PL-300 Manage and secure Power BI Practice Question
Exhibit
{
"dataset": {
"name": "HRData",
"mode": "DirectQuery",
"roles": [
{
"name": "HRManager",
"table": "Employees",
"filterExpression": "[Department] = \"HR\""
},
{
"name": "Executive",
"table": "Employees",
"filterExpression": "[Department] = \"Executive\""
}
]
}
}Refer to the exhibit. A user is a member of both 'HRManager' and 'Executive' RLS roles. The dataset uses DirectQuery. When the user views a report showing all employees, what data will they see?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rows where Department is 'HR' or 'Executive' (union).
Rows where Department is 'HR' or 'Executive' (union). In Power BI row-level security, when a user belongs to multiple roles, the role filters are combined with OR logic, so the user sees the union of the rows permitted by each role. This behavior applies regardless of whether the dataset uses DirectQuery or Import mode, since RLS role membership is evaluated per user at query time. Options A, B, and C are incorrect because RLS does not grant all rows, does not intersect multiple role filters, and does not produce an empty result due to role conflicts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All rows in the Employees table.
Why it's wrong here
Even though the user belongs to two security roles, row-level security is still enforced; membership in additional roles does not bypass filtering. A row must satisfy at least one role's predicate to be visible, so rows in departments other than HR or Executive remain hidden. Without any role matching those rows, they are filtered out no matter how many roles the user holds.
- ✗
Only rows where Department is both 'HR' and 'Executive' (intersection).
Why it's wrong here
Power BI does not evaluate multiple RLS roles with AND logic. If it did, the Department column would need to equal 'HR' and 'Executive' simultaneously, which is impossible for a single column value, so this would return no rows. Instead, roles are additive, and each role's filter contributes an OR condition to the combined predicate, making this option incorrect.
- ✗
No rows because roles conflict.
Why it's wrong here
There is no conflict here because security roles in Power BI never cancel each other out. When a user is a member of multiple roles, the filters are combined through OR, producing a broader set of permitted rows. Neither an empty result nor an error occurs; the user simply receives the union of the data allowed by each role, so the 'no rows' premise is false.
- ✓
Rows where Department is 'HR' or 'Executive' (union).
Why this is correct
The user effectively sees rows where Department = 'HR' OR Department = 'Executive'. Because the HR Manager role allows HR records and the Executive role allows Executive records, membership in both grants access to the union of those two sets. This is the expected additive behavior of multiple RLS roles in Power BI, where each role adds its permitted rows to the user's overall view.
Go deeper
Related to this question
About these practice questions
This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.