PL-300 Manage and secure Power BI Practice Question
A data analyst creates a Power BI report using a dataset that contains sensitive salary information. The analyst needs to ensure that only HR managers can see salary columns. What should the analyst use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Object-level security (OLS).
Object-level security (OLS) is the correct choice because it restricts access to specific tables or columns within a dataset, which is exactly what is needed to hide salary columns from everyone except HR managers. OLS is defined in the dataset's Tabular Model roles and can deny access to individual columns so that unauthorized users cannot see them in reports. Row-level security (RLS) only filters rows, not columns, so it cannot prevent viewing salary columns. Microsoft Purview sensitivity labels classify and protect data but do not control column visibility in Power BI reports, and 'Restrict access' is not a valid dataset security setting for column-level control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Row-level security (RLS).
Why it's wrong here
Row-level security (RLS) restricts which rows of data a user can query based on DAX filter predicates, but it never removes or hides columns from the report or dataset schema. A user subject to RLS can still see every column in a table, including sensitive attributes, as long as the row passes the filter. Therefore, RLS cannot achieve column-level protection, making it an incorrect solution for this scenario.
- ✗
Microsoft Purview sensitivity labels.
Why it's wrong here
Microsoft Purview sensitivity labels apply classification and protection (such as encryption or watermarking) to the content, but they operate on files and supporting metadata rather than on the Power BI tabular model's columns. In Power BI, a sensitivity label can be set on a dataset, report, or workspace to govern downstream use, yet it does not define per-role column permissions or hide a column from an authenticated viewer. Because labels classify the entire artifact without targeting specific columns, they do not satisfy the requirement to restrict a sensitive column.
- ✓
Object-level security (OLS).
Why this is correct
Object-level security (OLS) lets a modeler define roles that remove specific tables or columns from a user's view by setting their object permissions to None. In Power BI, OLS is implemented in the role editor (or via XMLA endpoints) where you can deny access to a column while leaving the rest of the model accessible. Since the requirement is to hide a sensitive column while allowing the rest of the dataset to remain usable, OLS is the correct mechanism.
- ✗
Set the dataset security to 'Restrict access'.
Why it's wrong here
There is no native 'Restrict access' dataset security setting in Power BI that controls column-level visibility; dataset security is normally configured through row-level security or workspace access permissions. A setting like that would at most remove the entire dataset from a user, not selectively hide one column. Relying on such a non-existent option would either over-restrict users (blocking all data) or fail to protect the sensitive column, so it is not a valid answer.
Go deeper
Related to this question
About these practice questions
One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.