PL-300 Manage and secure Power BI Practice Question
You manage a Power BI tenant. A workspace named 'Finance' contains a dataset that uses an on-premises SQL Server data source via an on-premises data gateway. The gateway is configured with a single data source that uses a SQL Server account for authentication. You need to ensure that when users view reports based on this dataset, they see only data for their own department, and the filtering must be enforced at query time without modifying the dataset. What should you do?
⚠ Common exam trap
A common mix-up: candidates confuse row-level security with column-level security or thinking that gateway authentication can enforce per-user data filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure row-level security (RLS) on the dataset and map users to roles.
Row-level security (RLS) is the correct approach because it dynamically filters data based on the user's identity at query time. It is defined within the dataset and does not require changes to the data source or gateway. Other options either duplicate content, do not enforce per-user filtering, or address column-level rather than row-level security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create separate reports for each department and distribute them via apps.
Why it's wrong here
Creating separate reports per department would require duplicating the dataset and reports, which increases maintenance overhead and does not scale. It also does not enforce security at query time; users could potentially access other reports if permissions are misconfigured. The requirement is to enforce filtering dynamically based on user identity, which is better handled by RLS.
- ✗
Configure column-level security on the dataset to hide sensitive columns.
Why it's wrong here
Column-level security restricts access to entire columns, not rows. It would not filter data by department. The scenario requires users to see only their own department's data, which is row-level filtering. Column-level security is useful for hiding sensitive attributes but does not satisfy the row-based requirement.
- ✗
Use the gateway's 'Add users to data source' feature to map each user to a specific SQL Server login.
Why it's wrong here
The gateway data source uses a single SQL Server account for authentication; it does not pass through individual user identities. Mapping users to specific SQL logins would require multiple data sources and is not supported for a single data source. This approach would not enforce row-level filtering based on the Power BI user's department.
- ✓
Configure row-level security (RLS) on the dataset and map users to roles.
Why this is correct
RLS defined in the dataset (either in Power BI Desktop or by using Tabular Editor) filters data based on the identity of the user viewing the report. When users access the report, Power BI passes their identity to the dataset, and the RLS rules restrict the rows they can see. This is enforced at query time and does not require changes to the underlying data source or gateway configuration.
Go deeper
Related to this question
About these practice questions
One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.