PL-900 Practice Question: Manage the Microsoft Power Platform environment
A company uses Microsoft Copilot Studio to create a custom copilot. The copilot needs to access customer data stored in a Dataverse table that contains sensitive information. The compliance team requires that data accessed by the copilot must be audited. What should the admin configure?
⚠ Common exam trap
Many exam-takers confuse analytics (usage metrics) with auditing (compliance logging), or assume that a DLP policy alone satisfies audit requirements, when in fact auditing must be explicitly enabled in Microsoft Purview to capture detailed interaction logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable auditing in Microsoft Purview and log copilot interactions.
Microsoft Purview auditing captures detailed logs of user and admin activities, including interactions with custom copilots built in Copilot Studio. By enabling auditing in Purview and logging copilot interactions, the admin can meet the compliance requirement to audit all data accessed by the copilot, ensuring a traceable record of sensitive customer data access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy Microsoft Sentinel to monitor copilot behavior.
Why it's wrong here
Microsoft Sentinel monitors and correlates security events; it does not record which Dataverse rows a copilot accessed. It is tempting because Sentinel provides auditing telemetry, but the compliance requirement is satisfied by enabling Dataverse auditing on the table, which logs record-level access.
- ✗
Configure a DLP policy to block non-compliant data access.
Why it's wrong here
A DLP policy blocks or warns on sensitive data flows; it prevents access rather than recording it. It is tempting because DLP addresses compliance around sensitive Dataverse data, but auditing demands a record of access, which Dataverse auditing supplies. DLP produces no access log for the copilot.
- ✓
Enable auditing in Microsoft Purview and log copilot interactions.
Why this is correct
Enabling auditing in Microsoft Purview captures copilot interactions and Dataverse data access in the unified audit log, satisfying the compliance team's requirement that copilot-accessed sensitive data be auditable. Other settings govern authentication or sharing, not audit trails.
- ✗
Use Copilot Studio analytics to track usage.
Why it's wrong here
Copilot Studio analytics reports conversation volume, resolution, and engagement metrics, not Dataverse record access. It is tempting because it is built-in telemetry, but it captures session-level usage rather than which sensitive rows were read. Dataverse auditing provides the required record-level trail.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.