PL-300 Manage and secure Power BI Practice Question
A Power BI administrator needs to enforce that all datasets published to the service use certified data sources only. Which two settings should be configured? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Certification' for dataflows in the Power BI tenant settings.
To enforce that all datasets use certified data sources only, an administrator should enable certification for data sources (Option C) and enable certification for dataflows (Option B). Option C allows data source owners to certify data sources, and Option B allows dataflow owners to certify dataflows. Combined, these settings promote the use of certified components. Option A (monitoring with Sentinel) only detects non-certified sources, it does not enforce. Option D (RLS) and Option E (B2B permissions) are unrelated to data source certification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Sentinel to audit Power BI activity logs and flag non-certified data sources.
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM/SOAR tool that can ingest Power BI activity log events and alert on anomalies such as connections to non-certified data sources, but it operates after the fact. It cannot block a dataset from being published or prevent a developer from selecting an uncertified source in the first place; it only raises alerts for review, so it is detective rather than preventive and does not meet an enforcement requirement.
- ✓
Enable 'Certification' for dataflows in the Power BI tenant settings.
Why this is correct
Enabling the 'Certification' tenant setting for dataflows activates the endorsement feature that lets authorized reviewers officially certify reusable dataflows. Once certified, those dataflows are the trusted building blocks that dataset authors can be required to use, and the tenant switch is a prerequisite for applying governance policies that mandate certified dataflows. Without this setting, dataflow certification is impossible, making it the correct control for enforcing that datasets use only certified dataflows.
- ✓
Enable 'Certification' for data sources in the Power BI tenant settings.
Why this is correct
Enabling 'Certification' for data sources in tenant settings lets an organization mark supported external connections, such as SQL Server databases, as certified so that dataset authors can identify and prefer approved sources. This directly supports the goal of ensuring datasets use only certified data sources, and it is the complementary setting to dataflow certification when governance must span both the raw source connection and the transformation layer. It provides the metadata foundation needed to implement policies that require certified data sources.
- ✗
Configure row-level security (RLS) on all datasets.
Why it's wrong here
Row-level security (RLS) dynamically filters the rows a given user can see within a dataset by evaluating DAX or role-based predicates set in Power BI Desktop or the service. It says nothing about the lineage of the dataset—a dataset can have RLS enabled and still be built on an uncertified source—so it is a data-access control, not a data-source governance control, and therefore does not enforce certified source usage.
- ✗
Set up B2B guest user permissions to restrict external data sources.
Why it's wrong here
B2B guest user settings govern how external Azure AD users can access Power BI items such as apps, workspaces, and dashboards; they are unrelated to the catalog of data sources available to internal dataset authors. Restricting external user access does nothing to control whether a dataset connects to a certified or uncertified data source, so it fails to address the requirement of enforcing certified data source usage.
Go deeper
Related to this question
About these practice questions
One of 217 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.