Courseiva

PL-300 Manage and secure Power BI Practice Question

Your organization uses row-level security (RLS) in Power BI. You have a table 'Sales' with a column 'Region'. You define a role 'RegionManagers' with the filter: [Region] = "North". A user named Alice is a member of this role. However, when Alice views a report that uses this dataset, she sees all regions. What is the most likely reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Alice is the dataset owner.

The correct answer is B: Alice is the dataset owner. In Power BI, members of the dataset's Admin/owner workspace role (or the dataset owner) bypass row-level security, so Alice sees all regions despite being assigned to the RegionManagers role with the filter [Region] = "North". RLS is enforced only for users who access the dataset with Viewer, Contributor, or read permissions, not for owners/admins. Option A is wrong because DirectQuery does support RLS. Option C is wrong because a static filter like [Region] = "North" is valid; USERNAME()/USERPRINCIPALNAME() is only needed for dynamic filtering. Option D is wrong because RLS is enforced in the Power BI service as well as in Desktop.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The dataset uses DirectQuery mode, which does not support RLS.

    Why it's wrong here

    DirectQuery mode does support row-level security (RLS). In Power BI, RLS can be defined for datasets that use DirectQuery, and Power BI enforces the rules by injecting row filters into the queries sent to the underlying data source. The only caveat is that if you use a live connection to an Analysis Services model, RLS must be configured at the source; but for DirectQuery against other databases, RLS works in Power BI. Therefore, the claim that DirectQuery is incompatible with RLS is false.

  • ✓

    Alice is the dataset owner.

    Why this is correct

    Alice, as the dataset owner, bypasses RLS entirely. In the Power BI service, users who have Owner permission (or Write permission) on the dataset are exempt from row-level security filters, so they can see all rows in any report built on that dataset. Even in Power BI Desktop, the model designer sees all data unless they explicitly test a role with 'View as'. Thus, Alice seeing all data is expected when she owns the dataset.

  • ✗

    The filter must use USERNAME() or USERPRINCIPALNAME() function.

    Why it's wrong here

    RLS rules do not require the USERNAME() or USERPRINCIPALNAME() functions. You can create static filters, such as [Region] = 'West', that apply a fixed row-level constraint to every user in a role. USERNAME() and USERPRINCIPALNAME() are only needed for dynamic security rules that must identify the current viewer and filter based on that identity. Therefore, saying the filter 'must' use these functions is incorrect.

  • ✗

    RLS is only applied in Power BI Desktop, not in the service.

    Why it's wrong here

    RLS is enforced in the Power BI service, not in Power BI Desktop. In Desktop, you can define roles and rules, but those rules are not applied to your own view when exploring data; you can test them using 'View as' to impersonate a role. When a report is published to the service, the RLS rules are applied for regular viewers who have at least the 'Read' (or 'Build') permission, filtering the data they see. Thus, RLS is not limited to Desktop.

About these practice questions

Courseiva writes every PL-300 question from scratch — 524 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.