Courseiva

CCNA Manage and secure Power BI Questions

71 questions · Manage and secure Power BI · All types, answers revealed

1
Multi-Selecteasy

A Power BI administrator wants to allow users to create dashboards and reports, but prevent them from sharing content outside the organization. Which two settings should be configured in the Power BI admin portal? (Choose two.)

Select 2 answers
A.Disable 'Create workspaces' in the tenant settings.
B.Disable 'Export data' in the tenant settings.
C.Disable 'Featured tables' in the tenant settings.
D.Disable 'Share content with external users' in the tenant settings.
E.Disable 'Publish to web' in the tenant settings.
AnswersD, E

The correct approach is to disable 'Share content with external users' in the tenant settings, because this switch directly governs whether users can share dashboards and reports with external email addresses. When turned off, the Share dialog rejects external recipients entirely, blocking both direct sharing and app access via external users. This is the primary tenant-level control for preventing outside access to dashboards without disabling internal collaboration.

Why this answer

Option D is correct because disabling 'Share content with external users' in the Power BI admin portal tenant settings blocks users from sharing dashboards and reports with recipients outside the organization, directly satisfying the requirement to prevent external sharing. Option E is correct because disabling 'Publish to web' prevents users from publishing reports to public websites, which is another channel for exposing content outside the organization. Option A is incorrect because disabling 'Create workspaces' would prevent users from creating workspaces, conflicting with the goal of allowing them to create dashboards and reports.

Option B is incorrect because disabling 'Export data' restricts exporting underlying data rather than sharing dashboards and reports externally. Option C is incorrect because 'Featured tables' relates to promoting tables in Excel's data types gallery and has no bearing on external sharing.

2
MCQhard

Your organization uses Power BI and has implemented Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security). A user reports that they are unable to export data from a Power BI report. The Power BI tenant settings allow export. What could be the cause?

A.The 'Export to Excel' setting is disabled in the Power BI admin portal.
B.A sensitivity label with high classification is applied to the report, automatically blocking export.
C.The user is an external guest user.
D.A Microsoft Defender for Cloud Apps session policy is blocking the export based on the user's risk level or the report's sensitivity.
AnswerD

Microsoft Defender for Cloud Apps session policies use Conditional Access App Control to intercept Power BI sessions in real time. An admin can create a policy that triggers the 'block download' action when a session meets conditions such as a high-risk sign-in or a report containing a specified sensitivity label. This occurs at the proxy layer, so it neither disables the Export button in the UI nor depends on the user being a guest—explaining why the export is blocked for this specific scenario.

Why this answer

The correct answer is D: a Microsoft Defender for Cloud Apps session policy is blocking the export based on the user's risk level or the report's sensitivity. Because Defender for Cloud Apps can proxy Power BI sessions via Conditional Access App Control, its session policies can inspect and block actions like export even when the Power BI tenant setting allows export. Option A is wrong because the scenario states the tenant settings already allow export.

Option B is wrong because sensitivity labels alone do not automatically block export; protection is enforced through encryption/permissions, not a blanket export block. Option C is wrong because being an external guest user does not by itself prevent exporting data.

3
MCQhard

A Power BI administrator needs to ensure that reports containing sensitive financial data are only accessible to users who have completed mandatory training and are using compliant devices. The organization uses Microsoft Entra ID and Microsoft Intune. Which feature should the administrator configure?

A.Deploy Microsoft Purview to scan the reports and enforce access policies
B.Use row-level security (RLS) to filter data based on user training status
C.Create a Conditional Access policy that requires device compliance and a specific group membership for training completion
D.Apply sensitivity labels to the reports and require MFA
AnswerC

Conditional Access is an Azure AD feature that evaluates signals such as group membership, device compliance (via Intune), and risk before issuing a token for cloud apps like Power BI. By creating a policy that requires the user to belong to a group representing training completion and that their device be marked as compliant, the administrator can block access to all Power BI reports at the authentication layer. This is the correct approach because it combines identity and device context in a single, centrally managed policy, which works across web and mobile clients.

Why this answer

The correct option is C: a Conditional Access policy that requires device compliance and a specific group membership for training completion. Conditional Access in Microsoft Entra ID can enforce both device compliance (via Intune) and group membership as access controls, so only users in the trained group on compliant devices can reach the Power BI reports. Option A is wrong because Microsoft Purview scans and classifies data but does not enforce training-based access at sign-in.

Option B is wrong because row-level security filters rows within a dataset, not user training status or device compliance. Option D is wrong because sensitivity labels and MFA do not verify training completion or device compliance.

4
MCQmedium

You are a Power BI administrator. A user reports that their scheduled data refresh fails with error 'The data source credentials are no longer valid.' The dataset uses a SQL Server database with Windows authentication. What should you do first to resolve the issue?

A.Reinstall the on-premises data gateway on the server.
B.Reassign the dataset to a different Premium capacity.
C.Modify the dataset to use 'Impersonate the authenticated user' for data sources.
D.Ask the user to update the data source credentials in the Power BI service dataset settings.
AnswerD

The error indicates stored credentials expired or were changed, so refreshing them in the dataset settings restores authentication. Because the source uses Windows authentication, the user must re-enter valid credentials in the Power BI service, directly resolving the refresh failure before investigating gateways or permissions.

Why this answer

The first step is to ask the user to update the data source credentials in the Power BI service dataset settings. The error explicitly states that credentials are no longer valid, so refreshing them is the direct fix. This is a common issue when passwords expire or service accounts change.

Exam trap

PL-300 often tests the tendency to overcomplicate credential issues, leading candidates to choose gateway or capacity changes instead of the simple credential update.

How to eliminate wrong answers

Option A is wrong because reinstalling the gateway is unnecessary if the error is about credentials; it would not resolve invalid credentials. Option B is wrong because reassigning to a different Premium capacity does not affect credentials. Option C is wrong because modifying to 'Impersonate the authenticated user' is a configuration change that may not be appropriate and does not directly address expired credentials.

5
Multi-Selecteasy

Which TWO are valid methods to secure access to a Power BI dataset? (Select exactly two.)

Select 2 answers
A.Row-level security (RLS)
B.Column-level security (CLS)
C.Object-level security (OLS)
D.App permissions
E.Data encryption at rest
AnswersA, C

Row-level security (RLS) is a valid method because it restricts data at the row level based on the identity of the signed-in user. By defining roles in Power BI Desktop and using DAX expressions (such as USERNAME() or USERPRINCIPALNAME()), RLS filters the underlying dataset dynamically, so each user only sees rows they are permitted to view. This filtering is enforced at query time, making it a robust, native access-control feature for Power BI datasets.

Why this answer

Row-level security (RLS) [CORRECT] is a valid method to secure access to a Power BI dataset because it restricts which rows a given user can see by applying DAX filter expressions to roles defined in the dataset, and those roles are assigned to users or groups in the Power BI service. Object-level security (OLS) [CORRECT] is also valid because it secures specific tables or columns in the dataset model by hiding them entirely from users who lack permission, preventing them from viewing or querying those objects. Column-level security (CLS) is not a separate Power BI feature; column-level restriction is achieved through OLS, so it is not a distinct valid method.

App permissions control access to Power BI apps and workspaces rather than securing the dataset model itself, and data encryption at rest protects stored data on disk but does not control which data a user can access within a dataset.

6
MCQmedium

You have a Power BI dataset that uses DirectQuery to a SQL Server data warehouse. You need to ensure that when users view reports, they see only data relevant to their department. The data warehouse contains a 'Department' column. What should you implement?

A.Configure the data source credentials to pass the user's identity.
B.Create separate datasets for each department and grant access accordingly.
C.Implement object-level security (OLS) on the 'Department' column.
D.Define row-level security (RLS) roles in Power BI Desktop and assign users.
AnswerD

Define row-level security (RLS) roles in Power BI Desktop by creating a role with a DAX filter—such as an expression using USERPRINCIPALNAME() or a mapping table—that filters the dataset to only the rows relevant to the signed-in user. After publishing, assign users or groups to the role in the Power BI Service, and the filter is automatically applied to all report consumers. This is the standard, supported approach for row-level access in a single dataset, and it works across DirectQuery and Import modes.

Why this answer

The correct option is D: defining row-level security (RLS) roles in Power BI Desktop and assigning users, because RLS filters rows at query time based on the user's identity, so each user sees only the rows matching their department in the 'Department' column, and it works with DirectQuery by translating the filter into the source query. This is the standard, scalable way to enforce per-user data visibility in a single dataset. Option A only controls how credentials are passed to the source and does not by itself filter rows by department.

Option B is inefficient and does not use a single governed dataset, and Option C, object-level security, restricts access to tables or columns rather than filtering rows by department value.

7
MCQeasy

Refer to the exhibit. User2 wants to add a new user to the Finance workspace. Can User2 perform this action, and why?

A.Yes, because User2 is a Contributor.
B.Yes, because User2 is a Member.
C.No, because the Premium capacity does not allow adding users.
D.No, because only Admins can add users.
AnswerD

Workspace roles follow a permission hierarchy, and only the Admin role includes the ability to add, remove, or change the roles of other workspace members. Since User2 is not an Admin, they cannot add a new user regardless of which non-Admin role they hold. This is why the correct answer is 'No' — the action requires Admin privileges, which User2 does not possess.

Why this answer

The correct answer is D: No, because only Admins can add users. In the workspace roles model, adding or removing users (managing workspace access) is an Admin-only capability; Members and Contributors can work with content but cannot change membership. Therefore User2 cannot add a new user to the Finance workspace regardless of being a Member or Contributor.

Option A is wrong because the Contributor role does not include user management, and Option B is wrong because the Member role also lacks that permission. Option C is wrong because Premium capacity is unrelated to workspace user-addition rights; permissions are governed by workspace roles, not capacity SKU.

8
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that Power BI reports can only be viewed on managed devices that are compliant with company policies. What should you configure?

A.Power BI Premium capacity setting 'Restrict access to mobile devices'.
B.Conditional Access policy in Microsoft Entra ID requiring device compliance.
C.Power BI tenant setting 'Require users to sign in with Microsoft Entra ID'.
D.Mobile app management (MAM) policy in Microsoft Intune.
AnswerB

A Conditional Access policy in Microsoft Entra ID is the correct mechanism to block Power BI from non-compliant devices. The policy can require a device to be marked as 'Compliant' by Microsoft Intune before allowing access; this evaluation happens at sign-in time using signals from Intune. For example, the grant control 'Require device to be marked as compliant' combined with the Power BI cloud app will deny access to devices that do not meet your organization's compliance policies. This is the standard and supported way to enforce device-based access control for Power BI.

Why this answer

The correct answer is B: a Conditional Access policy in Microsoft Entra ID requiring device compliance. Conditional Access is the mechanism that evaluates signals such as Intune device compliance state and enforces access controls, so a policy targeting the Power BI cloud app with a 'Require device to be marked as compliant' grant control ensures reports can only be viewed from managed, compliant devices. Option A is not a real Power BI Premium capacity setting for this purpose, and Power BI capacity settings do not enforce device compliance.

Option C only enforces Entra ID authentication for the tenant and does not check device compliance or management state. Option D, an Intune MAM policy, protects app data on mobile devices but does not gate access to Power BI reports based on device compliance.

9
MCQmedium

You are a Power BI administrator. A user reports they cannot publish a report to a shared workspace because they receive an error 'You need at least a Contributor role to publish to this workspace.' The user is a member of a security group that has been assigned the Viewer role on the workspace. What should you do to allow the user to publish?

A.Grant the user Read permission on the report in the workspace.
B.Add the user as a Contributor directly to the workspace, or change the security group role to Contributor.
C.Change the user's role to Viewer on the workspace and ask them to use the 'Publish to web' option.
D.Create a new workspace and add the user as a Member.
AnswerB

Publishing requires the Contributor role, which grants content creation and editing rights that Viewer lacks. Since the security group holds only Viewer, the user inherits insufficient permissions. Assigning Contributor directly, or elevating the group's role, satisfies the workspace role constraint and resolves the error.

Why this answer

The correct option is B: add the user as a Contributor directly to the workspace, or change the security group role to Contributor. In Power BI, publishing a report to a workspace requires at least the Contributor role, which grants content creation and editing permissions; the Viewer role only allows read-only access, so the user's current group-based Viewer role blocks publishing. Granting Contributor either directly or by elevating the group's role resolves the error.

Option A is insufficient because Read permission on an existing report does not grant publishing rights. Option C is wrong because Viewer plus 'Publish to web' is for public embedding, not workspace publishing. Option D is unnecessary and does not address the required role in the existing shared workspace.

10
MCQhard

A Power BI report uses a composite model combining Import and DirectQuery sources. When a user filters a visual, the report takes a long time to update. The admin wants to diagnose performance issues. Which tool should the admin use?

A.DAX Studio.
B.Performance Analyzer in Power BI Desktop.
C.Power BI activity log.
D.On-premises data gateway log.
AnswerB

Performance Analyzer in Power BI Desktop is the intended diagnostic tool because it records a chronological breakdown of operations for each visual, including DAX query time, visual display time, and other report-level processes. This lets you identify whether the slowdown comes from the composite model's query engine when combining imported and DirectQuery tables or from rendering. The results can be exported to JSON for further investigation, making it the definitive answer for visual-level performance analysis.

Why this answer

The correct option is B, Performance Analyzer in Power BI Desktop, because it captures per-visual query timings and DAX query durations as the user interacts with the report, letting the admin pinpoint which visual or filter is slow in a composite model. It records each visual's rendering and query events, so the admin can see whether the delay comes from the Import or DirectQuery portion. DAX Studio (A) is useful for tuning individual DAX queries but does not profile the report's visual-by-visual interaction flow.

The Power BI activity log (C) tracks usage and audit events, not query performance per visual, and the on-premises data gateway log (D) only covers gateway traffic for DirectQuery/refresh, not the full report rendering path.

11
MCQhard

Refer to the exhibit. A user is a member of both 'HRManager' and 'Executive' RLS roles. The dataset uses DirectQuery. When the user views a report showing all employees, what data will they see?

A.All rows in the Employees table.
B.Only rows where Department is both 'HR' and 'Executive' (intersection).
C.No rows because roles conflict.
D.Rows where Department is 'HR' or 'Executive' (union).
AnswerD

The user effectively sees rows where Department = 'HR' OR Department = 'Executive'. Because the HR Manager role allows HR records and the Executive role allows Executive records, membership in both grants access to the union of those two sets. This is the expected additive behavior of multiple RLS roles in Power BI, where each role adds its permitted rows to the user's overall view.

Why this answer

The correct answer is D: rows where Department is 'HR' or 'Executive' (union). In Power BI row-level security, when a user belongs to multiple roles, the role filters are combined with OR logic, so the user sees the union of the rows permitted by each role. This behavior applies regardless of whether the dataset uses DirectQuery or Import mode, since RLS role membership is evaluated per user at query time.

Options A, B, and C are incorrect because RLS does not grant all rows, does not intersect multiple role filters, and does not produce an empty result due to role conflicts.

12
MCQeasy

Your organization uses Microsoft Purview to catalog Power BI assets. You need to ensure that all published reports and dashboards are automatically scanned and added to the catalog. What should you do?

A.Register the Power BI tenant as a data source in Microsoft Purview.
B.Enable 'Allow Azure Active Directory authentication' in the Power BI admin portal.
C.Apply sensitivity labels to all assets.
D.Create a new workspace in Power BI and assign the catalog admin role.
AnswerA

Registering the Power BI tenant as a data source in Microsoft Purview is the essential first step because it establishes a connection from Purview Data Map to your organization's Power BI environment. Once registered, Purview automatically scans and catalogs metadata from all workspaces, datasets, dataflows, reports, and dashboards without requiring manual asset entry. This registration typically requires a Power BI administrator role so Purview can authenticate and retrieve the metadata.

Why this answer

The correct option is A: register the Power BI tenant as a data source in Microsoft Purview. Microsoft Purview scans and catalogs Power BI assets (reports, dashboards, datasets, dataflows) only after the Power BI tenant is registered as a data source and a scan is configured, which uses the Power BI Admin API and requires tenant-level read-only admin permissions. Option B is unrelated: enabling Azure AD authentication in the Power BI admin portal does not trigger Purview scanning or cataloging.

Option C, applying sensitivity labels, governs data protection and classification but does not populate the Purview catalog with Power BI assets. Option D is incorrect because creating a workspace and assigning a catalog admin role does not register the tenant or initiate scanning of published reports and dashboards.

13
MCQeasy

You are a Power BI administrator. A user in the Sales department needs to create reports using a shared dataset, but should not be able to modify the dataset or share it with others. What is the minimum permission level you should assign to the user on the dataset?

A.Reshare
B.Build
C.Write
D.Read
AnswerB

Build permission specifically grants the right to connect to the dataset as a source for new reports and to create new visualizations in the Power BI service or Power BI Desktop. It is the minimal permission because it satisfies the user's need to author new sales reports without exposing write capabilities or allowing resharing. With Build, the user can create and save new reports, but cannot modify the dataset or grant access to others.

Why this answer

The correct option is B, Build, because the Build permission on a shared dataset allows a user to create new reports and content based on that dataset without granting rights to edit the dataset itself or reshare it. This matches the requirement of report creation with no dataset modification or sharing capability. Reshare (A) would allow the user to share the dataset with others, which is explicitly prohibited.

Write (C) grants broader editing rights over the dataset, and Read (D) only permits viewing existing content, not authoring new reports from the dataset.

Exam trap

A common trap is to select Read, thinking it's sufficient for report creation, but Read only allows viewing, not building. Build is the minimum permission needed.

14
MCQeasy

You are a Power BI administrator. You need to prevent users from exporting underlying data from reports. Which tenant setting should you disable?

A.'Export data'
B.'Export reports as PowerPoint presentations'
C.'Export reports as PDF files'
D.'Export reports as MHTML files'
AnswerA

'Export data' in the Power BI admin tenant settings controls whether users can extract the underlying dataset from a visual, such as copying values to the clipboard, downloading a .csv file, or exporting summary data to Excel. This is the only option listed that reveals the actual numbers and granular row-level or aggregated fields behind a report. Disabling this setting prevents raw data extraction through the service, though visual snapshots in other export formats may still leak information visually.

Why this answer

'Export data' controls the ability to export underlying data. Option B is wrong because 'Export reports as PowerPoint' is for exporting the report itself. Option C is wrong because 'Export reports as PDF' is for static exports.

Option D is wrong because 'Export reports as MHTML' is also for report export.

15
MCQeasy

Refer to the exhibit. You are reviewing a DAX expression used in a Power BI measure. You need to ensure that only users in the 'West' region see data for that region. Which approach should you use?

A.Implement row-level security (RLS) in the dataset with a role filter.
B.Use the CALCULATE function with a filter on the report page.
C.Modify the measure to include a conditional statement that checks the user's email.
D.Create a calculated column with the same logic.
AnswerA

Correct. Row-level security (RLS) is enforced at the dataset level by defining one or more roles in Power BI Desktop, each with a DAX filter that restricts rows based on the current user (e.g., using USERPRINCIPALNAME() or CUSTOMDATA()). This filter is applied by the Analysis Services engine for every query against the dataset, regardless of which report pages, visuals, or measures are used, so no user can ever see rows outside their role's allowed set. It is the only option here that actually slices data by security identity before results reach the reporting layer.

Why this answer

Row-level security (RLS) in the dataset with a role filter is the correct approach because it enforces data restrictions at the model level, so users in the 'West' region automatically see only rows where the region equals 'West' regardless of which report or visual they open. RLS roles are defined in Power BI Desktop and assigned to users or groups in the Power BI Service, providing centralized and secure filtering. Using CALCULATE with a report-page filter (B) only affects calculations or visuals, not the underlying data visible to users, so it can be bypassed.

A measure with a conditional statement checking the user's email (C) is not a security boundary and cannot reliably restrict row visibility. A calculated column (D) computes values at refresh time and does not filter data per user, so it cannot enforce regional access.

16
MCQeasy

You are a Power BI administrator. The compliance team requires that all Power BI datasets and reports must be retained for seven years, even if users delete them. You need to configure the tenant to meet this requirement with minimal administrative effort. What should you do?

A.Configure a backup schedule for the Power BI workspace.
B.Enable Microsoft Purview retention policies for Power BI items.
C.Set the workspace retention policy to seven years in the workspace settings.
D.Instruct users to move items to a dedicated archive workspace.
AnswerB

Microsoft Purview retention policies can be applied to Power BI datasets, reports, and other items. When configured, they ensure that items are retained for the specified period even if users delete them. This is a centralized, tenant-wide solution that requires minimal ongoing effort once set up, and it meets the seven-year retention requirement.

Why this answer

Microsoft Purview retention policies are the correct solution because they can be applied to Power BI items to retain them for a specified period, even if users delete them. This is a tenant-level configuration that requires minimal effort and meets compliance requirements. Other options are either not valid Power BI features or do not enforce automatic retention.

Exam trap

The trap here is assuming that Power BI has built-in workspace-level retention settings or backup schedules, when retention is actually handled through Microsoft Purview.

17
MCQhard

A Power BI admin receives a support ticket that a user cannot see any data in a report that uses row-level security (RLS). The report is based on a dataset with a single table 'Sales' and RLS roles defined. The user is assigned to the role 'SalesManager' which filters Sales[Region] = 'West'. The dataset uses Import mode. The user can see the report but all visuals show blank. What is the most likely cause?

A.The RLS filter removes all rows for the user's role.
B.The user does not have permission to view the report page.
C.The user is viewing a dashboard tile instead of the report.
D.The dataset was refreshed using an RLS bypass account.
AnswerA

The correct diagnosis is that the row-level security (RLS) filter defined for the user's role is returning an empty result. RLS applies a DAX filter to every visual in the report; if the user's identity (via USERNAME()) doesn't match any row in the `Sales[Region]` column, all measures become BLANK and tables show zero rows. An admin can verify this by using 'View as' in Power BI Desktop and selecting the specific role to see the same empty output.

Why this answer

The correct answer is A: the RLS filter removes all rows for the user's role. In Import mode, RLS is enforced by DAX filters applied at query time, so if the 'SalesManager' role filters Sales[Region] = 'West' and the user's identity maps to no rows where Region equals 'West' (for example, due to case/spacing mismatches or the user not being in the intended region), every visual returns blank rather than an error. The other options do not fit: B would typically block report access entirely or show a permission error, not blank visuals; C describes a dashboard tile scenario, but the ticket says the user can see the report; and D is not a valid cause because refreshing with an RLS bypass account affects data loading, not the query-time RLS filtering applied to the user.

18
MCQmedium

Your organization uses Power BI in a shared capacity model. A report developer complains that a new report published to a workspace does not appear in the 'My workspace' area. They have the Contributor role on the workspace. What is the most likely cause?

A.The Contributor role does not have permission to publish reports to the workspace.
B.The report was automatically added to 'My workspace' but was deleted by an administrator.
C.Reports published to a workspace do not appear in 'My workspace' unless the user manually saves a copy there.
D.The user does not have a Power BI Pro license.
AnswerC

Reports published to a shared workspace live in that workspace, not in 'My workspace', which is reserved for each user's personal content. The user must manually save a copy to 'My workspace' if they want a private version; otherwise, the report is only accessible from the workspace where it was published. This is the correct explanation for the user's confusion about the report's location.

Why this answer

The correct answer is C: reports published to a workspace do not appear in 'My workspace' unless the user manually saves a copy there. In Power BI, 'My workspace' is a personal container separate from shared workspaces, so a report published to a shared workspace stays in that workspace and is not mirrored into the developer's personal area. The Contributor role is sufficient to publish and edit content in a workspace, so permission is not the issue.

Option A is wrong because Contributor does allow publishing, option B is wrong because no automatic copy is created to be deleted, and option D is wrong because licensing would not cause this specific display behavior.

19
Multi-Selectmedium

You need to audit Power BI activities such as viewing reports, sharing dashboards, and exporting data. Which TWO actions should you take to enable and access audit logs? (Choose two.)

Select 2 answers
A.Configure Microsoft Defender for Cloud Apps to forward logs to Microsoft Sentinel.
B.Access the audit log from the Microsoft 365 compliance portal.
C.Enable the 'Create audit logs for Power BI activities' tenant setting in the admin portal.
D.Use the 'Export' feature in Power BI to export audit logs to a CSV file.
E.Set up a diagnostic setting in Azure Monitor to collect Power BI logs.
AnswersB, C

Microsoft 365 compliance portal surfaces the unified audit log, which captures Power BI activities including report views, dashboard shares and exports. Because the stem requires auditing those specific events, retrieving them here satisfies the requirement; the log aggregates Microsoft Entra ID-authenticated activity across workloads rather than Power BI service settings alone.

Why this answer

To audit Power BI activities, you must first enable audit logging by turning on the 'Create audit logs for Power BI activities' tenant setting in the Power BI admin portal (option C). Once enabled, you can access the audit logs from the Microsoft 365 compliance portal (option B). Option A is incorrect because Microsoft Defender for Cloud Apps is not the primary location for audit logs; it can integrate but is not required.

Option D is incorrect because Power BI does not have an export feature for audit logs to CSV; you can export from the compliance portal. Option E is incorrect because Azure Monitor diagnostic settings are for Azure resources, not for Power BI audit logs.

20
MCQmedium

You are a Power BI administrator. Your organization uses Microsoft Entra ID for identity management. You need to ensure that only users from specific security groups can access the Power BI service. What should you configure?

A.In the Power BI admin portal, configure the 'Allow users to access Power BI' setting to specify the security groups.
B.Create a conditional access policy in Microsoft Entra ID that grants access to Power BI only for members of the allowed security groups.
C.Configure the 'B2B guest user settings' to allow only specific domains.
D.Modify the workspace access permissions to include only the allowed security groups.
AnswerB

A conditional access policy in Microsoft Entra ID can target the Power BI service as a cloud app and apply a grant control that only allows sign-ins from specific security groups, while blocking all other users. This is the recommended identity-driven approach because Power BI authenticates via Entra ID, so the policy is evaluated during every sign-in, and it can also incorporate conditions such as device compliance, MFA, or location.

Why this answer

Option B is correct because Microsoft Entra ID Conditional Access is the supported mechanism to restrict sign-in to a cloud app such as Power BI based on group membership: you create a policy assigned to the Power BI cloud app, target the specific security groups under Users, and grant access while blocking everyone else. This enforces the restriction at authentication time across the tenant, which is exactly what the scenario requires. Option A is wrong because the Power BI admin portal's 'Allow users to access Power BI' setting is a tenant-wide on/off toggle that cannot be scoped to specific security groups.

Option C is wrong because B2B guest settings govern external collaboration and domain allow/deny lists, not which internal security groups may use Power BI. Option D is wrong because workspace access permissions only control content within individual workspaces and do not prevent users from signing in to the Power BI service.

21
Multi-Selectmedium

Which TWO methods can a Power BI admin use to enforce the use of sensitivity labels on reports? (Choose two.)

Select 2 answers
A.Deploy a Microsoft Intune policy to block unlabeled reports.
B.Configure default labels in Power BI Desktop.
C.Apply labels automatically using Microsoft Purview Information Protection.
D.Require users to apply sensitivity labels when publishing reports.
E.Use row-level security to hide unlabeled reports.
AnswersC, D

Microsoft Purview Information Protection (MIP) auto-labeling policies can inspect report content for sensitive data patterns (e.g., credit card numbers or PII) and automatically apply the appropriate sensitivity label to Power BI assets. Because Power BI is deeply integrated with Purview, these policies run in the background and can label unlabeled reports, ensuring consistent protection without manual user action. This is a fully valid admin-centric enforcement approach.

Why this answer

Option C is correct because Microsoft Purview Information Protection can be configured with auto-labeling policies that automatically apply sensitivity labels to Power BI content based on sensitive information types or other conditions, ensuring reports are labeled without relying on user action. Option D is correct because the Power BI tenant setting 'Require users to apply sensitivity labels when publishing reports' (in the admin portal under Information protection) enforces labeling at publish time, blocking publication of unlabeled reports. Option A is not correct because Intune is for device and app management (MDM/MAM) and cannot block unlabeled Power BI reports.

Option B is not correct because default labels in Power BI Desktop only pre-populate a suggested label; users can still change or remove it, so it does not enforce labeling. Option E is not correct because row-level security (RLS) filters data rows by user identity and has no capability to detect or hide unlabeled reports.

22
MCQmedium

Your organization uses Power BI with Premium capacity. You need to configure a scheduled refresh for a dataset that connects to an Azure SQL Database. The refresh must complete before 6:00 AM every day. The dataset currently takes 45 minutes to refresh. What is the most important consideration?

A.Use an on-premises data gateway to connect to Azure SQL.
B.Schedule the refresh to start early enough to complete by 6:00 AM, considering any other scheduled refreshes.
C.Configure incremental refresh to reduce the refresh time.
D.Ensure the dataset does not exceed the maximum number of daily refreshes (8 for shared, 48 for Premium).
AnswerB

For a dataset in Power BI Premium capacity, you can schedule multiple refreshes per day (up to 48 per dataset), but each refresh must complete before the next one begins, and the service enforces a maximum refresh duration. To ensure data is loaded by 6:00 AM, you need to schedule the start early enough to account for the dataset's expected runtime, any queue time on the capacity, and potential competition from other datasets' refreshes. This directly addresses the core requirement of having fresh data by a specific time.

Why this answer

The correct option is B: schedule the refresh to start early enough to complete by 6:00 AM, considering any other scheduled refreshes. Since the dataset takes 45 minutes, the schedule must begin by 5:15 AM at the latest, and because Power BI Premium allows up to 48 scheduled refreshes per day but serializes overlapping refreshes on the same capacity, other datasets sharing that capacity can delay the start and push completion past 6:00 AM. Option A is unnecessary because Azure SQL Database is a cloud service reachable directly over the internet, so no on-premises data gateway is required.

Option C could reduce refresh duration but is an optimization, not the essential scheduling consideration, and option D is irrelevant because the dataset needs only one daily refresh, far below the Premium limit.

23
MCQhard

You are a Power BI administrator. You need to audit all activities related to sharing reports and dashboards in the Power BI service. Which tool should you use?

A.Microsoft Purview compliance portal audit log
B.Azure diagnostic settings for Power BI
C.Power BI activity log (via admin API or portal)
D.Microsoft Sentinel
AnswerC

The Power BI activity log records granular events including ShareReport, ShareDashboard and CreateDashboard, retrievable through the admin portal or REST API. It satisfies the audit requirement by capturing who shared what, with whom, and when across the tenant.

Why this answer

The Power BI activity log provides a comprehensive record of all user activities within the Power BI service, including sharing reports and dashboards. Option A (Microsoft Purview compliance portal audit log) can capture some Power BI activities but is less specific and may not include all sharing events. Option B (Azure diagnostic settings) exports telemetry data to other destinations and is not designed for direct auditing of user actions.

Option D (Microsoft Sentinel) is a SIEM tool that can ingest logs but is not the primary tool for auditing Power BI activities. The Power BI activity log is the correct choice as it is purpose-built for auditing Power BI user activities.

24
MCQhard

Your organization uses Power BI with a shared capacity. You have a dataset that is refreshed daily from an on-premises SQL Server database using an on-premises data gateway. The dataset contains sensitive financial data. The security team requires that all access to the dataset be logged and that any access from outside the corporate network be flagged. You need to implement a monitoring solution. What should you do?

A.Audit the SQL Server database using Azure SQL Auditing.
B.Use Microsoft Defender for Cloud Apps to enforce conditional access policies.
C.Enable logging on the on-premises data gateway and monitor the logs.
D.Enable Power BI activity logging and stream to Azure Log Analytics, then create alerts on access events from external IPs.
AnswerD

Power BI activity logging captures all user interactions with datasets, including views, exports, and sharing, and can be streamed to an Azure Log Analytics workspace for centralized analysis. Once in Log Analytics, you can write KQL queries to filter activity records by IP address ranges and configure alerts to trigger when access originates from external IPs. This approach fully satisfies the requirement to log all dataset access and proactively monitor for suspicious external access in a shared capacity environment.

Why this answer

Option D is correct because Power BI activity logging captures dataset access events (including who accessed the dataset and from which client IP), and streaming those logs to Azure Log Analytics lets you query and alert on access originating from outside the corporate network, satisfying both the logging and external-access-flagging requirements. The other options do not fit: Azure SQL Auditing (A) only logs activity at the SQL Server level, not Power BI dataset access, and the source is on-premises SQL Server rather than Azure SQL. Microsoft Defender for Cloud Apps (B) enforces conditional access but does not provide the required access logging and external-IP flagging for the dataset.

Gateway logging (C) records gateway connectivity and query traffic, not end-user dataset access events or their source IPs.

25
Multi-Selectmedium

Which TWO of the following are valid methods to share a Power BI report with external users (outside your organization)? (Choose two.)

Select 2 answers
A.Export the report to PDF and email it to the external user.
B.Send the external user a direct link to the report via email; they can view it without any additional setup.
C.Invite the external user as a guest in your Microsoft Entra ID (Azure AD) and share the report directly with them.
D.Embed the report in a SharePoint Online page using the Power BI web part.
E.Use the 'Publish to web' option to create an embed code that can be placed on a public website.
AnswersC, E

Azure AD B2B collaboration allows sharing with external guests.

Why this answer

The correct answers are C and E. Option C: By inviting external users as guests in your Microsoft Entra ID (Azure AD) using Azure AD B2B, you can share Power BI reports directly with them without requiring them to have a Power BI license. Option E: 'Publish to web' creates a public embed code that anyone on the internet can view, making it suitable for sharing with external users.

Option A is incorrect because exporting to PDF creates a static file, not an interactive report, and is not a sharing method. Option B is incorrect because external users need to be set up as guests or use publish to web; a direct link alone will not work without proper authentication. Option D is incorrect because embedding in SharePoint Online requires the external user to have access to the SharePoint site, which typically involves additional setup such as guest access.

26
MCQeasy

Refer to the exhibit. You have a Power BI dataset with the JSON policy shown. You add a user to the USOnly role. What happens when that user views a report based on this dataset?

A.The user sees all rows in the Sales table.
B.The user sees only rows where Region is 'US' in the Sales table.
C.The user sees all rows but the SalesAmount column is hidden.
D.The user sees all rows in all tables of the dataset.
AnswerB

This is exactly what the role's DAX filter does. When a user maps to a role with a table-level filter like [Region] = 'US', Power BI applies that predicate to every query against the Sales table, returning only matching rows. All other rows are filtered out at the data source level (or in-memory during import), so the user's report and any aggregations are based only on US sales. This is the intended behavior of RLS.

Why this answer

Row-level security (RLS) restricts data: only rows where Region is 'US' are visible. Option A is wrong because RLS does not hide the entire table. Option C is wrong because RLS does not affect columns.

Option D is wrong because RLS does not affect other tables unless defined.

27
MCQhard

Your organization uses Power BI and has deployed Microsoft Purview Data Loss Prevention (DLP) policies. You want to prevent users from exporting data from Power BI reports that contain credit card numbers. What should you configure?

A.Configure row-level security (RLS) to hide the credit card column from users.
B.Create a DLP policy in Microsoft Purview that detects credit card numbers in Power BI and set the action to block export.
C.Apply a Microsoft Purview sensitivity label 'Highly Confidential' to the dataset and configure the label to prevent export.
D.Disable the 'Export to Excel' and 'Export to CSV' settings in the Power BI admin portal.
AnswerB

A Microsoft Purview DLP policy scoped to Power BI with a sensitive information type detecting credit card numbers enforces the block at export time. This satisfies the requirement because enforcement follows the data itself, regardless of which workspace or report contains it.

Why this answer

The correct option is B: create a DLP policy in Microsoft Purview that detects credit card numbers in Power BI and set the action to block export. Microsoft Purview DLP supports Power BI as a workload, so a policy can use the sensitive information type for credit card numbers (e.g., Credit Card Number) and enforce a block-export action when that data appears in Power BI reports. This directly targets the scenario's requirement of preventing export only when credit card numbers are present.

Option A does not fit because row-level security restricts which rows users can see, not export of sensitive content. Option C is not the right mechanism because sensitivity labels apply protection/policy to items but do not provide content-based detection of credit card numbers for blocking export in Power BI. Option D is too broad because disabling export settings in the Power BI admin portal blocks export for all content, not specifically reports containing credit card numbers.

28
MCQhard

Refer to the exhibit. A Power BI dataset has the scheduled refresh configuration shown in the JSON. The refresh fails on Monday, March 2, 2026. Who will be notified?

A.All workspace admins.
B.The dataset owner.
C.The Power BI tenant admin.
D.All users with access to the dataset.
AnswerB

The dataset owner is the correct recipient because MailOnFailure is a dataset-level property that triggers an email to the owner's Power BI account when a scheduled refresh fails. This notification is tied to the individual who originally created or has explicit ownership of the dataset, not to any broader group or role. Even when other users edit the dataset, the owner remains the fixed point of contact for the dataset's operational alerts, such as refresh failures.

Why this answer

The correct option is B, the dataset owner, because Power BI scheduled refresh failure notifications are sent by default to the owner of the dataset (the user who configured/owns the refresh), not to broader groups. In the exhibit's scheduled refresh configuration, no additional notification recipients are specified, so only the dataset owner receives the failure alert for the March 2, 2026 refresh. Workspace admins are not automatically notified of refresh failures unless they are the dataset owner or explicitly added as recipients.

The Power BI tenant admin and all users with dataset access are also not default recipients of scheduled refresh failure emails.

29
MCQmedium

You are a Power BI administrator. A user in your organization wants to share a report with an external user who does not have a Power BI license. You want to allow the external user to view the report without requiring them to sign in. What should you do?

A.Create a new user account in your Microsoft Entra ID for the external user and assign a Power BI Pro license.
B.Share the report directly with the external user's email address.
C.Invite the external user as a guest in Microsoft Entra ID, then share the report.
D.Use the 'Publish to web' option to generate an embed code and send the link to the external user.
AnswerD

Publishing to web is the only option that bypasses all authentication and licensing requirements entirely: it generates a publicly accessible embed code and a URL that anyone with the link can open in a browser, with no sign-in or Power BI license needed. This exactly matches the requirement of letting an external user view report content without credentials, but it is also risky because the report is effectively published on the internet for anyone who discovers the link to see, including potentially sensitive data. In production, this feature is appropriate only for non-confidential, public-facing content, and an administrator should ensure the tenant-level 'Publish to web' setting is allowed before using it.

Why this answer

The correct option is D: use 'Publish to web' to generate an embed code and send the link, because this feature creates a publicly accessible URL that renders the report anonymously, so the external user needs no Power BI license and no sign-in. It is designed exactly for anonymous, internet-wide viewing of non-sensitive reports. Option A is wrong because assigning a Power BI Pro license still requires the external user to authenticate with that account.

Option B is wrong because direct sharing requires the recipient to have a Power BI account/license and to sign in. Option C is wrong because guest access in Microsoft Entra ID still requires the external user to sign in with the guest identity.

30
MCQhard

You are a Power BI administrator. A Power BI dataset owner reports that the dataset is not refreshing automatically, but manual refreshes work fine. The dataset uses a cloud data source (Azure SQL Database) with OAuth2 credentials. What is the most likely cause?

A.Row-level security (RLS) is misconfigured.
B.The on-premises data gateway is offline.
C.The dataset exceeds the refresh limit for the assigned capacity.
D.The OAuth2 token used for the data source credentials has expired.
AnswerD

OAuth2 tokens are issued with a limited lifetime (usually 1 hour to 90 days depending on the provider) and are used for authentication when connecting to cloud data sources. When a token expires, the Power BI service cannot refresh the dataset automatically because it lacks the ability to prompt for reauthentication. A manual refresh opens a dialog that lets the dataset owner re-authenticate, renewing the token and successfully completing the refresh.

Why this answer

The correct answer is D: the OAuth2 token used for the data source credentials has expired. In Power BI, scheduled refreshes run unattended using the stored credentials; if the OAuth2 access/refresh token for the Azure SQL Database source is no longer valid, the scheduled refresh fails while an interactive manual refresh can still succeed because the user re-authenticates on the spot. Options A, B, and C do not fit: RLS misconfiguration would typically cause permission or data-visibility errors rather than a refresh failure, an on-premises data gateway is irrelevant for a cloud data source like Azure SQL Database, and exceeding the capacity refresh limit would affect both scheduled and manual refreshes, not just automatic ones.

31
Multi-Selectmedium

You are a Power BI administrator. Your organization has a Power BI Premium capacity. You need to configure a new workspace to use a specific capacity and ensure that only users with the 'Contributor' role can publish content to the workspace, while users with the 'Viewer' role can only view reports. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Enable the 'Allow contributors to update the app' setting in the workspace settings.
B.Assign the workspace to the Premium capacity in the workspace settings.
C.Add users to the workspace and assign them the appropriate roles (Contributor, Viewer).
D.Configure row-level security (RLS) on the dataset to restrict data access based on user roles.
E.Create a sensitivity label and apply it to the workspace.
AnswersB, C

Assigning the workspace to a Premium capacity ensures that the workspace uses the dedicated resources of that capacity, which is required for features like larger datasets and increased refresh rates. This action is necessary to meet the requirement of using a specific capacity. It is done through the workspace settings in the Power BI service, where you can select the capacity from a dropdown list.

Why this answer

To configure the workspace to use a specific Premium capacity, assign the workspace to that capacity in the workspace settings. To control publishing and viewing permissions, add users to the workspace with the Contributor or Viewer roles as appropriate. These two actions meet the requirements.

Exam trap

The trap here is confusing workspace roles with dataset-level security like RLS, but RLS does not control publishing permissions.

32
MCQeasy

Refer to the exhibit. The Power BI admin settings are shown. A user reports that they cannot share a dashboard with an external partner. What is the most likely reason?

A.The 'exportDataEnabled' setting is disabled.
B.The 'publishToWebEnabled' setting is disabled.
C.The 'workspaceCreationEnabled' setting is disabled.
D.The 'externalSharingEnabled' setting is disabled.
AnswerD

The 'externalSharingEnabled' setting is the tenant-level switch that directly controls whether users can share dashboards and reports with individuals outside the organization. When disabled, the Share option for external email addresses is blocked, and any existing external shares become inaccessible. Because the question describes an inability to share with external users, this disabled setting precisely explains the behavior and is the correct answer.

Why this answer

The correct option is D, the 'externalSharingEnabled' setting is disabled. Sharing a dashboard with an external partner requires the tenant-level external sharing setting to be enabled, so if it is disabled, the user cannot share with recipients outside the organization. The other options do not fit: exportDataEnabled controls exporting data, publishToWebEnabled controls public web publishing, and workspaceCreationEnabled controls creating workspaces, none of which directly govern sharing a dashboard with an external partner.

33
MCQeasy

You need to grant a user the ability to manage permissions, add members, and edit content in a Power BI workspace, but not delete the workspace. Which role should you assign?

A.Member
B.Admin
C.Contributor
D.Viewer
AnswerA

The Member role in a Power BI workspace grants the ability to manage permissions—adding or removing members, assigning roles, and editing content—without allowing workspace deletion. This precisely matches the requirement to manage permissions while retaining the workspace. Therefore, Member is the correct assignment.

Why this answer

The Member role is correct because in a Power BI workspace it grants the ability to add members, manage permissions, and edit and publish content, while it does not allow deleting or renaming the workspace, which matches the stated requirement. Admin would be too permissive since it can delete the workspace and manage all aspects of it. Contributor allows editing and publishing content but cannot add members or manage permissions.

Viewer only provides read access to content and cannot edit or manage anything.

34
MCQeasy

You are a Power BI administrator. A user reports that they cannot refresh a dataset that connects to an on-premises SQL Server using a gateway. The dataset was previously refreshing successfully. You need to ensure that the dataset can refresh again. What should you do first?

A.Increase the dataset refresh timeout in the dataset settings.
B.Check the gateway cluster status and ensure the gateway is online and has the latest version.
C.Republish the dataset from Power BI Desktop.
D.Re-enter the data source credentials in the dataset settings.
AnswerB

The first step in troubleshooting a refresh failure is to verify that the gateway is operational. If the gateway is offline or outdated, it cannot connect to the on-premises data source. Checking the gateway status in the Power BI service under 'Manage gateways' will reveal if the gateway is online and if an update is available. This is a common cause of refresh failures.

Why this answer

The most likely cause of a sudden refresh failure for an on-premises data source is an issue with the gateway. Checking the gateway status is the first troubleshooting step because if the gateway is offline or outdated, the refresh will fail. Other steps like re-entering credentials or increasing timeout are secondary.

Exam trap

The trap here is jumping to credential or timeout issues without first verifying the gateway health, which is a common oversight.

35
MCQmedium

You have a Power BI dataset that uses a live connection to an Azure Analysis Services (AAS) model. The AAS model has object-level security (OLS) that hides certain measures. Your Power BI report users need to see those measures. What should you do?

A.Use Power BI Desktop object-level security to override AAS settings.
B.Configure row-level security (RLS) in Power BI to grant access.
C.Change the dataset to import mode and then apply OLS in Power BI.
D.Modify the object-level security roles in Azure Analysis Services to include the measures.
AnswerD

Since the Power BI dataset uses a live connection, it fully relies on the Azure Analysis Services tabular model for security enforcement. To make the measures visible to users, you must edit the object-level security roles in AAS and grant those roles read permission on the measure metadata objects that are currently hidden. This ensures that the measures appear in the field list and are accessible to queries from Power BI for the assigned users.

Why this answer

The correct answer is D: Modify the object-level security roles in Azure Analysis Services to include the measures. Because the Power BI dataset uses a live connection, all security—including OLS that hides measures—is enforced by the AAS model itself, so the only way to expose those measures to report users is to edit the OLS roles in AAS to grant access to them. Power BI cannot override or bypass AAS security in a live connection, so options A and B are ineffective, and option C would require abandoning the live connection and rebuilding the model, which is unnecessary and changes the architecture.

36
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps to monitor Power BI activity. You need to receive an alert when a user exports a report with a sensitivity label of 'Highly Confidential' from Power BI service. What should you configure?

A.Set up a Microsoft 365 compliance alert for data export events.
B.Enable audit logging in Power BI and configure alerts in Microsoft Sentinel.
C.Apply a protection policy in Microsoft Purview that blocks export for 'Highly Confidential' labels.
D.Create an activity policy in Microsoft Defender for Cloud Apps.
AnswerD

Defender for Cloud Apps activity policies are purpose-built for monitoring cloud app usage and can detect Power BI export activities in near real time. You can create a policy that filters on Activity type 'Export' and a sensitivity label of 'Highly Confidential' (via Microsoft Information Protection integration), then trigger a custom alert. This provides the precise alerting for data exfiltration events that the scenario requires.

Why this answer

The correct option is D: create an activity policy in Microsoft Defender for Cloud Apps. Defender for Cloud Apps connects to Power BI via the app connector and its activity policies can trigger alerts on specific user activities, such as downloading or exporting a report, filtered by the sensitivity label 'Highly Confidential'. Option A is wrong because Microsoft 365 compliance alerts do not natively target Power BI report export events with sensitivity-label conditions.

Option B is wrong because Power BI audit logging plus Microsoft Sentinel requires custom analytics rules and does not directly provide the built-in activity-policy alerting for this scenario. Option C is wrong because a Microsoft Purview protection policy blocks export rather than generating the requested alert.

37
MCQhard

Refer to the exhibit. You are reviewing a Power BI activity log entry. What action should you take to ensure compliance if the user who created the report should not have access to 'Confidential' data?

A.Delete the report immediately.
B.Change the sensitivity label on the report to 'General'.
C.Investigate the user's permissions on the dataset 'SalesDataset' to verify they are authorized to access confidential data.
D.Ignore the event because the report creation is logged but not necessarily a violation.
AnswerC

Investigating the user's permissions on SalesDataset is the correct first step because the activity log shows only the outcome (a report created with a Confidential label), not the authorization chain. The analyst should check the user's effective permissions through workspace roles, dataset sharing, and row-level security, using the lineage view or the 'Manage permissions' page. Only after confirming whether the user is allowed to see the underlying data can you decide to take action, thereby adhering to the principle of least privilege and proper incident response.

Why this answer

The correct action is C: investigate the user's permissions on the dataset 'SalesDataset' to verify they are authorized to access confidential data. In a Power BI activity log, a report creation event alone does not prove a compliance breach; the actual access control is enforced through the dataset's permissions and the sensitivity label applied to the data, so you must confirm whether the user legitimately has access to 'Confidential' data before taking any remediation. Option A is wrong because deleting the report is a destructive action that does not address the underlying permission issue and could destroy legitimate work.

Option B is wrong because changing the sensitivity label to 'General' would misclassify the data and could itself create a compliance violation. Option D is wrong because simply ignoring the event fails to verify whether the user's access was authorized, which is the required compliance check.

38
MCQhard

You are a Power BI administrator. Your organization uses Microsoft Purview sensitivity labels integrated with Power BI. A report author applies a sensitivity label named 'Confidential' to a Power BI dataset. Later, the author exports a Power BI report that uses this dataset to a PDF file. You need to ensure that the exported PDF file retains the same sensitivity label and protection settings as the dataset. What should you do?

A.Configure the dataset to use row-level security (RLS) so that only authorized users can export the report.
B.Enable the tenant setting 'Apply sensitivity labels to exported data' in the Power BI admin portal.
C.Instruct the author to manually apply the same sensitivity label to the PDF file after exporting.
D.Publish the report to a Power BI app and require users to access it through the app.
AnswerB

This tenant setting ensures that when data is exported from Power BI to supported formats like PDF, the sensitivity label from the dataset is automatically applied to the exported file. This maintains the protection and compliance requirements. It is the correct configuration to enforce label inheritance for exports, as long as the label is applied to the dataset and the export format supports labeling.

Why this answer

Enabling the tenant setting 'Apply sensitivity labels to exported data' ensures that exported files, such as PDFs, inherit the sensitivity label from the dataset. This maintains protection and compliance. The other options do not achieve automatic label inheritance for exports.

Exam trap

The trap here is assuming that sensitivity labels are automatically applied to all exports without any tenant configuration, but the setting must be enabled.

39
MCQeasy

You create a Power BI report that uses a live connection to an Azure Analysis Services (AAS) model. You want to enforce row-level security defined in the AAS model. What should you do?

A.Use object-level security (OLS) instead.
B.No additional configuration needed; RLS from AAS is automatically applied.
C.Use Power BI service to create RLS roles on the dataset.
D.Define the same RLS roles in Power BI Desktop and publish.
AnswerB

When a Power BI report uses a live connection to Azure Analysis Services (AAS) or SQL Server Analysis Services (SSAS), row-level security defined in the source tabular model is enforced directly by the source. The live connection passes the authenticated user's identity to the server, which then evaluates the RLS roles and filters rows before returning data to Power BI. There is no need for additional configuration in Power BI; the source model is the single authority for data security, ensuring consistent and secure row filtering across all reports that connect live.

Why this answer

Option B is correct because when a Power BI report uses a live connection to an Azure Analysis Services (AAS) model, the report does not contain its own dataset or RLS definitions; instead, it queries the AAS model directly, so the row-level security roles and memberships defined in the AAS model are automatically enforced for the connecting user. This is the standard behavior for live connections to Analysis Services, where security is managed at the source model rather than in Power BI. Option A is wrong because object-level security (OLS) restricts columns/tables, not rows, and is not a substitute for RLS.

Option C is wrong because you cannot create RLS roles on the dataset in the Power BI service when the report uses a live connection, since there is no imported dataset in Power BI to configure. Option D is wrong because defining RLS roles in Power BI Desktop and publishing applies only to imported or DirectQuery datasets hosted in Power BI, not to live-connected AAS models.

40
MCQhard

A Power BI administrator needs to allow an external partner organization to access a specific report without requiring them to have Power BI Pro licenses. The report is stored in a workspace assigned to a Premium capacity. What is the correct configuration?

A.Add the external users as members of the workspace and assign them a Viewer role
B.Publish the report to the web and share the public link
C.Invite the external users as guest users in Microsoft Entra ID, add them to the workspace with Viewer role, and share the report or app
D.Embed the report in a secure portal using the 'embed for your organization' option
AnswerC

This is the correct approach because you first invite the external partner as a B2B guest user in Microsoft Entra ID, which creates a secure identity in your tenant for them. After they accept the invitation, you can add them to the workspace and assign the Viewer role, restricting them to read-only access. Finally, you share the report or app directly with them, and because the workspace resides in Premium capacity, the guest users can view it without needing their own Power BI Pro licenses. This method ensures authenticated, authorized access while maintaining full security and auditability.

Why this answer

Option C is correct because it uses Microsoft Entra B2B guest invitations so external partners authenticate with their own credentials, and then grants them Viewer access to the workspace/app; with the workspace on Premium capacity, guests can consume the content without needing Power BI Pro licenses. Adding them as workspace members with Viewer role alone (A) does not establish the required external identity in the tenant. Publishing to the web (B) creates an anonymous public link, which is insecure and not appropriate for a specific partner. 'Embed for your organization' (D) is for internal users with Power BI accounts and does not provide the licensing-free external sharing scenario.

41
MCQmedium

A Power BI administrator needs to audit which users have exported data from a specific report in the last 30 days. What is the most efficient way to retrieve this information?

A.Use the Microsoft Purview compliance portal to search for 'Export' events.
B.Check the report's usage metrics report for export counts.
C.Query the Power BI activity log using the audit log search in the Microsoft 365 Defender portal.
D.Review the 'Export to Excel' metrics in the Azure Monitor for Power BI Premium.
AnswerC

The Power BI activity log records every user export action as an event, including the user ID, timestamp, report name, and export type, and these events are ingested into the Microsoft 365 unified audit log. Using the audit log search in the Microsoft 365 Defender portal, an administrator can filter for Power BI export operations and retrieve a complete, user-level audit trail. This is the authoritative source for answering the audit question because it directly captures the exact export events needed.

Why this answer

The correct option is C: query the Power BI activity log using the audit log search in the Microsoft 365 Defender portal, because Power BI audit events such as ExportReport, ExportData, and ExportToFile are centralized in the unified Microsoft 365 audit log, which supports filtering by user, date range, and activity type for the last 30 days. This is the most efficient way to identify exactly which users exported data from a specific report, since the audit log records per-user, per-item activity. Option A is not the right tool because Microsoft Purview compliance portal search is oriented toward compliance and eDiscovery scenarios rather than granular Power BI report export auditing.

Option B only provides aggregated usage metrics (view counts and similar statistics) without per-user export detail. Option D is incorrect because Azure Monitor for Power BI Premium focuses on capacity and resource telemetry, not user-level export auditing.

42
MCQhard

Your organization uses Power BI Premium capacity. You notice that reports are slow during peak hours. You need to identify which workspaces are consuming the most CPU resources on the capacity. What should you use?

A.Open the dataset in Power BI Desktop and view the performance analyzer.
B.Install and review the Power BI Premium Capacity Metrics app.
C.Enable diagnostic logging in Azure Monitor for the capacity.
D.Check the 'Capacity settings' in the Power BI admin portal.
AnswerB

The Premium Capacity Metrics app is the dedicated monitoring solution for Power BI Premium, prebuilt with per-workspace metrics for CPU time, memory consumption, refresh durations, and query performance. Admins install it from AppSource or the admin portal, and it connects to the capacity's metadata to provide a breakdown of resource usage by workspace and operation. This directly addresses the need to detect which areas of the capacity are under heavy load.

Why this answer

The Power BI Premium Capacity Metrics app is the correct tool because it is purpose-built to monitor Premium capacity health and provides per-workspace breakdowns of resource consumption, including CPU usage over time, so you can pinpoint which workspaces are driving load during peak hours. It surfaces metrics like CPU utilization, memory usage, query durations, and dataset refreshes at both the capacity and workspace level. In contrast, Power BI Desktop's Performance Analyzer (option A) only profiles a single report's visuals and queries on your local machine, not capacity-wide CPU consumption.

Azure Monitor diagnostic logging (option C) can capture activity logs and metrics, but it requires manual setup and analysis and does not directly present workspace-level CPU rankings. The Capacity settings page in the admin portal (option D) only lets you configure capacity size, admins, and workload settings; it does not report which workspaces consume the most CPU.

43
MCQhard

You are a Power BI administrator. Your organization uses Microsoft Purview to manage sensitivity labels. You need to ensure that when a report is exported to PDF, the sensitivity label is automatically applied to the PDF file. What should you configure?

A.Enable the tenant setting 'Apply sensitivity labels to exported data' in the Power BI admin portal.
B.Enable 'Microsoft Purview Information Protection' file encryption settings.
C.Set the default sensitivity label for the workspace to 'Confidential'.
D.Configure a Microsoft Purview auto-labeling policy for Power BI reports.
AnswerA

The tenant-level admin setting named 'Apply sensitivity labels to exported data' directly controls whether an export carries the source report's sensitivity label. When enabled, files exported from labeled items in the Power BI service receive the corresponding label, which preserves data classification and protection outside the service. Without this setting, exported content loses the label even if the original report is labeled.

Why this answer

Option A is correct because the Power BI tenant setting 'Apply sensitivity labels to exported data' (in the Power BI admin portal) is specifically what causes the sensitivity label on a report to be inherited by exported files such as PDF, PPTX, and XLSX. When this setting is enabled, Power BI propagates the report's label to the exported artifact so the PDF carries the same protection. Option B is incorrect because Purview Information Protection encryption settings govern encryption behavior, not the propagation of labels to Power BI exports.

Option C is incorrect because setting a workspace default label only assigns labels to new items in that workspace; it does not control label inheritance on exported PDFs. Option D is incorrect because a Purview auto-labeling policy applies labels based on content inspection and does not govern the export-labeling behavior of Power BI reports.

44
MCQmedium

You have a Power BI workspace named Sales. You need to ensure that only users in the Finance security group can view reports in this workspace, while members of the Sales team can edit and share content. What should you do?

A.Add Finance as Viewer, Sales as Member.
B.Add Finance as Contributor, Sales as Member.
C.Add Finance as Viewer, Sales as Admin.
D.Use row-level security to restrict Finance data, add both as Member.
AnswerA

Assigning Finance the Viewer role grants read-only report access, while the Sales team as Members can edit and share content. This satisfies both constraints simultaneously, since workspace roles govern exactly these permissions without broader tenant-level access.

Why this answer

Workspace roles in Power BI are designed to grant specific permissions: Viewer allows read-only access, ideal for Finance who only need to view reports; Member allows editing and sharing, which matches the Sales team's requirements. Option B is wrong because Contributor role cannot share content, which Sales needs. Option C is wrong because Admin grants full control, including managing permissions, which is unnecessary and excessive.

Option D is wrong because row-level security (RLS) controls data access within reports, not workspace-level permissions.

Exam trap

A common trap is confusing Contributor with Member. Contributor can edit but not share, while Member can both edit and share. Also, a candidate might think Viewer is insufficient for Finance, but it correctly restricts access.

45
MCQhard

You manage a Power BI tenant. A workspace named 'Finance' contains a dataset that uses an on-premises SQL Server data source via an on-premises data gateway. The gateway is configured with a single data source that uses a SQL Server account for authentication. You need to ensure that when users view reports based on this dataset, they see only data for their own department, and the filtering must be enforced at query time without modifying the dataset. What should you do?

A.Create separate reports for each department and distribute them via apps.
B.Configure column-level security on the dataset to hide sensitive columns.
C.Use the gateway's 'Add users to data source' feature to map each user to a specific SQL Server login.
D.Configure row-level security (RLS) on the dataset and map users to roles.
AnswerD

RLS defined in the dataset (either in Power BI Desktop or by using Tabular Editor) filters data based on the identity of the user viewing the report. When users access the report, Power BI passes their identity to the dataset, and the RLS rules restrict the rows they can see. This is enforced at query time and does not require changes to the underlying data source or gateway configuration.

Why this answer

Row-level security (RLS) is the correct approach because it dynamically filters data based on the user's identity at query time. It is defined within the dataset and does not require changes to the data source or gateway. Other options either duplicate content, do not enforce per-user filtering, or address column-level rather than row-level security.

Exam trap

The trap here is confusing row-level security with column-level security or thinking that gateway authentication can enforce per-user data filtering.

46
MCQmedium

You are a Power BI administrator. The company has a premium capacity that many users publish reports to. Recently, users have reported that some reports are slow to load. You suspect that the capacity is being overused by certain large datasets. You need to identify which workspaces and datasets are consuming the most memory and CPU resources on the capacity. You want to use a tool that provides historical metrics and can be queried. What should you do?

A.Install the Power BI Premium Capacity Metrics app from AppSource.
B.Use Performance Analyzer in Power BI Desktop for each report.
C.Use the Power BI admin portal to view capacity metrics in real-time.
D.Enable Power BI activity logs and query Log Analytics for capacity metrics.
AnswerA

The Premium Capacity Metrics app from AppSource is Microsoft's official monitoring solution for Premium capacities. It periodically pulls telemetry from the capacity metrics API, stores it in a dedicated dataset, and presents historical CPU, memory, query counts, and refresh statistics per workspace and dataset. The underlying data is DAX-queryable, enabling a three-month retrospective analysis, which makes it the only listed tool that satisfies the stated need for historical resource-level metrics.

Why this answer

The Power BI Premium Capacity Metrics app (option A) is the correct tool because it is installed from AppSource and provides historical, queryable metrics on memory and CPU consumption per workspace and dataset on a Premium capacity, directly addressing the need to find the top resource consumers. It surfaces dataset sizes, refresh durations, CPU usage, and memory usage over time, which is exactly what the administrator requires. Option B, Performance Analyzer, only measures rendering and query performance of individual reports in Power BI Desktop and does not give capacity-wide historical resource metrics.

Option C, the admin portal, shows current capacity health and utilization but not the detailed historical, queryable per-dataset metrics needed. Option D, activity logs in Log Analytics, capture user and admin activity events, not the granular memory and CPU consumption metrics of datasets on the capacity.

47
MCQhard

Your organization uses Power BI with a shared capacity (no Premium capacity). You need to implement row-level security (RLS) on a dataset that is used by multiple reports. Which of the following is a limitation you must consider?

A.RLS is not supported in shared capacity; you need a Premium license.
B.RLS roles must be created in the Power BI service after publishing; they cannot be created in Power BI Desktop.
C.RLS cannot be applied when the dataset uses DirectQuery to a data source that requires single sign-on (SSO) because the user's identity is passed through, and the source must enforce RLS.
D.RLS can only be applied to tables that are imported, not to tables using DirectQuery.
AnswerC

When a DirectQuery dataset connects to a source requiring SSO, Power BI passes the signed-in user's identity to the source database and does not apply static RLS filters from the role. This is because the queries are executed in the source engine under the user's credentials, so the source itself must implement row-level security (e.g., via security predicates). Without SSO, Power BI can still apply RLS to DirectQuery tables by adding filter conditions to the generated queries.

Why this answer

The correct option is C: RLS cannot be applied when the dataset uses DirectQuery to a data source that requires single sign-on (SSO) because the user's identity is passed through, and the source must enforce RLS. In a shared capacity, Power BI does not perform RLS for DirectQuery sources that use SSO; instead, it passes the user's credentials to the source, so the source system must enforce its own row-level security. Options A, B, and D are incorrect: RLS is supported in shared capacity, roles can be created in Power BI Desktop, and RLS can be applied to DirectQuery tables (with the SSO caveat noted in C).

Exam trap

The key trap is that while RLS works with DirectQuery in general, when SSO is enabled, the user's identity flows to the source, and Power BI's RLS cannot filter rows—the source must handle security.

48
MCQeasy

You have a Power BI dataset that connects to an Azure SQL Database. You need to use single sign-on (SSO) so that users' identities are passed to the database. What authentication method should you configure?

A.Windows authentication
B.Key authentication
C.OAuth2 with Microsoft Entra ID
D.Basic authentication with a service account
AnswerC

OAuth2 with Microsoft Entra ID is the correct choice because Power BI can obtain an OAuth2 access token from Microsoft Entra ID on behalf of the signed-in user and pass that token to Azure SQL Database. This enables true single sign-on (SSO) because the database sees the individual user's identity rather than a shared service account. Consequently, row-level security (RLS) and audit logs reflect the actual user, and conditional access policies in Entra ID are enforced.

Why this answer

OAuth2 with Microsoft Entra ID (option C) is correct because Power BI's SSO to Azure SQL Database relies on Microsoft Entra ID token-based authentication, where the user's Entra ID identity is passed through to the database via OAuth2, enabling row-level security and auditing per user. Azure SQL Database natively supports Entra ID authentication, and Power BI can forward the user's token when the data source is configured with DirectQuery and SSO enabled. Windows authentication (A) is not applicable since Azure SQL Database does not accept on-premises Windows/Kerberos credentials directly without a gateway and Entra ID setup.

Key authentication (B) uses a shared key rather than a user identity, so it cannot provide SSO. Basic authentication with a service account (D) uses a single shared credential, not the individual user's identity, so it also fails to meet the SSO requirement.

49
MCQhard

Your organization is deploying Power BI content to multiple stages (dev, test, prod) using deployment pipelines. You need to ensure that test data is not visible to production users. What is the best approach?

A.Manually replace the dataset in the production workspace after deployment.
B.Apply row-level security to filter test data in production.
C.Create separate Power BI tenants for each stage.
D.Use deployment pipelines with separate datasets per stage and configure data source parameters to point to different databases.
AnswerD

Using deployment pipelines with separate datasets per stage and configuring data source parameters to point to different databases is the correct approach because it automates the propagation of reports, dashboards, and datasets across environments while preserving the separation of data at each stage. By defining parameters for the server and database in Power Query, you can deploy the same report package but repoint each stage to its own database, ensuring test and QA workloads never hit production data and enabling safe validation before final release.

Why this answer

Option D is correct because deployment pipelines support deployment rules that let you bind each stage's dataset to a different data source via parameters, so the production stage connects to the production database and never exposes test data. Configuring data source parameters per stage is the standard mechanism for environment-specific connections in Power BI deployment pipelines. Option A is wrong because manually swapping datasets after deployment is error-prone and not a pipeline feature.

Option B is wrong because row-level security filters rows for users, not test versus production data sources, and would still leave test data in the production dataset. Option C is wrong because separate tenants per stage is an extreme, costly approach that deployment pipelines are specifically designed to avoid.

50
MCQeasy

A user reports that they cannot publish a Power BI Desktop file to the Power BI service. The error message indicates insufficient permissions. The user is a member of a workspace and has the Viewer role. What is the most likely cause?

A.The user has the Viewer role in the workspace
B.Row-level security (RLS) is preventing the user from seeing the data
C.The user does not have a Power BI Pro license
D.The .pbix file is stored on a network share that restricts write access
AnswerA

In the Power BI service, workspace roles form a permission hierarchy: Admin, Member, Contributor, and Viewer. All roles except Viewer can create, edit, and publish items in the workspace; the Viewer role grants only read-only access and does not include content management rights. Because the user is assigned Viewer, the service rejects the publish attempt with an insufficient-permissions error, which directly matches the symptom.

Why this answer

The correct answer is A: the user has the Viewer role in the workspace. In Power BI, the Viewer role only allows viewing and interacting with existing content; it does not grant permission to publish or import .pbix files into the workspace, which requires at least the Contributor role. That directly matches the reported 'insufficient permissions' error when attempting to publish from Power BI Desktop.

Option B is incorrect because RLS filters data rows for viewers and would not block publishing. Option C is not the most likely cause, since a Pro license is needed to publish to shared workspaces but the error specifically points to workspace role permissions. Option D is unrelated, as the .pbix file's storage location does not determine Power BI service publishing rights.

Exam trap

The trap is that users often confuse data access permissions (RLS) with workspace permissions. The question tests whether you know that Viewer role cannot publish, regardless of data access or licensing.

51
MCQmedium

You have a Power BI report that uses a DirectQuery dataset. You need to ensure that users see only the data relevant to their department. What should you implement?

A.Q&A features to restrict natural language queries.
B.Row-level security (RLS) with DAX filter expressions.
C.Object-level security (OLS) to hide tables.
D.Data lineage view to control access.
AnswerB

DirectQuery datasets push filters to the source, and row-level security with DAX filter expressions is evaluated server-side, restricting each user to their department's rows. This satisfies the requirement that users see only data relevant to their department.

Why this answer

Row-level security (RLS) is the correct approach because it filters data at the query level based on the user's identity. In a DirectQuery model, RLS translates DAX filter expressions into source queries, ensuring that each user only sees rows relevant to their department without duplicating reports or datasets.

Exam trap

The trap here is that candidates confuse row-level security (RLS) with object-level security (OLS), thinking OLS can filter rows when it only hides entire objects like tables or columns.

How to eliminate wrong answers

Option A is wrong because Q&A features allow natural language queries but do not restrict data visibility; they only control how users can phrase questions. Option C is wrong because object-level security (OLS) hides entire tables or columns, not rows, so it cannot filter data by department. Option D is wrong because data lineage view is a metadata visualization tool for impact analysis, not a security mechanism to control user access to data.

52
Multi-Selecthard

A Power BI administrator needs to enforce that all datasets published to the service use certified data sources only. Which two settings should be configured? (Choose two.)

Select 2 answers
A.Use Microsoft Sentinel to audit Power BI activity logs and flag non-certified data sources.
B.Enable 'Certification' for dataflows in the Power BI tenant settings.
C.Enable 'Certification' for data sources in the Power BI tenant settings.
D.Configure row-level security (RLS) on all datasets.
E.Set up B2B guest user permissions to restrict external data sources.
AnswersB, C

Enabling the 'Certification' tenant setting for dataflows activates the endorsement feature that lets authorized reviewers officially certify reusable dataflows. Once certified, those dataflows are the trusted building blocks that dataset authors can be required to use, and the tenant switch is a prerequisite for applying governance policies that mandate certified dataflows. Without this setting, dataflow certification is impossible, making it the correct control for enforcing that datasets use only certified dataflows.

Why this answer

To enforce that all datasets use certified data sources only, an administrator should enable certification for data sources (Option C) and enable certification for dataflows (Option B). Option C allows data source owners to certify data sources, and Option B allows dataflow owners to certify dataflows. Combined, these settings promote the use of certified components.

Option A (monitoring with Sentinel) only detects non-certified sources, it does not enforce. Option D (RLS) and Option E (B2B permissions) are unrelated to data source certification.

53
MCQeasy

You need to audit which users have accessed a specific Power BI dashboard in the last 30 days. What should you use?

A.Microsoft Sentinel.
B.Power BI Activity Log (audit log) in the Microsoft 365 admin center.
C.Microsoft Purview compliance portal.
D.Power BI REST API 'Get Datasets' endpoint.
AnswerB

The Power BI activity log is part of the Microsoft 365 unified audit log and serves as the authoritative record for user actions such as viewing a dashboard or opening a report. This log is visible in the Microsoft 365 admin center under the audit log search, where you can filter by activities like ViewDashboard and ViewReport to see who accessed the item, when, and from which client. The audit log automatically captures the user ID, item name, and timestamp for every Power BI interaction, provided auditing is enabled in your tenant. This makes the activity log in the Microsoft 365 admin center the correct answer for auditing user access to a specific Power BI dashboard.

Why this answer

The Power BI Activity Log (audit log) in the Microsoft 365 admin center is the correct tool because it records user activities such as viewing dashboards and reports, and it can be filtered by date range (e.g., last 30 days) and by item to identify exactly which users accessed a specific dashboard. It captures events like ViewDashboard and ViewReport with user, timestamp, and artifact details, which is precisely what this audit requires. Microsoft Sentinel is a SIEM for security analytics and would only have this data if the Power BI logs were explicitly ingested, so it is not the direct source.

Microsoft Purview compliance portal focuses on data governance, classification, and compliance rather than Power BI usage auditing. The Power BI REST API 'Get Datasets' endpoint only returns dataset metadata and does not provide user access activity.

54
MCQeasy

You are a Power BI administrator. A user reports that they are unable to share a dashboard with an external user from a partner organization. The external user has a Microsoft Entra ID account in their own tenant. What is the most likely reason?

A.External users cannot view Power BI content; they need a Power BI license.
B.The 'Share content with external users' tenant setting is disabled.
C.The dashboard is based on a dataset that uses RLS and the external user is not in the role.
D.External users must be added as members in the same tenant.
AnswerB

The 'Share content with external users' tenant setting is a Power BI admin control that, when disabled, prevents users from sharing dashboards, reports, and apps with anyone outside the organization. If this setting is turned off, the share option for external users will be unavailable or result in an error, even if the external user is already a guest in the tenant. To resolve the issue, the administrator must enable this setting in the Power BI admin portal.

Why this answer

The correct answer is B: the 'Share content with external users' tenant setting is disabled. In Power BI, an administrator must enable the 'Share content with external users' setting in the Admin portal (Tenant settings) before users can share dashboards and reports with Microsoft Entra ID (Azure AD) B2B guest users from other tenants, so if it is off, sharing attempts fail regardless of the external user's account. Option A is wrong because external users can view Power BI content once properly licensed and invited; a license may be required but that is not the most likely blocker described.

Option C is wrong because RLS would only filter data for an already-authorized viewer, not prevent the share action itself. Option D is wrong because external users are added as B2B guest users in the host tenant, not as members, and this is not the reason sharing is blocked.

55
MCQeasy

You need to grant a user the ability to manage permissions on a Power BI workspace but not to view or edit the content. What minimum role should you assign?

A.Contributor
B.Viewer
C.Member
D.Admin
AnswerD

Admin can manage permissions, but it also allows viewing and editing content; there is no role that manages permissions without content access.

Why this answer

The Admin role is the only workspace role that can manage permissions and membership, even though it also allows viewing and editing content. The minimum role required to manage permissions is Admin. Option A is incorrect because Contributor can view and edit content but cannot manage permissions.

Option B is incorrect because Viewer can only view content and cannot manage permissions. Option C is incorrect because Member can view and edit content but cannot manage permissions.

Exam trap

Note that the Admin role still allows viewing and editing content; it is not a permissions-only role. The minimum role to manage permissions is Admin, but it comes with full content access.

56
Multi-Selecthard

Which THREE of the following are required to configure Microsoft Purview Information Protection sensitivity labels for Power BI? (Choose three.)

Select 3 answers
A.Each user must have a Power BI Pro license.
B.Have a Power BI Premium capacity assigned to the workspace.
C.Users must have appropriate permissions (e.g., Azure Information Protection rights) to apply labels.
D.Sensitivity labels must be published in the Microsoft 365 Compliance Center.
E.Enable sensitivity labels in the Power BI admin tenant settings.
AnswersC, D, E

To apply sensitivity labels, a user's identity must have the appropriate rights defined in the label itself via Azure Information Protection (now Microsoft Purview Information Protection). This is usually accomplished by adding the user to the label's 'Viewer' or 'Editor' permission list, which grants them the right to see and modify content protected by that label. Without these rights, the label will appear in the picker but the user will receive an error when trying to apply it, because the label's encryption policy forbids them from doing so. Delegating these rights to individual users or groups is an explicit configuration action that must be performed outside of Power BI.

Why this answer

Option C is correct because applying a sensitivity label to a Power BI artifact requires the user to hold the appropriate usage rights, such as Azure Information Protection (AIP) rights, so the label's protection settings can be enforced on the item. Option D is correct because sensitivity labels must first be created and published to the relevant users from the Microsoft 365 Compliance Center (Microsoft Purview compliance portal) before they become available for use in Power BI. Option E is correct because an admin must enable sensitivity labels for Power BI in the Power BI admin portal tenant settings; otherwise the labeling feature remains unavailable in the service and Desktop.

Option A is not required because sensitivity labels are not gated on a Power BI Pro license specifically, and Option B is not required because labeling works without assigning the workspace to a Power BI Premium capacity.

57
Multi-Selecthard

You are a Power BI administrator. You need to configure a data loss prevention (DLP) policy in Microsoft Purview to protect sensitive information in Power BI. The policy must detect and restrict sharing of reports that contain credit card numbers. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Configure a data gateway to scan Power BI datasets for sensitive data.
B.Enable the tenant setting 'Allow users to apply sensitivity labels to their content'.
C.Create a DLP policy in Microsoft Purview that applies to the Power BI workload.
D.Define a sensitive information type for credit card numbers and add it to the DLP policy rules.
E.Publish the DLP policy to all users in the organization.
AnswersC, D

A DLP policy must be created in Microsoft Purview and scoped to the Power BI workload to monitor and protect Power BI content. This is the foundational step to enable detection and enforcement for Power BI items. Without this policy, no DLP rules will apply to Power BI.

Why this answer

To detect and restrict sharing of Power BI reports containing credit card numbers, you must create a DLP policy that applies to the Power BI workload and define rules that include a sensitive information type for credit card numbers. These two actions enable detection and enforcement. Other actions, such as enabling label application or using a gateway, do not provide DLP detection for Power BI content.

Exam trap

The trap here is assuming that enabling sensitivity labels or using a data gateway will provide DLP detection, when DLP requires a policy scoped to Power BI with appropriate sensitive information types.

58
Multi-Selecteasy

Which TWO methods can you use to share a Power BI report with external users who do not have a Power BI Pro license? (Choose two.)

Select 2 answers
A.Embed the report in a secure portal using 'Embed for your customers'.
B.Publish to a public website (Publish to web).
C.Export the report to PDF and share the file.
D.Share directly via Power BI using the user's email address.
E.Export the report to Excel and attach it to an email.
AnswersA, B

'Embed for your customers' uses an app-owns-data model, issuing an embed token so external users authenticate against your application rather than Microsoft Entra ID. This satisfies the stem's constraint that recipients lack a Power BI Pro licence, since consuming embedded analytics requires no per-user Power BI licence.

Why this answer

Option A is correct because the 'Embed for your customers' (app-owns-data) scenario uses an embed token and a service principal or master account to render the report inside your own application or secure portal, so the external viewers authenticate to your app and never need a Power BI Pro license. Option B is correct because 'Publish to web' generates an anonymous public embed code/URL that anyone can view in a browser without any Power BI license, Pro or otherwise. Option C is not correct because exporting to PDF produces a static file, not a shared interactive Power BI report, and it is not a Power BI sharing method.

Option D is not correct because direct sharing via email in the Power BI service requires the recipient to have a Power BI Pro (or PPU) license to open the report. Option E is not correct because exporting to Excel yields a static data extract, not a live report, and likewise is not a Power BI sharing mechanism.

Exam trap

PL-300 often tests the misconception that any sharing method works for external users without licenses, but only 'Embed for your customers' and 'Publish to web' are designed for that; direct sharing and exports do not provide interactive report access without a license.

59
MCQeasy

A data analyst creates a Power BI report using a dataset that contains sensitive salary information. The analyst needs to ensure that only HR managers can see salary columns. What should the analyst use?

A.Row-level security (RLS).
B.Microsoft Purview sensitivity labels.
C.Object-level security (OLS).
D.Set the dataset security to 'Restrict access'.
AnswerC

Object-level security (OLS) lets a modeler define roles that remove specific tables or columns from a user's view by setting their object permissions to None. In Power BI, OLS is implemented in the role editor (or via XMLA endpoints) where you can deny access to a column while leaving the rest of the model accessible. Since the requirement is to hide a sensitive column while allowing the rest of the dataset to remain usable, OLS is the correct mechanism.

Why this answer

Object-level security (OLS) is the correct choice because it restricts access to specific tables or columns within a dataset, which is exactly what is needed to hide salary columns from everyone except HR managers. OLS is defined in the dataset's Tabular Model roles and can deny access to individual columns so that unauthorized users cannot see them in reports. Row-level security (RLS) only filters rows, not columns, so it cannot prevent viewing salary columns.

Microsoft Purview sensitivity labels classify and protect data but do not control column visibility in Power BI reports, and 'Restrict access' is not a valid dataset security setting for column-level control.

60
MCQeasy

You need to share a Power BI dashboard with a large group of users in your organization. The users should not be able to edit the dashboard or share it with others. What is the most efficient method?

A.Add all users as Members of the workspace.
B.Share the dashboard directly with each user's email address.
C.Publish the dashboard to the web.
D.Create a workspace app and grant the group Viewer access.
AnswerD

A workspace app distributes the dashboard to many users at once, satisfying the large-group requirement efficiently. Viewer access grants read-only interaction, preventing edits, while app audiences cannot reshare content. This combination meets both constraints without per-user sharing overhead.

Why this answer

The correct answer is D: create a workspace app and grant the group Viewer access. A workspace app packages the dashboard (and its reports) for distribution to a broad audience, and the Viewer role gives read-only access without edit or reshare rights, which matches the requirement efficiently for a large group. Option A is wrong because the Member role allows editing and sharing content, violating the restriction.

Option B is inefficient for a large group and grants per-user sharing permissions rather than a single managed distribution. Option C is wrong because Publish to web makes the dashboard publicly accessible on the internet with no access control.

61
MCQhard

A Power BI administrator needs to ensure that all reports in a workspace are labeled with a sensitivity label automatically when created. The workspace is used by multiple departments. What should the administrator configure?

A.Set a default sensitivity label for the workspace in the workspace settings.
B.Configure a Microsoft Purview auto-labeling policy for the workspace.
C.Set the default sensitivity label for the entire Power BI tenant.
D.Instruct all users to manually apply the sensitivity label when creating reports.
AnswerA

Setting a default sensitivity label in the workspace settings is the correct, administrator-controlled method. Any new report created in that workspace inherits this label automatically, and users can still change it if they have appropriate permissions. This meets the requirement without relying on user discipline.

Why this answer

The correct option is A: setting a default sensitivity label for the workspace in the workspace settings. In Power BI, a workspace admin can assign a default sensitivity label at the workspace level, so any new report or dataset created in that workspace automatically inherits that label without user action, which fits the requirement that all reports be labeled automatically on creation. Option B does not fit because Microsoft Purview auto-labeling policies apply to supported workloads like Exchange, SharePoint, and OneDrive, not directly to Power BI workspace-created items.

Option C is incorrect because a tenant-wide default label is not the mechanism for per-workspace automatic labeling of new reports. Option D is incorrect because manual labeling by users is not automatic and would not guarantee consistent labeling.

62
MCQmedium

You are a Power BI administrator. A new analyst joins the team and needs to publish reports to an existing workspace named Sales Analytics. The analyst must be able to create and edit content in the workspace but must not be allowed to add or remove other members or change workspace settings. Which workspace role should you assign to the analyst?

A.Viewer
B.Member
C.Admin
D.Contributor
AnswerD

Contributor allows creating, editing, and deleting content within the workspace, but does not permit adding or removing members or changing workspace settings. This matches the analyst's needs exactly. It grants the necessary publishing and editing rights without the administrative capabilities that must be withheld.

Why this answer

The Contributor role allows a user to create and edit content such as reports and datasets in a workspace, but does not allow managing workspace membership or settings. Assigning Contributor gives the analyst the needed publishing and editing capabilities while enforcing least privilege. Admin and Member grant excessive rights, and Viewer lacks the required editing permissions.

Exam trap

The trap here is assuming that Member is the least-privilege role for editing content, when Member also allows adding members and managing access, which exceeds the requirement.

63
Multi-Selectmedium

Which TWO actions are required to enable Bring Your Own Key (BYOK) encryption for Power BI datasets? (Select exactly two.)

Select 2 answers
A.Assign the workspace to a Power BI Premium capacity
B.Store the encryption key in the Power BI service admin settings
C.Upload the customer-managed key to Azure Key Vault
D.Configure the Power BI admin settings to use the key from Azure Key Vault
E.Register the encryption key in Microsoft Purview compliance portal
AnswersC, D

The customer-managed key must exist in Azure Key Vault before Power BI can reference it. Uploading the key establishes the vault-held asymmetric key that Power BI later wraps around the dataset encryption key, which is the prerequisite step enabling BYOK rather than Microsoft-managed encryption.

Why this answer

BYOK for Power BI requires the customer-managed key to be created and stored in Azure Key Vault, so option C is correct because the RSA 2048-bit (or 3072/4096-bit) key must reside in an Azure Key Vault subscription you control. Option D is also correct because, after the key exists in Key Vault, a Power BI admin must enable BYOK in the Power BI admin portal (Tenant settings) and point the tenant to that Key Vault key, granting the Power BI service the necessary wrap/unwrap permissions. Option A is not required because BYOK is a tenant-level feature available with Power BI Premium (or Fabric capacity) but assigning a specific workspace to a capacity is not the action that enables BYOK.

Option B is incorrect because the key itself is never stored in Power BI admin settings; only a reference to the Key Vault key is configured there. Option E is incorrect because Microsoft Purview is not used to register the encryption key for Power BI BYOK.

64
MCQmedium

You are the Power BI administrator for a company that uses Microsoft 365. The security team requires that when a user opens a Power BI report on a personal device, the user must authenticate with Microsoft Entra ID and satisfy a conditional access policy that demands multifactor authentication. The report is in a workspace that is not backed by Fabric capacity. Which feature should you enable to meet this requirement?

A.Power BI Embedded
B.Microsoft Entra ID Conditional Access
C.Row-level security (RLS)
D.Sensitivity labels
AnswerB

Configuring a Conditional Access policy in Microsoft Entra ID that targets the Power BI cloud app and requires multifactor authentication enforces the MFA challenge when a user signs in to Power BI, including on personal devices. Because Power BI uses Microsoft Entra ID for authentication, the policy applies at sign-in and satisfies the security team's requirement without needing Fabric capacity.

Why this answer

The requirement is to force MFA when users open a report on personal devices. Because Power BI authenticates users through Microsoft Entra ID, a Conditional Access policy that targets the Power BI app and requires MFA will enforce the challenge at sign-in. This works regardless of whether the workspace uses Fabric capacity.

Other features like sensitivity labels, RLS, or Embedded do not enforce interactive MFA.

Exam trap

The trap here is assuming that sensitivity labels or row-level security can enforce multifactor authentication, when authentication strength is controlled by Microsoft Entra ID Conditional Access.

65
MCQhard

Your organization uses row-level security (RLS) in Power BI. You have a table 'Sales' with a column 'Region'. You define a role 'RegionManagers' with the filter: [Region] = "North". A user named Alice is a member of this role. However, when Alice views a report that uses this dataset, she sees all regions. What is the most likely reason?

A.The dataset uses DirectQuery mode, which does not support RLS.
B.Alice is the dataset owner.
C.The filter must use USERNAME() or USERPRINCIPALNAME() function.
D.RLS is only applied in Power BI Desktop, not in the service.
AnswerB

Alice, as the dataset owner, bypasses RLS entirely. In the Power BI service, users who have Owner permission (or Write permission) on the dataset are exempt from row-level security filters, so they can see all rows in any report built on that dataset. Even in Power BI Desktop, the model designer sees all data unless they explicitly test a role with 'View as'. Thus, Alice seeing all data is expected when she owns the dataset.

Why this answer

The correct answer is B: Alice is the dataset owner. In Power BI, members of the dataset's Admin/owner workspace role (or the dataset owner) bypass row-level security, so Alice sees all regions despite being assigned to the RegionManagers role with the filter [Region] = "North". RLS is enforced only for users who access the dataset with Viewer, Contributor, or read permissions, not for owners/admins.

Option A is wrong because DirectQuery does support RLS. Option C is wrong because a static filter like [Region] = "North" is valid; USERNAME()/USERPRINCIPALNAME() is only needed for dynamic filtering. Option D is wrong because RLS is enforced in the Power BI service as well as in Desktop.

66
MCQmedium

Your organization uses Microsoft Power BI with Microsoft Purview for data governance. You have a dataset that contains customer data classified as 'Highly Confidential' under a sensitivity label. The compliance team requires that when this dataset is shared with external users, a Microsoft Purview data loss prevention (DLP) policy must block the sharing and notify the compliance team. You need to configure this. What should you do?

A.Use Microsoft Defender for Cloud Apps to create a session policy that blocks sharing.
B.Configure Microsoft Sentinel to monitor and block sharing events.
C.In the Power BI admin portal, disable sharing for workspaces containing 'Highly Confidential' content.
D.Create a DLP policy in Microsoft Purview that applies to Power BI and blocks sharing of content with the 'Highly Confidential' label.
AnswerD

Creating a Data Loss Prevention policy in Microsoft Purview that targets the Power BI workload is the correct, service-native approach: the policy can specify a condition that the sensitivity label equals 'Highly Confidential', and define an action to block the share, optionally allowing an override or business justification. When a user attempts to share a labeled item, Purview, via its integration with Power BI, intercepts the request and enforces the policy in near real time, providing both audit and DLP event logs. This is the only listed option that directly uses label-aware DLP semantics to prevent unauthorized sharing.

Why this answer

The correct option is D: create a DLP policy in Microsoft Purview that applies to Power BI and blocks sharing of content with the 'Highly Confidential' label. Microsoft Purview DLP natively supports Power BI as a workload, so a policy scoped to Power BI can detect items carrying the specified sensitivity label and block external sharing while sending notifications to the compliance team. Option A is wrong because Defender for Cloud Apps session policies govern SaaS session activity, not Power BI item-level label-based sharing.

Option B is wrong because Microsoft Sentinel is a SIEM/SOAR platform for monitoring and alerting, not for enforcing DLP blocking. Option C is wrong because disabling sharing at the workspace level is a blunt control that does not target the 'Highly Confidential' label or notify compliance.

67
MCQeasy

You have a Power BI capacity that is frequently hitting its memory limits, causing refreshes to fail. You need to reduce memory usage without increasing capacity size. What should you do?

A.Increase the eviction time for unused data.
B.Reduce the number of parallel data refresh operations.
C.Remove row-level security (RLS) from the dataset.
D.Increase the frequency of scheduled refreshes.
AnswerB

Reducing the number of parallel data refresh operations lowers the peak memory and CPU demand on the capacity because each refresh must load and compress the entire dataset into memory. By serializing refreshes, you flatten the resource usage curve, preventing the capacity from reaching its memory threshold during overlapping refresh jobs. This is a direct, effective lever to avoid capacity throttling and eviction.

Why this answer

The correct answer is B: reducing the number of parallel data refresh operations lowers peak memory usage because each concurrent refresh consumes memory for its own data processing, and running fewer at once means fewer simultaneous memory spikes on the capacity. This directly addresses the memory-limit failures without requiring a larger capacity SKU. Option A is wrong because increasing eviction time keeps unused data in memory longer, which would increase rather than reduce memory pressure.

Option C is wrong because RLS is not the primary driver of refresh memory usage, and removing it would not reliably solve capacity memory limits. Option D is wrong because more frequent refreshes increase overall memory and CPU load, making the problem worse.

68
Multi-Selecteasy

Which TWO are valid Power BI workspace roles?

Select 2 answers
A.Viewer
B.Admin
C.Owner
D.Reader
E.Editor
AnswersA, B

Viewer is a legitimate read-only workspace role in Power BI. Viewers can see and interact with dashboards, reports, and apps in the workspace, but they cannot edit content, share items, or manage permissions. This role is ideal for consumers who only need to view and analyze data without modifying the underlying reports.

Why this answer

In Power BI, the four valid workspace roles are Admin, Member, Contributor, and Viewer, so option A (Viewer) is correct because it grants read-only access to view reports and dashboards without editing content, and option B (Admin) is correct because it provides full control of the workspace including adding/removing users, managing permissions, and deleting the workspace. Option C (Owner) is not a Power BI workspace role—ownership concepts apply to items or capacities, not workspace membership roles. Option D (Reader) is not a workspace role; read-only access is provided by the Viewer role.

Option E (Editor) is not a workspace role; edit permissions are granted via Contributor, Member, or Admin roles.

69
MCQeasy

You are a Power BI administrator. You need to ensure that users in your organization can only access Power BI through the web browser and cannot use the Power BI Desktop application to connect to the Power BI service. Which tenant setting should you configure?

A.Disable 'Publish to web' for the entire organization.
B.Disable 'Allow users to connect to the Power BI service with Power BI Desktop'.
C.Disable 'Allow service principals to use Power BI APIs'.
D.Disable 'Allow users to try Power BI Desktop for free'.
AnswerB

This tenant setting specifically blocks users from connecting Power BI Desktop to the Power BI service. Enabling this restriction ensures that users can only use the browser-based service, as required. It is the direct control for limiting Desktop client access to the service.

Why this answer

The tenant setting 'Allow users to connect to the Power BI service with Power BI Desktop' controls whether Desktop can be used to connect to the service. Disabling it restricts users to the web browser. Other settings address different features such as publishing publicly or API access, and do not prevent Desktop connections.

Exam trap

The trap here is confusing settings that limit publishing or trial usage with the specific setting that blocks Desktop connections to the service.

70
MCQeasy

You need to audit Power BI activity for compliance. Which tool should you use to access detailed logs of user actions?

A.Microsoft Defender XDR
B.Microsoft Purview compliance portal (Audit)
C.Microsoft Purview Data Map
D.Power BI Premium capacity metrics app
AnswerB

The Microsoft Purview compliance portal (Audit) hosts the unified audit log for Microsoft 365, which captures user and admin activities across services, including Power BI. Events such as viewing a report, modifying a dataset, sharing a dashboard, and exporting data are recorded with actor, timestamp, operation, and affected item details. Searching this log is the standard way to perform compliance auditing of Power BI user activities, making it the correct answer.

Why this answer

The correct option is B, Microsoft Purview compliance portal (Audit), because it provides the unified audit log that captures detailed Power BI user activity such as viewed reports, edited datasets, shared dashboards, and exported data, which is exactly what a compliance audit requires. Power BI activity events are surfaced through the Microsoft 365 audit log, accessible via the Purview compliance portal's Audit search (or the Search-UnifiedAuditLog cmdlet), letting you filter by workload, user, and date. Option A, Microsoft Defender XDR, focuses on security incidents and threat detection across endpoints, identities, and email, not on Power BI activity auditing.

Option C, Microsoft Purview Data Map, catalogs and classifies data assets for governance but does not record user action logs. Option D, the Power BI Premium capacity metrics app, reports on capacity utilization and performance metrics, not detailed per-user activity logs.

71
MCQmedium

Your organization is implementing a data sensitivity labeling strategy for Power BI. You have created labels in Microsoft Purview Compliance Portal. After publishing a report, you notice that some labels are not available for selection in Power BI. What is the most likely cause?

A.The labels were created in the wrong workspace.
B.The Power BI tenant does not have Premium capacity.
C.The labels are not included in a label policy that applies to Power BI.
D.Users do not have Power BI Pro licenses.
AnswerC

Power BI only exposes sensitivity labels that are published through a sensitivity label policy in Microsoft Purview. Creating a label alone is insufficient—the label must be added to a policy that is enabled for Power BI and scoped to the appropriate users or security groups. Without such a policy, the labels remain invisible in the Power BI interface.

Why this answer

The correct answer is C: the labels are not included in a label policy that applies to Power BI. Sensitivity labels created in Microsoft Purview only become selectable in Power BI when they are published through a label policy whose scope includes Power BI (and the users are in that policy); simply creating the labels does not make them available. Options A, B, and D do not fit: labels are tenant-level objects not tied to a Power BI workspace, Premium capacity is not required for sensitivity labels, and Power BI Pro licensing does not control label availability.

Ready to test yourself?

Try a timed practice session using only Manage and secure Power BI questions.