Courseiva
Manage the Microsoft Power Platform environmentmediumMultiple SelectObjective-mapped

PL-900 Practice Question: Manage the Microsoft Power Platform environment

A company wants to enforce data loss prevention (DLP) policies for Power Automate flows. Which TWO actions can the administrator perform?

⚠ Common exam trap

Many candidates confuse environment-level DLP policy assignment with user-level assignment, or assume that tenant-level policies are automatically inherited by all environments, when in fact each environment can have its own independent DLP policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Block specific connectors from being used in flows

Administrators can block specific connectors from being used in Power Automate flows as part of a DLP policy, preventing data from being shared with unauthorized services. Option C is correct because DLP policies can be scoped to a specific environment, allowing granular control over connector usage within that environment. This enables the administrator to enforce data protection rules tailored to different business contexts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Allow users to bypass DLP policies with administrator approval

    Why it's wrong here

    DLP policies cannot be bypassed; they are enforced.

  • Block specific connectors from being used in flows

    Why this is correct

    Blocking connectors is a common DLP action.

  • Create a custom DLP policy for a specific environment

    Why this is correct

    Creating a custom DLP policy allows defining connector groups for that environment.

  • Assign DLP policies to specific users

    Why it's wrong here

    DLP policies are applied to environments, not individual users.

  • Inherit the tenant-level DLP policy for all environments

    Why it's wrong here

    Inheriting is a configuration, not an action to enforce; the admin can set it, but the question asks for actions to enforce.

About these practice questions

Courseiva writes every PL-900 question from scratch — 904 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on PL-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses Microsoft Power Platform and wants to enforce data loss prevention (DLP) policies for all environments. The admin needs to block the use of SharePoint connector in all default environments. Which action should the admin take?

medium
  • A.Create a DLP policy and assign it to the default environment only.
  • B.Use Microsoft Entra ID conditional access to block the SharePoint connector.
  • C.Create a DLP policy that applies to all environments and block the SharePoint connector.
  • D.Configure connector sharing settings in Power Apps to block SharePoint.

Why C: DLP policies in Microsoft Power Platform are designed to control connector usage across environments. By creating a DLP policy that applies to all environments and blocking the SharePoint connector, the admin ensures that the connector is prohibited in every environment, including all default environments. This action directly enforces the data loss prevention requirement at the tenant level.

Variation 2. A global company with offices in multiple regions wants to ensure that Power Automate flows processing sensitive customer data are only executed in specific geographic regions to comply with data residency requirements. What should the administrator configure?

medium
  • A.Data loss prevention (DLP) policies
  • B.Audit log settings
  • C.Solution checker
  • D.Environment routing rules

Why A: Data loss prevention (DLP) policies can be applied to environments in specific geographic regions to restrict connectors and data flow, ensuring that sensitive data is processed only in allowed regions. Environment routing rules do not exist as a feature in Power Platform. Audit logs only record events, not enforce residency. Solution checker analyzes solutions for code issues, not data residency.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.