Courseiva
Maintain a Data Analytics SolutionhardMultiple SelectObjective-mapped

DP-600 Maintain a Data Analytics Solution Practice Question

You are auditing security in a Fabric workspace. You need to identify which two actions are required to ensure that a user can view a report without having access to the underlying Lakehouse files. Which two actions should you perform?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assign the user the Viewer role in the workspace.

Restricting access requires a separation of concerns between the reporting layer and the data storage layer. By leveraging workspace roles and specific semantic model permissions, you enforce the principle of least privilege. This ensures that business users can consume data through Power BI visuals while the sensitive raw data files in OneLake remain protected from direct file-level access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign the user the Viewer role in the workspace.

    Why this is correct

    The Viewer role provides read-only access to the items within the workspace, such as Power BI reports and semantic models, without granting the user the ability to browse or download the files located in the underlying Lakehouse storage. This effectively isolates the reporting content from raw storage access.

  • Grant the user the Contributor role in the workspace.

    Why it's wrong here

    The Contributor role provides broad access to create and manage items, including the ability to interact with data assets directly. Granting this level of access violates security best practices when users only require report consumption capabilities, as it provides far more permissions than the user actually needs.

  • Share the semantic model with 'Build' permission.

    Why this is correct

    Sharing the semantic model with Build permission allows the user to create reports based on that model without needing direct access to the Lakehouse or the underlying storage tables. This is the correct way to allow report creation while strictly isolating the user from the raw data layer.

  • Grant the user access to the Lakehouse folder via OneLake.

    Why it's wrong here

    Granting folder-level access in OneLake exposes the raw files to the user, contradicting the requirement to prevent access to the underlying Lakehouse files. This action effectively bypasses the semantic model layer and exposes the Parquet files to the user for direct download and manipulation.

  • Add the user to the workspace Admin role.

    Why it's wrong here

    The Admin role provides full control over all items, including the ability to delete assets and modify security settings. This level of access is highly excessive for a user who only needs to view a report and poses a significant security risk to the entire analytics solution.

About these practice questions

This DP-600 question is part of Courseiva's 12-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-600 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-600 exam.