DP-700 sample questions with answers

10 free practice questions for the Microsoft Certified: Fabric Data Engineer Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Implement and manage an analytics solution

Nod Publishers secures dbo.Royalties in a warehouse with a T-SQL security policy that filters rows by author. A data scientist who reads the same table through a OneLake shortcut in her own lakehouse, from a Spark notebook, sees every author's rows. What explains this behavior?

  1. A.

    Spark reads the shortcut through the lakehouse's SQL analytics endpoint, which runs in delegated identity mode by default.

  2. B.

    Security defined with T-SQL in a warehouse is enforced only in the warehouse's SQL engine and is not translated into OneLake security for the shortcut path.

  3. C.

    OneLake-to-OneLake shortcuts always use delegated authentication, so she reads the data as the person who created the shortcut.

  4. D.

    The security policy was created with schema binding, which skips predicate enforcement for reads that come from other items.

Show answer

Answer: B

Warehouse RLS, CLS and object permissions are enforced only in the warehouse's TDS execution context and are not converted into OneLake security, so shortcut and Spark reads bypass them.

  • A. Spark reads OneLake directly and does not go through the SQL analytics endpoint.
  • B. Warehouse T-SQL security applies only in its SQL engine and is not carried into OneLake security for shortcuts.
  • C. Same-tenant OneLake shortcuts default to passthrough; either mode still bypasses warehouse T-SQL security.
  • D. Schema binding governs changes to dependent objects, not which access paths enforce the predicate.
Question 2Implement and manage an analytics solution

Contoso Logistics runs nightly PySpark notebooks in a Fabric workspace that is backed by an F64 capacity. The jobs need memory optimized nodes and must autoscale between 3 and 10 nodes. The starter pool cannot be reconfigured. You need every new notebook and Spark job definition in the workspace to use the required compute by default, with the least administrative effort. What should you do?

  1. A.

    Add a %%configure cell at the top of every notebook that requests the node size and the minimum and maximum number of nodes for the session.

  2. B.

    In the workspace settings, open Data Engineering/Science and create a custom Spark pool with the required node family and autoscale range, then set it as the workspace default pool.

  3. C.

    In the Fabric admin portal, turn off the starter pool for the tenant so that every workload in the capacity falls back to memory optimized nodes that autoscale.

  4. D.

    Create an environment, set Spark properties for driver and executor memory, and attach the environment to each notebook and to each Spark job definition.

Show answer

Answer: B

A custom Spark pool created in the workspace Spark settings and set as the workspace default gives every new notebook and Spark job definition the required node family and autoscale range.

  • A. %%configure affects a single notebook session, so it is repeated work and is not applied to Spark job definitions or pipeline runs.
  • B. A custom pool is the only object that defines node family, node size and autoscale bounds, and the workspace default setting applies it to every item.
  • C. Admin settings only allow or block pool customization; turning off the starter pool creates no pool and selects no node family.
  • D. Spark properties tune the runtime inside existing executors; they cannot change the node family or the autoscale range of the pool.
Question 3Implement and manage an analytics solution

Wide World Importers builds an order application on a SQL database in Fabric. Developers want the database objects tracked as a SQL project in an Azure DevOps repository, and the rows of the lookup table dbo.OrderStatus must be restored automatically whenever the database is updated from Git or deployed. What should they do?

  1. A.

    Connect the workspace to Git, commit the database, and set a MERGE query in Shared Queries as the post-deployment script

  2. B.

    Mirror the SQL database into a mirrored database, then connect the mirrored database to Git and commit it

  3. C.

    Export a .bacpac file of the database every night with a pipeline and commit the file to the Azure DevOps repository after each run

  4. D.

    Create a deployment pipeline and add a data source rule that copies dbo.OrderStatus rows into each stage

Show answer

Answer: A

Committing a SQL database in Fabric to Git turns it into a SQL project, and a post-deployment script in Shared Queries manages static lookup data on every update or deployment.

  • A. Git commit converts the database into a SQL project, and a post-deployment script runs on each update and deployment to restore the lookup rows.
  • B. Mirroring creates a read-only replica for analytics; it doesn't manage the source database's schema in Git.
  • C. A .bacpac is a packaged export, not object-level source code, and it does not run static-data logic on updates.
  • D. Deployment rules swap data sources, parameters or default lakehouses; they never copy table rows.
Question 4Implement and manage an analytics solution

Certification is enabled in Northwind Traders' tenant for the Data-Stewards group. A steward who holds the Contributor role in the Sales-Analytics workspace certifies its lakehouses, notebooks and reports without problems, but the Certified option is unavailable for one item named Sales Overview. What is the most likely cause?

  1. A.

    Certifying an item that another user owns requires the Admin role in the workspace, not the Contributor role.

  2. B.

    Sales Overview carries a sensitivity label, and labeled items can be promoted but never certified.

  3. C.

    A steward must first request certification through the Learn more link before certifying any item herself.

  4. D.

    Sales Overview is a Power BI dashboard, and dashboards are the one item type that cannot be certified.

Show answer

Answer: D

All Fabric and Power BI items can be certified except Power BI dashboards, so the option is missing for a dashboard.

  • A. Certification requires write permission on the item, which Contributors have; Admin is not required.
  • B. The certification requirements are enablement, authorization and write permission; none of them involves sensitivity labels.
  • C. Requesting certification is for unauthorized users; authorized certifiers apply the badge directly.
  • D. Every Fabric and Power BI item except Power BI dashboards can be certified.
Question 5Implement and manage an analytics solution

The security team at Trey Research must record every read of files in the Research workspace's lakehouses that is made through ADLS-compatible APIs or the OneLake file explorer, including the caller's user principal name and access time. The events must land in a lakehouse for analysis. What should you enable?

  1. A.

    SQL audit logs on each lakehouse's SQL analytics endpoint, with the Batch Was Completed action group enabled

  2. B.

    OneLake diagnostics in the workspace's OneLake settings, sending events to a lakehouse on the same capacity

  3. C.

    A Microsoft Purview audit log search that is scheduled to export the Fabric activities of the Research workspace

  4. D.

    Workspace monitoring in the Research workspace, which logs every lakehouse file read to its monitoring Eventhouse

Show answer

Answer: B

OneLake diagnostics streams data access events, including every operation made through the Blob or ADLS APIs, as JSON logs into a lakehouse on the same capacity.

  • A. SQL audit logs capture T-SQL activity on the endpoint, not direct OneLake file access.
  • B. OneLake diagnostics logs every ADLS or Blob API and UI operation, with caller and time, into a same-capacity lakehouse.
  • C. Learn states the Fabric audit log is not a complete source for OneLake data-plane activity.
  • D. Workspace monitoring (preview) collects item operation logs, not OneLake file reads.
Question 6Implement and manage an analytics solution

School of Fine Art plans to switch the SQL analytics endpoint of its Archive-LH lakehouse from delegated identity access mode to User's identity access mode so that OneLake security roles apply to T-SQL queries. Which two consequences should the team plan for? (Choose TWO.)

Choose 2.

  1. A.

    Workspace Contributors become subject to the OneLake security roles defined on Archive-LH.

  2. B.

    Running and queued queries on all SQL analytics endpoints in the workspace are canceled while the mode changes.

  3. C.

    Existing SQL roles on the endpoint are deleted and cannot be recovered.

  4. D.

    SQL GRANT and REVOKE statements on tables continue to control which tables each user can read.

  5. E.

    Users can then insert and update table rows directly through the SQL analytics endpoint.

  6. F.

    Dynamic data masking rules defined on the endpoint start being enforced by OneLake for Spark users.

Show answer

Answer: B, C

Changing the access mode briefly takes every SQL analytics endpoint in the workspace offline and cancels its queries, and switching to user identity mode deletes existing SQL roles permanently.

  • A. Admins, Members and Contributors keep elevated access; OneLake roles target Viewers and Read users.
  • B. A mode change makes every endpoint in the workspace briefly unavailable and cancels running and queued queries.
  • C. Switching to user identity mode deletes existing SQL roles, and they cannot be recovered.
  • D. In user identity mode, table access is governed by OneLake roles; SQL GRANT on tables is not allowed.
  • E. Write operations are not supported through the endpoint in user identity mode.
  • F. DDM is not supported in OneLake security and never applies to Spark reads.
Question 7Implement and manage an analytics solution

Every morning at Wide World Importers, raw files must be copied into a lakehouse, an analyst's Dataflow Gen2 must then cleanse them, and a PySpark notebook must finally build aggregates. Each step must start only after the previous one succeeds, and failures must be retried. How should you orchestrate the three steps?

  1. A.

    Create a pipeline with a Copy activity, a Dataflow activity and a Notebook activity linked by success dependencies, with retries set on each activity.

  2. B.

    Schedule the Copy, the Dataflow Gen2 and the notebook at staggered times 30 minutes apart so that each step has enough time to finish before the next.

  3. C.

    Add a step inside the Dataflow Gen2 that calls the notebook when its queries finish, and schedule the dataflow after the copy.

  4. D.

    Call the Dataflow Gen2 and the copy from the notebook by using notebookutils.notebook.runMultiple() with dependencies.

Show answer

Answer: A

A pipeline chains Copy, Dataflow and Notebook activities with success dependencies and retries, which the other options can't do.

  • A. A pipeline runs each item as an activity, starts the next only on success, and applies per-activity retry settings.
  • B. Staggered schedules don't wait for success; a slow or failed step still lets the next one start on stale data.
  • C. Dataflow Gen2 can't call a notebook; its steps are Power Query transformations.
  • D. runMultiple runs notebooks only; it can't run a Dataflow Gen2 or a Copy activity.
Question 8Implement and manage an analytics solution

Nod Publishers reads the same Amazon S3 files through lakehouse shortcuts in the Books-Analytics workspace dozens of times a day, and AWS egress charges are rising. Most files are between 50 MB and 400 MB and rarely change. You need to reduce egress without copying the data into OneLake with a pipeline. What should you do?

  1. A.

    On the OneLake tab of the workspace settings, turn on shortcut caching and choose a retention period.

  2. B.

    Ask a tenant admin to turn off Users can access data stored in OneLake with apps external to Fabric.

  3. C.

    Recreate each shortcut as an ADLS Gen2 shortcut that points at the same S3 bucket through a gateway.

  4. D.

    On the OneLake tab of the workspace settings, turn on Add diagnostic events to a lakehouse for the workspace.

Show answer

Answer: A

Shortcut caching on the workspace OneLake tab serves repeat reads of S3 shortcut files from a cache, reducing egress.

  • A. Shortcut caching stores files read through S3 shortcuts in a workspace cache and serves repeat reads from it, cutting egress.
  • B. That tenant setting controls external apps reaching OneLake, not how OneLake reads from Amazon S3.
  • C. An ADLS Gen2 shortcut can't target an S3 bucket, and ADLS Gen2 shortcuts aren't cached anyway.
  • D. Diagnostics records who accessed data; it doesn't reduce reads against Amazon S3.
Question 9Implement and manage an analytics solution

Adventure Works needs a visual canvas where engineers chain a Copy activity, a Dataflow Gen2 refresh and a notebook, branch on conditions and loop over lists without writing code. Which Fabric item provides this?

  1. A.

    A Spark job definition with a main definition file

  2. B.

    A Data Factory pipeline

  3. C.

    A Dataflow Gen2 with staging enabled on every query

  4. D.

    A KQL queryset attached to an eventhouse

Show answer

Answer: B

The pipeline is Fabric's visual orchestration canvas for chaining activities, branching and looping.

  • A. A Spark job definition runs batch Spark code; it isn't a visual orchestration canvas.
  • B. Pipelines are the orchestration canvas with activities for copy, dataflows, notebooks, branching and loops.
  • C. Dataflow Gen2 runs Power Query transformations and can't chain other items or branch on conditions.
  • D. A KQL queryset stores KQL queries for an eventhouse and doesn't orchestrate items.
Question 10Implement and manage an analytics solution

Field technicians at Contoso hold only the Viewer role in the Assets workspace. They must upload inspection photos into Files/inspections/uploads of the Plant-LH lakehouse through the OneLake file explorer, but must not write anywhere else in Plant-LH, and they must not receive a higher workspace role. What should you configure?

  1. A.

    A OneLake security role that grants ReadWrite on Files/inspections/uploads, with the technicians as members

  2. B.

    The Contributor role on Assets, plus a OneLake security role that limits the analysts to Files/inspections/uploads

  3. C.

    A share of Plant-LH that grants the technicians Read all with Apache Spark on the lakehouse

  4. D.

    A OneLake security role that grants Read on Files/inspections/uploads with a row-level security rule for technicians

Show answer

Answer: A

The ReadWrite permission in a OneLake security role gives read-only users write access to selected folders, including uploading files through OneLake clients such as the file explorer.

  • A. ReadWrite lets Viewer-level users write only in the selected folder, including through the file explorer.
  • B. Contributor is forbidden and is not restricted by OneLake roles, so it could write everywhere.
  • C. Lakehouse sharing grants read access only, so uploads would fail.
  • D. Read cannot upload, and RLS applies to tables, not folders of files.

Keep going with 502 more DP-700 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

DP-700 sample questions with answers (10 free) · CertifyCloudx