PL-300 Manage and secure Power BI Practice Question
Your organization uses Microsoft Power BI with Microsoft Purview for data governance. You have a dataset that contains customer data classified as 'Highly Confidential' under a sensitivity label. The compliance team requires that when this dataset is shared with external users, a Microsoft Purview data loss prevention (DLP) policy must block the sharing and notify the compliance team. You need to configure this. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a DLP policy in Microsoft Purview that applies to Power BI and blocks sharing of content with the 'Highly Confidential' label.
The correct option is D: create a DLP policy in Microsoft Purview that applies to Power BI and blocks sharing of content with the 'Highly Confidential' label. Microsoft Purview DLP natively supports Power BI as a workload, so a policy scoped to Power BI can detect items carrying the specified sensitivity label and block external sharing while sending notifications to the compliance team. Option A is wrong because Defender for Cloud Apps session policies govern SaaS session activity, not Power BI item-level label-based sharing. Option B is wrong because Microsoft Sentinel is a SIEM/SOAR platform for monitoring and alerting, not for enforcing DLP blocking. Option C is wrong because disabling sharing at the workspace level is a blunt control that does not target the 'Highly Confidential' label or notify compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Defender for Cloud Apps to create a session policy that blocks sharing.
Why it's wrong here
Microsoft Defender for Cloud Apps session policies work at the application access layer, enabling real-time controls like blocking downloads on unmanaged devices, but they do not natively inspect sensitivity labels or intercept Power BI sharing events to block them. While MDCA can surface suspicious activity, it lacks the label-aware data-loss-prevention logic required to prevent a user from invoking a share action on content explicitly marked 'Highly Confidential'. This scenario demands a Purview DLP policy, as it focuses specifically on the act of sharing and understands sensitivity labels as a condition.
- ✗
Configure Microsoft Sentinel to monitor and block sharing events.
Why it's wrong here
Microsoft Sentinel is a security information and event management (SIEM) solution that aggregates and analyzes audit logs from across your environment; it can alert on or investigate sharing events after the fact, but it does not provide preventative enforcement at the moment a user tries to share. Blocking would require a custom automation rule that triggers a logic app to revoke permissions, a slow, non-native, and unreliable approach compared to service-side DLP. Sentinel is best suited for detection and response, not as a direct policy engine for Power BI sharing actions.
- ✗
In the Power BI admin portal, disable sharing for workspaces containing 'Highly Confidential' content.
Why it's wrong here
The Power BI admin portal offers tenant-level configuration for sharing capabilities, such as toggling external sharing for the entire tenant or for specific security groups, but it cannot evaluate the sensitivity label of an individual item and conditionally block its sharing. Disabling sharing for entire workspaces would be misaligned because a workspace may contain reports with different labels, and the setting is not label-aware. Furthermore, admin portal settings do not enforce Microsoft Purview DLP rules, which are the proper mechanism for controlling dissemination of content based on 'Highly Confidential' labels.
- ✓
Create a DLP policy in Microsoft Purview that applies to Power BI and blocks sharing of content with the 'Highly Confidential' label.
Why this is correct
Creating a Data Loss Prevention policy in Microsoft Purview that targets the Power BI workload is the correct, service-native approach: the policy can specify a condition that the sensitivity label equals 'Highly Confidential', and define an action to block the share, optionally allowing an override or business justification. When a user attempts to share a labeled item, Purview, via its integration with Power BI, intercepts the request and enforces the policy in near real time, providing both audit and DLP event logs. This is the only listed option that directly uses label-aware DLP semantics to prevent unauthorized sharing.
Go deeper
Related to this question
About these practice questions
One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.