Courseiva

PL-300 Manage and secure Power BI Practice Question

Your organization uses Microsoft Defender for Cloud Apps to monitor Power BI activity. You need to receive an alert when a user exports a report with a sensitivity label of 'Highly Confidential' from Power BI service. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an activity policy in Microsoft Defender for Cloud Apps.

The correct option is D: create an activity policy in Microsoft Defender for Cloud Apps. Defender for Cloud Apps connects to Power BI via the app connector and its activity policies can trigger alerts on specific user activities, such as downloading or exporting a report, filtered by the sensitivity label 'Highly Confidential'. Option A is wrong because Microsoft 365 compliance alerts do not natively target Power BI report export events with sensitivity-label conditions. Option B is wrong because Power BI audit logging plus Microsoft Sentinel requires custom analytics rules and does not directly provide the built-in activity-policy alerting for this scenario. Option C is wrong because a Microsoft Purview protection policy blocks export rather than generating the requested alert.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up a Microsoft 365 compliance alert for data export events.

    Why it's wrong here

    Microsoft 365 compliance alerts are designed to detect issues like data retention, eDiscovery, or mislabeled sensitive items, but they do not monitor cloud app activities such as Power BI exports carrying sensitivity labels. They lack the app-specific telemetry and label-aware correlation that Defender for Cloud Apps provides. Without integration into Power BI's activity stream, these alerts cannot reliably fire on the exact condition of an export with a 'Highly Confidential' label.

  • ✗

    Enable audit logging in Power BI and configure alerts in Microsoft Sentinel.

    Why it's wrong here

    Configuring alerts in Microsoft Sentinel for Power BI audit logs would provide general security monitoring, making it tempting for broad threat detection across an organisation's digital estate. However, Sentinel does not natively interpret or act upon Power BI sensitivity labels for specific data exfiltration scenarios. Microsoft Defender for Cloud Apps is purpose-built to understand and enforce policies based on sensitivity labels during export events, which is the precise requirement for this scenario.

  • ✗

    Apply a protection policy in Microsoft Purview that blocks export for 'Highly Confidential' labels.

    Why it's wrong here

    A Purview protection policy (e.g., a DLP or sensitivity label policy) is an enforcement control that can block export actions, but it does not generate alerts when an export occurs; it simply denies or restricts the action. Since the requirement is to be notified of export events rather than to prevent them, this option does not meet the objective. Furthermore, DLP policies are often scoped to endpoints or Exchange/SharePoint, not necessarily to Power BI service export actions with granular label filters.

  • ✓

    Create an activity policy in Microsoft Defender for Cloud Apps.

    Why this is correct

    Defender for Cloud Apps activity policies are purpose-built for monitoring cloud app usage and can detect Power BI export activities in near real time. You can create a policy that filters on Activity type 'Export' and a sensitivity label of 'Highly Confidential' (via Microsoft Information Protection integration), then trigger a custom alert. This provides the precise alerting for data exfiltration events that the scenario requires.

About these practice questions

Courseiva writes every PL-300 question from scratch — 524 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.