PL-300 Manage and secure Power BI Practice Question
Exhibit
{
"caller": "user@contoso.com",
"operation": "CreateReport",
"itemName": "SalesReport",
"workspaceId": "12345678-1234-1234-1234-123456789012",
"dataset": "SalesDataset",
"sensitivityLabel": "Confidential"
}Refer to the exhibit. You are reviewing a Power BI activity log entry. What action should you take to ensure compliance if the user who created the report should not have access to 'Confidential' data?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the user's permissions on the dataset 'SalesDataset' to verify they are authorized to access confidential data.
The correct action is C: investigate the user's permissions on the dataset 'SalesDataset' to verify they are authorized to access confidential data. In a Power BI activity log, a report creation event alone does not prove a compliance breach; the actual access control is enforced through the dataset's permissions and the sensitivity label applied to the data, so you must confirm whether the user legitimately has access to 'Confidential' data before taking any remediation. Option A is wrong because deleting the report is a destructive action that does not address the underlying permission issue and could destroy legitimate work. Option B is wrong because changing the sensitivity label to 'General' would misclassify the data and could itself create a compliance violation. Option D is wrong because simply ignoring the event fails to verify whether the user's access was authorized, which is the required compliance check.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the report immediately.
Why it's wrong here
Deleting the report immediately is premature and destructive: it removes the evidence of the potential violation from the workspace, and more importantly, it does nothing to change the user's access to the underlying SalesDataset. If the user truly lacks authorization, revoking their dataset permissions or workspace role is the corrective action. A hasty deletion also destroys the audit trail artifact that a compliance investigation would need to analyze.
- ✗
Change the sensitivity label on the report to 'General'.
Why it's wrong here
Changing the sensitivity label to 'General' only alters classification metadata; it neither grants nor removes access to the SalesDataset, because sensitivity labels in Power BI are not an access control mechanism. The user would still be able to create confidential reports if their dataset permissions are invalid. Further, mislabeling confidential data as general could itself cause a compliance violation, since the label is used for protection policies and downstream tracking.
- ✓
Investigate the user's permissions on the dataset 'SalesDataset' to verify they are authorized to access confidential data.
Why this is correct
Investigating the user's permissions on SalesDataset is the correct first step because the activity log shows only the outcome (a report created with a Confidential label), not the authorization chain. The analyst should check the user's effective permissions through workspace roles, dataset sharing, and row-level security, using the lineage view or the 'Manage permissions' page. Only after confirming whether the user is allowed to see the underlying data can you decide to take action, thereby adhering to the principle of least privilege and proper incident response.
- ✗
Ignore the event because the report creation is logged but not necessarily a violation.
Why it's wrong here
Ignoring the event because it is logged fails to recognize that the audit log exists specifically to facilitate post-hoc detection of security incidents, not to validate their legitimacy. A logged report creation can be the first indicator of data exfiltration, especially when a Confidential label is applied by a user without a need to know. Proper governance requires reviewing the event in context with the user's role and permissions rather than dismissing it outright.
About these practice questions
One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.