Courseiva

PL-300 · topic practice

Manage and secure Power BI practice questions

This domain covers Power BI administration and security: tenant settings in the Power BI admin portal, workspace roles, row-level security (RLS) with DAX filters and role membership, sharing with internal and external users, sensitivity labels, and Microsoft Entra ID authentication and conditional access for report access.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage and secure Power BI

What the exam tests

What to know about Manage and secure Power BI

Be able to configure tenant settings, build and validate RLS roles with DAX, assign workspace roles, and share securely with external users. The single most important thing: verify what each role and setting actually exposes before claiming data is protected.

Disabling tenant settings such as Export data and Export reports in the Power BI admin portal

Configuring row-level security roles with DAX filter expressions and assigning users or groups

Sharing reports and apps with external users via Microsoft Entra B2B guest invitations or publish-to-web

Applying Microsoft Entra ID authentication and Conditional Access policies to Power BI access

Watch out for

Common Manage and secure Power BI exam traps

  • ▸Confusing workspace roles (Admin, Member, Contributor, Viewer) with dataset RLS roles; Viewers still see all data unless RLS is defined and enforced.
  • ▸Assuming external sharing always needs a Pro license; guest users can be covered by the host tenant's capacity or per-user licensing in some configurations.
  • ▸Testing RLS as an Admin or Member and seeing all data, then concluding RLS is broken; use View as role to validate filters.

Practice set

Manage and secure Power BI questions

20 questions · select your answer, then reveal the explanation

You are a Power BI administrator. A user reports that a shared dashboard shows 'Sensitive data detected' for certain visualizations, but the dashboard is configured with row-level security (RLS). What is the most likely cause of this issue?

Refer to the exhibit. You are a Power BI administrator reviewing a workspace capacity configuration in the Power BI admin portal. Based on the exhibit, which of the following is true?

Exhibit

{
  "properties": {
    "encryption": "ServiceManaged",
    "dataClassification": "Confidential",
    "defaultDatasetStorageFormat": "ABFSSmall",
    "allowedDataSources": [
      "SQLServer",
      "AzureSQL",
      "OData"
    ]
  }
}

A Power BI administrator needs to prevent users from creating new workspaces, but allow existing workspaces to continue functioning. Which two settings should be configured? (Choose two.)

You are a Power BI administrator. A user reports that they cannot see a shared dashboard in their Power BI account. You verify that the dashboard has been shared with the user. What is the most likely cause?

You are a Power BI administrator. Your organization wants to use Microsoft Defender XDR to monitor Power BI activity for suspicious behavior. Which two components are essential for this integration? (Choose two.)

A company deploys Power BI for internal reporting. The security team requires that all report data be encrypted at rest and in transit, and that access be granted only to users with verified identities. Which combination of features should the Power BI administrator use?

Refer to the exhibit. A Power BI administrator is reviewing a dataset configuration exported from a workspace. The dataset connects to an on-premises SQL Server using Windows authentication. The administrator wants to configure a gateway to support scheduled refresh without storing credentials. Which gateway type and configuration should be used?

Exhibit

{
  "dataSources": [
    {
      "name": "SalesDB",
      "connectionString": "Data Source=sqlserver.contoso.com;Initial Catalog=Sales;Integrated Security=SSPI;"
    }
  ],
  "datasets": [
    {
      "name": "SalesDataset",
      "tables": [
        {
          "name": "Orders",
          "columns": [
            {"name": "OrderID", "dataType": "int"},
            {"name": "CustomerID", "dataType": "int"},
            {"name": "Amount", "dataType": "decimal"}
          ]
        }
      ]
    }
  ]
}

A Power BI administrator deploys a dashboard that uses a real-time dataset from Azure Stream Analytics. The dashboard must refresh every minute. The administrator notices that the dashboard sometimes shows stale data. What is the most likely cause and solution?

A Power BI workspace contains a report that uses a shared dataset. The dataset owner leaves the company. The report still works, but the dataset cannot be refreshed. What should the administrator do to restore refresh capability?

An organization uses Power BI with Microsoft Purview Information Protection. A report contains sensitive customer data. The administrator wants to ensure that when the report is exported to Excel, the sensitivity label is automatically applied. What must be configured?

A Power BI administrator receives a support ticket that users can see reports in the Power BI service but cannot access them, receiving a 'not found' error. The reports are stored in a shared workspace. What should the administrator check first?

An administrator wants to monitor all Power BI activities, including viewing reports, exporting data, and sharing workspaces. Which tool should they use?

Which THREE components must be in place to enable Power BI data sensitivity labels from Microsoft Purview? (Select exactly three.)

Which Power BI component can be used to restrict access to specific rows of data for different users?

Refer to the exhibit. The Power BI admin portal shows capacity usage. The Sales workspace is on Premium capacity and the Marketing workspace is on Shared capacity. The Marketing report uses a dataset from the Sales workspace. The admin notices that the Sales dataset refresh takes 45 minutes, and the Marketing dataset refresh takes 10 minutes. Users complain that during the Sales dataset refresh, the Marketing report becomes slow. What is the most likely cause?

Exhibit

{
  "capacity": "Premium",
  "workspaces": [
    {
      "name": "Sales",
      "type": "Premium",
      "datasets": [
        {
          "name": "SalesDataset",
          "size": "1.5 GB",
          "refreshTime": "00:45:00"
        }
      ]
    },
    {
      "name": "Marketing",
      "type": "Shared",
      "datasets": [
        {
          "name": "CampaignAnalysis",
          "size": "200 MB",
          "refreshTime": "00:10:00"
        }
      ]
    }
  ]
}

Refer to the exhibit. A Power BI administrator reviews a row-level security (RLS) policy for the Sales dataset. The SalesManager role should see all sales above $10,000, and the SalesRep role should see all sales above $0. However, users in the SalesRep role report that they cannot see any data when they open the report. What is the most likely issue?

Exhibit

{
  "policies": [
    {
      "name": "SalesRLS",
      "roles": [
        {
          "name": "SalesManager",
          "filterExpression": "[SalesAmount] > 10000"
        },
        {
          "name": "SalesRep",
          "filterExpression": "[SalesAmount] > 0"
        }
      ]
    }
  ]
}

You have a Power BI workspace that contains a report connected to an Azure Analysis Services (AAS) model. The data source uses Single Sign-On (SSO) with Microsoft Entra ID. When users access the report, they see an error that the data cannot be refreshed. What is the most likely cause?

You need to ensure that only members of a specific security group can view a Power BI dashboard. The dashboard is in a shared workspace. What should you do?

Your organization uses Microsoft Purview Information Protection to label sensitive data in Power BI datasets. You need to ensure that when a report is exported to Excel, the sensitivity label is automatically applied. What should you configure?

You manage a Power BI environment where users create reports using data from Azure SQL Database. You need to enforce that all data sources use Single Sign-On (SSO) with Microsoft Entra ID. What should you do?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage and secure Power BI sessions

Start a Manage and secure Power BI only practice session

Every question in these sessions is drawn from the Manage and secure Power BI domain — nothing else.

Related practice questions

Related PL-300 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PL-300 exam test about Manage and secure Power BI?
Be able to configure tenant settings, build and validate RLS roles with DAX, assign workspace roles, and share securely with external users. The single most important thing: verify what each role and setting actually exposes before claiming data is protected.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage and secure Power BI questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage and secure Power BI domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PL-300 topics?
Use the topic links above to move to related areas, or go back to the PL-300 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PL-300 exam covers. They are not copied from any real exam or dump site.