PL-300 Manage and secure Power BI Practice Question
You need to audit which users have accessed a specific Power BI dashboard in the last 30 days. What should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Power BI Activity Log (audit log) in the Microsoft 365 admin center.
The Power BI Activity Log (audit log) in the Microsoft 365 admin center is the correct tool because it records user activities such as viewing dashboards and reports, and it can be filtered by date range (e.g., last 30 days) and by item to identify exactly which users accessed a specific dashboard. It captures events like ViewDashboard and ViewReport with user, timestamp, and artifact details, which is precisely what this audit requires. Microsoft Sentinel is a SIEM for security analytics and would only have this data if the Power BI logs were explicitly ingested, so it is not the direct source. Microsoft Purview compliance portal focuses on data governance, classification, and compliance rather than Power BI usage auditing. The Power BI REST API 'Get Datasets' endpoint only returns dataset metadata and does not provide user access activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel.
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM/SOAR platform designed for security monitoring and threat response. While it can ingest Microsoft 365 audit logs through connectors to detect suspicious activity, it is not the native or primary audit trail for Power BI. To identify which users accessed a specific dashboard, you would need to query the unified audit log in the Microsoft 365 admin center or Purview portal; Sentinel would only be relevant after you have configured data collection and alerting rules. Therefore, Sentinel is an optional downstream consumer of audit data, not the authoritative source for Power BI access history.
- ✓
Power BI Activity Log (audit log) in the Microsoft 365 admin center.
Why this is correct
The Power BI activity log is part of the Microsoft 365 unified audit log and serves as the authoritative record for user actions such as viewing a dashboard or opening a report. This log is visible in the Microsoft 365 admin center under the audit log search, where you can filter by activities like ViewDashboard and ViewReport to see who accessed the item, when, and from which client. The audit log automatically captures the user ID, item name, and timestamp for every Power BI interaction, provided auditing is enabled in your tenant. This makes the activity log in the Microsoft 365 admin center the correct answer for auditing user access to a specific Power BI dashboard.
- ✗
Microsoft Purview compliance portal.
Why it's wrong here
The Microsoft Purview compliance portal offers a user interface for searching the unified audit log, but it does not contain a separate copy of Power BI access data—the underlying logs are the same Power BI activity logs stored in Microsoft 365. You can query the same audit events from Purview as from the admin center, often with additional features like retention policies and alerts, but it is not the direct source of the activity data. Since the question asks where you would audit which users accessed a dashboard, the activity log itself (viewable in the Microsoft 365 admin center) is the primary answer, whereas Purview is just another gateway to that same log. Thus, Purview is wrong because it is a management surface for audit logs, not the original store.
- ✗
Power BI REST API 'Get Datasets' endpoint.
Why it's wrong here
The Power BI REST API endpoint 'Get Datasets' returns dataset metadata, such as table names, measures, and properties, but it does not track user access events or provide audit history for dashboards or reports. To audit access, you would need the Power BI activity log, which can be retrieved programmatically via the Office 365 Management Activity API or by using the 'Get Power BI Activity Events' operation in the Power BI REST API. The 'Get Datasets' endpoint has no concept of who viewed a resource or when, making it completely unsuitable for auditing user access. It is designed for discovering and manipulating dataset definitions, not for security auditing.
Go deeper
Related to this question
About these practice questions
This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PL-300
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A Power BI admin needs to audit which users have accessed a specific report in the last 30 days. Which log should the admin use?
easy- ✓ A.Power BI activity log (audit log) in the Power BI admin portal.
- B.Microsoft Defender XDR audit log.
- C.Power BI usage metrics report.
- D.Microsoft Purview audit log.
Why A: The Power BI activity log captures user access events. Option B is wrong because the audit log in Microsoft 365 Defender may not have detailed Power BI access events. Option C is wrong because usage metrics reports show view counts but not per-user details. Option D is wrong because the Microsoft Purview audit log is for compliance, not detailed access logs.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.