PL-300 Manage and secure Power BI Practice Question
Your organization uses Power BI with a shared capacity. You have a dataset that is refreshed daily from an on-premises SQL Server database using an on-premises data gateway. The dataset contains sensitive financial data. The security team requires that all access to the dataset be logged and that any access from outside the corporate network be flagged. You need to implement a monitoring solution. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Power BI activity logging and stream to Azure Log Analytics, then create alerts on access events from external IPs.
Power BI activity logging captures dataset access events (including who accessed the dataset and from which client IP), and streaming those logs to Azure Log Analytics lets you query and alert on access originating from outside the corporate network, satisfying both the logging and external-access-flagging requirements. The other options do not fit: Azure SQL Auditing (A) only logs activity at the SQL Server level, not Power BI dataset access, and the source is on-premises SQL Server rather than Azure SQL. Microsoft Defender for Cloud Apps (B) enforces conditional access but does not provide the required access logging and external-IP flagging for the dataset. Gateway logging (C) records gateway connectivity and query traffic, not end-user dataset access events or their source IPs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit the SQL Server database using Azure SQL Auditing.
Why it's wrong here
Azure SQL Auditing is designed to capture database-level events such as SELECT, INSERT, or login attempts against the underlying SQL Server/Azure SQL database. It does not record who opened a Power BI report or dataset in the Power BI service because those interactions occur at the application tier, not the database tier. Even if the Power BI dataset queries an Azure SQL database, the audit log would show the service principal or gateway as the client, not the end user, making it useless for detecting external IP access to Power BI shares.
- ✗
Use Microsoft Defender for Cloud Apps to enforce conditional access policies.
Why it's wrong here
Microsoft Defender for Cloud Apps (now part of Microsoft 365 Defender) enforces conditional access, session policies, and anomaly detection, but it is not an auditing mechanism for capturing every dataset access event. While it can provide some visibility into Power BI usage via app governance, it does not produce a complete, searchable log of who viewed or exported each dataset in shared capacity. The primary requirement here is to log all dataset access and alert on external IPs, which requires the Power BI activity log rather than Defender policies.
- ✗
Enable logging on the on-premises data gateway and monitor the logs.
Why it's wrong here
The on-premises data gateway logs only data refresh operations—for example, when a dataset checks for updated data or when a scheduled refresh runs. It does not log interactive user access to reports or datasets in the Power BI service, because such access never traverses the gateway. Thus, enabling gateway logging would provide no insight into which user opened a dataset or from which IP address, leaving the monitoring requirement completely unfulfilled.
- ✓
Enable Power BI activity logging and stream to Azure Log Analytics, then create alerts on access events from external IPs.
Why this is correct
Power BI activity logging captures all user interactions with datasets, including views, exports, and sharing, and can be streamed to an Azure Log Analytics workspace for centralized analysis. Once in Log Analytics, you can write KQL queries to filter activity records by IP address ranges and configure alerts to trigger when access originates from external IPs. This approach fully satisfies the requirement to log all dataset access and proactively monitor for suspicious external access in a shared capacity environment.
Go deeper
Related to this question
About these practice questions
One of 524 original PL-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.