PL-900 Practice Question: Manage the Microsoft Power Platform environment
A company uses Power Automate flows that access Microsoft SharePoint and Microsoft Dataverse. They want to prevent data from leaving the organization. What should they configure?
⚠ Common exam trap
Many exam-takers confuse data loss prevention with broader security tools like Microsoft Purview or Conditional Access, not realizing that DLP policies are the specific Power Platform feature for controlling connector-level data flow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a data loss prevention (DLP) policy in the Power Platform admin center that blocks sharing data with external connectors.
Data Loss Prevention (DLP) policies in the Power Platform admin center are specifically designed to prevent data from leaving the organization by controlling which connectors can share data. By blocking external connectors, the policy ensures that SharePoint and Dataverse data cannot be sent to unauthorized external services, directly addressing the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Microsoft Purview to automatically classify and protect data in Power Automate.
Why it's wrong here
Purview classification labels and protects data at rest and in supported workloads, but it does not govern connector-level transfers inside Power Automate flows. It is tempting because Purview is Microsoft's data-governance suite, yet preventing SharePoint-to-Dataverse egress requires a Data Loss Prevention policy.
- ✗
Enable Microsoft Defender XDR to monitor for suspicious data transfers.
Why it's wrong here
Defender XDR detects and correlates suspicious activity after the fact; it does not block data from leaving through Power Automate connectors. It is tempting because it provides cross-workload threat visibility, but the requirement is preventive enforcement, which Data Loss Prevention policies supply.
- ✓
Create a data loss prevention (DLP) policy in the Power Platform admin center that blocks sharing data with external connectors.
Why this is correct
A tenant-level DLP policy in the Power Platform admin center classifies connectors into business, non-business and blocked groups, preventing flows from combining SharePoint and Dataverse data with external connectors, which directly enforces the no-data-leaving constraint.
- ✗
Apply Microsoft Entra ID Conditional Access policies to require managed devices.
Why it's wrong here
Conditional Access governs sign-in and device compliance, not the movement of data between connectors within a flow. It is tempting because managed-device policies restrict access to corporate resources, but they cannot inspect or block SharePoint-to-Dataverse transfers; Data Loss Prevention policies do that.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.