PL-900 Demonstrate the capabilities of Power Apps Practice Question
A company uses Power Apps to create a canvas app for employee expense reporting. The app needs to integrate with the corporate HR system to fetch employee details such as manager email and cost center. The HR system exposes a REST API that requires an API key in the header. Which approach should the app maker use to securely connect to the HR system?
⚠ Common exam trap
PL-900 often tests the misconception that storing API keys in app formulas or using HTTP actions is acceptable, when the exam expects you to recognize custom connectors with proper authentication as the secure approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom connector with API key authentication and use it in the app.
Creating a custom connector with API key authentication is the recommended approach because it securely stores the API key in the connector's authentication configuration, and the connector can be reused across apps and flows. This avoids exposing the key in the app's formulas or client-side code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the HR data in a SharePoint list and connect the app to SharePoint.
Why it's wrong here
A SharePoint list cannot hold the API key in a header or call the REST endpoint, so the HR data would be stale and the key unsecured. It is tempting because SharePoint is a familiar connector, and would be correct if the HR system already synchronised its data there.
- ✗
Build a Power Automate flow that calls the API and returns data to the app.
Why it's wrong here
Power Automate cannot return data synchronously to a canvas app without a response action, and the API key would still need storing in the flow's connection or environment variable rather than the app's secure connector. It suits scheduled or triggered background integrations, not on-demand per-user data retrieval.
- ✓
Create a custom connector with API key authentication and use it in the app.
Why this is correct
A custom connector lets the maker declare API key authentication, so Power Apps injects the key header on every call without exposing it in formulas. This satisfies the stem's requirement to fetch employee details from a REST API secured by a header key, and the connector can be shared and governed through a Power Platform environment.
- ✗
Use the HTTP action in Power Apps to call the API and include the API key in the headers as a static value.
Why it's wrong here
Hard-coding the API key in the app exposes it to every user who opens the app, since canvas app formulas are readable client-side. The HTTP action with a static header value cannot reference a secure connection. A custom connector storing the key in Microsoft Entra ID-authenticated credentials is the correct approach.
Go deeper
Related to this question
About these practice questions
One of 701 original PL-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.