Courseiva

PL-300 Manage and secure Power BI Practice Question

A Power BI administrator needs to ensure that reports containing sensitive financial data are only accessible to users who have completed mandatory training and are using compliant devices. The organization uses Microsoft Entra ID and Microsoft Intune. Which feature should the administrator configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that requires device compliance and a specific group membership for training completion

The correct option is C: a Conditional Access policy that requires device compliance and a specific group membership for training completion. Conditional Access in Microsoft Entra ID can enforce both device compliance (via Intune) and group membership as access controls, so only users in the trained group on compliant devices can reach the Power BI reports. Option A is wrong because Microsoft Purview scans and classifies data but does not enforce training-based access at sign-in. Option B is wrong because row-level security filters rows within a dataset, not user training status or device compliance. Option D is wrong because sensitivity labels and MFA do not verify training completion or device compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Microsoft Purview to scan the reports and enforce access policies

    Why it's wrong here

    Microsoft Purview is a data governance and catalog service that scans and classifies sensitive data across the estate, but it does not enforce real-time access control for Power BI reports. Access to reports is governed by Microsoft Entra Conditional Access, workspace permissions, and app-level settings. While Purview can apply data policies at the source, it cannot evaluate device compliance or training completion before a user opens a report. Therefore, it is not the appropriate tool for this requirement.

  • ✗

    Use row-level security (RLS) to filter data based on user training status

    Why it's wrong here

    Row-level security (RLS) restricts which rows of data a user sees within a report by applying DAX filters after the user has already accessed the report. It does not control whether that user can open the report in the first place, nor can it inspect device compliance or verify that the user completed required training. RLS relies solely on the signed-in user's identity and role mappings, so it cannot enforce the external conditions described. Thus, RLS is a data-level filter, not an access-control mechanism for the report itself.

  • ✓

    Create a Conditional Access policy that requires device compliance and a specific group membership for training completion

    Why this is correct

    Conditional Access is an Microsoft Entra ID feature that evaluates signals such as group membership, device compliance (via Intune), and risk before issuing a token for cloud apps like Power BI. By creating a policy that requires the user to belong to a group representing training completion and that their device be marked as compliant, the administrator can block access to all Power BI reports at the authentication layer. This is the correct approach because it combines identity and device context in a single, centrally managed policy, which works across web and mobile clients.

  • ✗

    Apply sensitivity labels to the reports and require MFA

    Why it's wrong here

    Sensitivity labels, powered by Microsoft Information Protection, classify and encrypt content to prevent unauthorized sharing or handling of the report data. While labels and MFA add security, neither can evaluate whether the user's device is compliant or whether the user has completed training. MFA only proves something about the user's identity, and sensitivity labels protect the content regardless of the user's context. These measures complement Conditional Access but do not replace it, so they cannot satisfy the specific enforcement requirements.

About these practice questions

This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.