- A
Microsoft Purview compliance portal audit log
Why wrong: Also logs but less granular for Power BI.
- B
Azure diagnostic settings for Power BI
Why wrong: Export logs to storage/event hub, not for querying.
- C
Power BI activity log (via admin API or portal)
Directly logs all user actions.
- D
Microsoft Sentinel
Why wrong: SIEM tool, not primary audit.
Quick Answer
The answer is the Power BI activity log, accessible through the admin API or the admin portal. This tool is correct because it captures a comprehensive, queryable record of every user action in the Power BI service, including all sharing activities such as sharing reports, dashboards, and apps with users or groups. On the Microsoft Power BI Data Analyst PL-300 exam, this question tests your understanding of native auditing versus external tools—a common trap is choosing Microsoft Purview, which offers broader audit logs but lacks the granular, Power-BI-specific detail needed for sharing audits. Diagnostic settings and Microsoft Sentinel are for log forwarding and security analysis, not direct auditing. To remember, think of the activity log as Power BI’s own “black box” for sharing events—if you need to audit who shared what and when, start here.
PL-300 Manage and secure Power BI Practice Question
This PL-300 practice question tests your understanding of manage and secure power bi. Read the scenario carefully and evaluate each option against the stated constraints before committing to an answer. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.
You are a Power BI administrator. You need to audit all activities related to sharing reports and dashboards in the Power BI service. Which tool should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Power BI activity log (via admin API or portal)
The Power BI activity log provides auditing of all user activities, including sharing. Option A is correct. Option B is wrong because Microsoft Purview compliance portal has audit log but Power BI activity log is more specific and detailed. Option C is wrong because diagnostic settings export logs to other destinations, not for direct querying. Option D is wrong because Microsoft Sentinel collects logs but is not the primary auditing tool.
Key principle: NAT direction and interface roles matter as much as the IP address mapping. Inside/outside designation controls which traffic is translated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview compliance portal audit log
Why it's wrong here
Also logs but less granular for Power BI.
- ✗
Azure diagnostic settings for Power BI
Why it's wrong here
Export logs to storage/event hub, not for querying.
- ✓
Power BI activity log (via admin API or portal)
Why this is correct
Directly logs all user actions.
Related concept
Static NAT maps one inside address to one outside address.
- ✗
Microsoft Sentinel
Why it's wrong here
SIEM tool, not primary audit.
Common exam traps
Common exam trap: NAT rules depend on direction and matching traffic
NAT is not only about the public address. The inside/outside interface roles and the ACL or rule that matches traffic are just as important.
Detailed technical explanation
How to think about this question
NAT questions usually test address translation, overload/PAT behaviour, static mappings and whether the right traffic is being translated. Read the interface direction and address terms carefully.
KKey Concepts to Remember
- Static NAT maps one inside address to one outside address.
- PAT allows many inside hosts to share one public address using ports.
- Inside local and inside global describe the private and translated addresses.
- NAT ACLs identify traffic for translation, not always security filtering.
TExam Day Tips
- Identify inside and outside interfaces first.
- Check whether the scenario needs static NAT, dynamic NAT or PAT.
- Do not confuse NAT matching ACLs with normal packet-filtering intent.
Key takeaway
NAT direction and interface roles matter as much as the IP address mapping. Inside/outside designation controls which traffic is translated.
Real-world example
How this comes up in practice
A cloud solutions architect for a retail company is evaluating services for a new workload. The correct answer here reflects best practice for the specific scenario described — not a general cloud recommendation. NAT direction and interface roles matter as much as the IP address mapping. Inside/outside designation controls which traffic is translated. Cloud exam questions reward reading the constraint carefully: the same technology can be right or wrong depending on the use case.
What to study next
Got this wrong? Here's your next step.
Review the four NAT address types (inside local, inside global, outside local, outside global), PAT port overload, and static vs dynamic NAT use cases. Then practise related PL-300 NAT questions on configuration and troubleshooting.
- →
Manage and secure Power BI — study guide chapter
Learn the concepts, then practise the questions
- →
Manage and secure Power BI practice questions
Targeted practice on this topic area only
- →
All PL-300 questions
966 questions across all exam domains
- →
Microsoft Power BI Data Analyst PL-300 study guide
Full concept coverage aligned to exam objectives
- →
PL-300 practice test guide
How to use practice tests most effectively before exam day
Related practice questions
Related PL-300 practice-question pages
Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.
Prepare the data practice questions
Practise PL-300 questions linked to Prepare the data.
Deploy and maintain assets practice questions
Practise PL-300 questions linked to Deploy and maintain assets.
Model the data practice questions
Practise PL-300 questions linked to Model the data.
Visualize and analyze the data practice questions
Practise PL-300 questions linked to Visualize and analyze the data.
Manage and secure Power BI practice questions
Practise PL-300 questions linked to Manage and secure Power BI.
PL-300 fundamentals practice questions
Practise PL-300 questions linked to PL-300 fundamentals.
PL-300 scenario practice questions
Practise PL-300 questions linked to PL-300 scenario.
PL-300 troubleshooting practice questions
Practise PL-300 questions linked to PL-300 troubleshooting.
Practice this exam
Start a free PL-300 practice session
Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.
FAQ
Questions learners often ask
What does this PL-300 question test?
Manage and secure Power BI — This question tests Manage and secure Power BI — Static NAT maps one inside address to one outside address..
What is the correct answer to this question?
The correct answer is: Power BI activity log (via admin API or portal) — The Power BI activity log provides auditing of all user activities, including sharing. Option A is correct. Option B is wrong because Microsoft Purview compliance portal has audit log but Power BI activity log is more specific and detailed. Option C is wrong because diagnostic settings export logs to other destinations, not for direct querying. Option D is wrong because Microsoft Sentinel collects logs but is not the primary auditing tool.
What should I do if I get this PL-300 question wrong?
Review the four NAT address types (inside local, inside global, outside local, outside global), PAT port overload, and static vs dynamic NAT use cases. Then practise related PL-300 NAT questions on configuration and troubleshooting.
What is the key concept behind this question?
Static NAT maps one inside address to one outside address.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on PL-300
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator wants to monitor all Power BI activities, including viewing reports, exporting data, and sharing workspaces. Which tool should they use?
easy- ✓ A.Power BI activity log in the admin portal
- B.Power BI usage metrics report
- C.Power BI capacity metrics app
- D.Microsoft 365 audit log
Why A: Option A is correct because the Power BI activity log captures user activities such as viewing, exporting, and sharing. Option B is wrong because the usage metrics report shows aggregate usage, not detailed activities. Option C is wrong because Microsoft 365 audit log is broader but less specific to Power BI; the activity log is the dedicated tool. Option D is wrong because the admin portal's capacity metrics focus on performance.
Variation 2. You need to audit Power BI activities such as viewing reports, sharing dashboards, and exporting data. Which TWO actions should you take to enable and access audit logs? (Choose two.)
medium- A.Configure Microsoft Defender for Cloud Apps to forward logs to Microsoft Sentinel.
- ✓ B.Access the audit log from the Microsoft 365 compliance portal.
- ✓ C.Enable the 'Create audit logs for Power BI activities' tenant setting in the admin portal.
- D.Use the 'Export' feature in Power BI to export audit logs to a CSV file.
- E.Set up a diagnostic setting in Azure Monitor to collect Power BI logs.
Why B: Options A and C are correct. Enabling the audit log in the Power BI admin portal is the first step. Option C is correct because audit logs are stored in the Microsoft 365 compliance portal. Option B is wrong because Microsoft Defender for Cloud Apps is not the primary storage for audit logs. Option D is wrong because Azure Monitor is not used for Power BI audit logs. Option E is wrong because Power BI itself does not store audit logs; it sends them to the Microsoft 365 audit log.
Variation 3. You need to audit Power BI activity for compliance. Which tool should you use to access detailed logs of user actions?
easy- A.Microsoft Defender XDR
- ✓ B.Microsoft Purview compliance portal (Audit)
- C.Microsoft Purview Data Map
- D.Power BI Premium capacity metrics app
Why B: Option A is correct because Microsoft Purview provides unified audit logs. Option B is wrong because it's for data mapping. Option C is wrong because it's for threat detection. Option D is wrong because it's for capacity management.
Variation 4. A Power BI administrator needs to audit which users have exported data from a specific report in the last 30 days. What is the most efficient way to retrieve this information?
medium- A.Use the Microsoft Purview compliance portal to search for 'Export' events.
- B.Check the report's usage metrics report for export counts.
- ✓ C.Query the Power BI activity log using the audit log search in the Microsoft 365 Defender portal.
- D.Review the 'Export to Excel' metrics in the Azure Monitor for Power BI Premium.
Why C: Option A is correct because the Power BI activity log contains export events (e.g., 'ExportToCSV', 'ExportToExcel') that can be filtered by report and date. Option B is wrong because Azure Monitor for Power BI Premium provides metrics but not detailed user-level export logs. Option C is wrong because Microsoft Purview audit logs may not include Power BI export events. Option D is wrong because the usage metrics report only shows aggregate usage, not individual export actions.
Last reviewed: Jun 21, 2026
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.