PL-900 Demonstrate the capabilities of Power Apps Practice Question
A company has a canvas app that connects to a Microsoft Dataverse table containing sensitive customer information. The app is shared with a group of users, but the security team wants to ensure that users can only see records that they own and cannot modify records owned by others. The maker needs to implement record-level security. What should the maker do?
⚠ Common exam trap
The trap here is thinking that filtering records in the app or restricting app editing permissions provides security, when actual record-level security must be enforced by Dataverse security roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Dataverse security role that grants User-level read and write privileges on the table and assign it to the users.
Record-level security in Dataverse is enforced through security roles with access scopes. Assigning a role with User-level read and write privileges ensures users can only access records they own. This is enforced at the data layer and applies regardless of the app used. Client-side filtering or app-sharing settings do not provide true security, and column-level security addresses a different requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the app's sharing permissions to only allow users to run the app but not edit it.
Why it's wrong here
App sharing permissions control who can use or modify the app itself, not the data within it. Even if users cannot edit the app, they could still access all records if their Dataverse security role grants broad access. The requirement is about restricting record access, which is governed by Dataverse security roles, not by app sharing settings. Therefore, this does not achieve record-level security.
- ✗
Configure column-level security on the Dataverse table to hide sensitive fields.
Why it's wrong here
Column-level security restricts access to specific fields but does not control which records a user can see or edit. The requirement is about record ownership and modification rights, not field visibility. Column-level security would not prevent a user from viewing or editing records owned by others; it only hides certain columns. Therefore, it does not meet the need for record-level security.
- ✓
Create a Dataverse security role that grants User-level read and write privileges on the table and assign it to the users.
Why this is correct
Dataverse security roles define privileges at the table level with access scopes such as User, Business Unit, or Organization. Setting the read and write privileges to User scope means users can only access records they own. Assigning this role to the group enforces record-level security directly in Dataverse, which the canvas app respects because it uses the user's credentials. This is the correct way to restrict access to owned records.
- ✗
Use the Filter function in the canvas app to show only records where the owner equals the current user.
Why it's wrong here
Filtering in the app is a client-side approach that improves the user experience but does not enforce security. A malicious user could bypass the filter by modifying the app or using other tools to access Dataverse directly. True security must be enforced at the data layer. Relying on app-level filtering leaves the data vulnerable and does not satisfy the security team's requirement.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.