Courseiva

PL-300 Manage and secure Power BI Practice Question

Which TWO are valid methods to secure access to a Power BI dataset? (Select exactly two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Row-level security (RLS)

Row-level security (RLS) [CORRECT] is a valid method to secure access to a Power BI dataset because it restricts which rows a given user can see by applying DAX filter expressions to roles defined in the dataset, and those roles are assigned to users or groups in the Power BI service. Object-level security (OLS) [CORRECT] is also valid because it secures specific tables or columns in the dataset model by hiding them entirely from users who lack permission, preventing them from viewing or querying those objects. Column-level security (CLS) is not a separate Power BI feature; column-level restriction is achieved through OLS, so it is not a distinct valid method. App permissions control access to Power BI apps and workspaces rather than securing the dataset model itself, and data encryption at rest protects stored data on disk but does not control which data a user can access within a dataset.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Row-level security (RLS)

    Why this is correct

    Row-level security (RLS) is a valid method because it restricts data at the row level based on the identity of the signed-in user. By defining roles in Power BI Desktop and using DAX expressions (such as USERNAME() or USERPRINCIPALNAME()), RLS filters the underlying dataset dynamically, so each user only sees rows they are permitted to view. This filtering is enforced at query time, making it a robust, native access-control feature for Power BI datasets.

  • ✗

    Column-level security (CLS)

    Why it's wrong here

    Column-level security (CLS) is not a valid method because Power BI does not offer a feature specifically named CLS. The correct feature for hiding columns is object-level security (OLS), which can protect entire tables and columns, but CLS as such does not exist in the Power BI security model. Attempting to implement CLS is a common misconception that leads to confusion with OLS, which is the actual mechanism for column-level protection.

  • ✓

    Object-level security (OLS)

    Why this is correct

    Object-level security (OLS) is a valid method because it secures access to metadata by hiding entire tables and columns from specific users. Defined through roles in Tabular Editor (or by scripting metadata changes), OLS is enforced at the model level and prevents users from even seeing or querying protected schema objects. OLS works alongside RLS to create defense-in-depth: RLS filters rows while OLS hides the existence of the data structure itself.

  • ✗

    App permissions

    Why it's wrong here

    App permissions are not a valid method to secure Power BI dataset access because they only govern who can access the app's reports and dashboards, not the underlying dataset. A user with app access can still view all data shown in those reports unless other mechanisms like RLS or OLS are applied. App permissions solely manage presentation-layer distribution, so they cannot enforce row- or column-level restrictions on the data model.

  • ✗

    Data encryption at rest

    Why it's wrong here

    Data encryption at rest is not a valid method for securing access because it protects data from unauthorized physical or storage-level intrusion, not from user authentication or authorization in Power BI. Encryption at rest ensures data is unreadable if copied from storage, but it does not filter what a user can see or query through reports. Access control, by contrast, requires identity-based rules such as RLS or OLS, which operate at the semantic layer.

About these practice questions

One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.