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide?tabs=azure-cli
upvoted 1 times
...
...
auwia
Highly Voted 9 months, 3 weeks ago
Selected Answer: C
Correct answer: A customer-managed key can only be configured on an empty data Factory. The data factory can't contain any resources such as linked services, pipelines and data flows. https://learn.microsoft.com/en-us/azure/data-factory/enable-customer-managed-key#post-factory-creation-in-data-factory-ui
upvoted 6 times
...
aca357f
Most Recent 3 months ago
Selected Answer: A
Correct answer should be A. When encrypting Azure Data Factory (ADF) resources using Azure Key Vault (AKV), a private endpoint connection ensures that the communication between the Data Factory and Key Vault happens over a private network rather than a public endpoint. This is required to securely retrieve encryption keys like key1.
upvoted 1 times
...
kkk5566
7 months, 3 weeks ago
Selected Answer: C
is the first step.
upvoted 1 times
...
[Removed]
9 months, 2 weeks ago
Selected Answer: C
Correct
upvoted 1 times
...
vctrhugo
10 months ago
A customer-managed key can only be configured on an empty data Factory. The data factory can't contain any resources such as linked services, pipelines and data flows. https://learn.microsoft.com/en-us/azure/data-factory/enable-customer-managed-key#post-factory-creation-in-data-factory-ui
upvoted 1 times
...
rzeng
1 year, 5 months ago
so you need to encrypt the df, you need to remove the bonded service first , answer is correct
upvoted 1 times
...
Rajashekharc
1 year, 7 months ago
Its C: Your ADF should be empty during encryption process using a KEY
upvoted 3 times
...
Deeksha1234
1 year, 8 months ago
Selected Answer: C
correct answer
upvoted 3 times
...
juanlu46
1 year, 11 months ago
Selected Answer: C
You don't need to enable "RBAC", access policies is a default and more simple way to assign permissions, so B option is not necesary, but it is a requirement to delete the linked services to configure customer-managed key. So the correct answer is C - Delete linked services first. https://docs.microsoft.com/en-us/azure/key-vault/general/assign-access-policy?tabs=azure-portal https://docs.microsoft.com/en-us/azure/data-factory/enable-customer-managed-key#enable-customer-managed-keys
upvoted 1 times
...
ploer
2 years, 2 months ago
Selected Answer: C
Correct. "A customer-managed key can only be configured on an empty data Factory. The data factory can't contain any resources such as linked services, pipelines and data flows."
upvoted 1 times
...
MFR
2 years, 3 months ago
A customer-managed key can only be configured on an empty data Factory. The data factory can’t contain any resources such as linked services, pipelines and data flows. It is recommended to enable customer-managed key right after factory creation. Note: Azure Data Factory encrypts data at rest, including entity definitions and any data cached while runs are in progress. By default, data is encrypted with a randomly generated Microsoft-managed key that is uniquely assigned to your data factory. Reference: https://docs.microsoft.com/en-us/azure/data-factory/enable-customer-managed-key
upvoted 3 times
...
Canary_2021
2 years, 3 months ago
Selected Answer: B
B should be the correct answer. https://docs.microsoft.com/en-us/azure/key-vault/general/rbac-guide?tabs=azure-cli
upvoted 1 times
...
x089797
2 years, 4 months ago
Should it be D? https://docs.microsoft.com/en-us/powershell/module/az.datafactory/new-azdatafactoryv2linkedserviceencryptedcredential?view=azps-7.0.0
upvoted 1 times
...
eoicp
2 years, 5 months ago
I thin k it's B. I recently changed a linked service pwf to key vault. I didn't delete the service and just added the managed Identity access to the vault with all the desired rules.
upvoted 2 times
...
Satschi
2 years, 7 months ago
Isn't B Correct ?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago