PL-900 Practice Question: Describe the business value of Microsoft Power Platform
A company has a legacy on-premises SQL Server database and wants to build a Power BI report that refreshes daily. However, the database is behind a firewall. What should they use to securely access the data?
⚠ Common exam trap
A common mix-up: candidates confuse a VPN or direct connector (like Power Automate) as sufficient for firewall traversal, but the PL-900 exam specifically tests the on-premises data gateway as the only secure, supported method for scheduled Power BI refresh from behind a firewall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An on-premises data gateway
An on-premises data gateway is the correct solution because it acts as a secure bridge between on-premises data sources (like SQL Server behind a firewall) and cloud services such as Power BI. The gateway encrypts data in transit and allows scheduled refresh without opening inbound ports in the firewall, using outbound connections to Azure Service Bus.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Power Automate with SQL connector
Why it's wrong here
Power Automate flows run in the cloud and cannot reach a database behind an on-premises firewall, so they cannot supply refresh data. It is tempting because the SQL connector appears to query databases directly, and it would be correct for triggering actions on data changes once an on-premises data gateway is installed.
- ✓
An on-premises data gateway
Why this is correct
An on-premises data gateway installs inside the corporate network, letting Power BI cloud services query the firewalled SQL Server without exposing it to inbound internet traffic. It satisfies the daily refresh requirement by relaying scheduled refresh requests securely outbound, authenticated through Microsoft Entra ID, so the legacy database stays protected behind the firewall.
- ✗
Microsoft Dataverse
Why it's wrong here
Dataverse is a cloud-based low-code data platform, not a connectivity tool for on-premises SQL Server behind a firewall. It lacks the on-premises data gateway required to bridge the firewall and enable scheduled Power BI refresh from a legacy database. This option tempts because Dataverse can store and manage data for Power BI, but it cannot directly ingest data from a locked-down on-premises SQL Server without a gateway. It would be correct if the company wanted to build a cloud-native data store for Power BI from scratch, not connect to an existing on-premises database.
- ✗
A VPN connection to the database
Why it's wrong here
A VPN tunnels the workstation's traffic but does not give the Power BI cloud service a route to an on-premises database, so scheduled refresh still fails. It is tempting because VPNs do secure remote access, and one would be correct for an interactive user session rather than unattended cloud refresh, which needs an on-premises data gateway.
Go deeper
Related to this question
About these practice questions
One of 701 original PL-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.