DP-600 Maintain a Data Analytics Solution Practice Question
Exhibit
{"policy": "Deny", "action": "DataExport", "principal": "AllUsers", "condition": "WorkspaceLevel"}Refer to the exhibit. You are reviewing an organization's Fabric security policy. Based on the provided JSON snippet, what is the impact of this policy on your data analytics solution?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy prevents users from exporting data from all reports within the workspace.
This policy implements a governance guardrail that prevents users from exporting data out of the Fabric workspace. In an enterprise environment, this is crucial for maintaining compliance and preventing data exfiltration. By controlling the export action at the workspace level, you ensure that sensitive insights remain contained within the secure Microsoft Fabric boundary, regardless of user permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Users can export data from individual reports if they have Owner permissions.
Why it's wrong here
The policy specifies 'Deny' for the 'DataExport' action for 'AllUsers'. This global prohibition overrides individual user roles within the workspace, meaning that even users with high-level permissions like Owner cannot bypass this restriction to export data into formats like Excel or CSV from the report visuals.
- ✓
The policy prevents users from exporting data from all reports within the workspace.
Why this is correct
The policy explicitly targets the DataExport action across the entire workspace for all users. This effectively disables the export functionality in the Power BI user interface, ensuring that sensitive data used in reports cannot be extracted into external files, thereby maintaining strict control over data distribution policies.
- ✗
The policy allows exporting if the data is anonymized.
Why it's wrong here
The policy is a blanket denial of the DataExport action and does not contain any logic for content-based inspection or anonymization. The system will block all export requests regardless of the data content or the user's justification, ensuring a consistent application of the security mandate across the workspace.
- ✗
The policy only affects users with the Guest role.
Why it's wrong here
The policy explicitly lists 'AllUsers' as the principal, which encompasses all members of the workspace, including internal employees and guests. There is no distinction made based on user origin, ensuring that the security posture is enforced uniformly across every person who has access to the target workspace.
About these practice questions
Courseiva writes every DP-600 question from scratch — 12 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-600 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-600 exam.