Courseiva

PL-900 Practice Question: Describe the business value of Microsoft Power Platform

A global manufacturing company uses Microsoft Power Platform to manage its equipment maintenance processes. The company has over 10,000 maintenance technicians worldwide who use a Power Apps mobile app to report equipment issues and log repairs. The app connects to a common data service (Dataverse) that stores all maintenance records. Recently, the company experienced a data breach where a malicious user exploited a vulnerability in the app to access and delete maintenance records from multiple high-value machines. The security team traced the issue to the app's permissions model: the app was using a single service account with elevated privileges to perform all data operations. The company now wants to redesign the app's security to follow the principle of least privilege while maintaining usability for technicians. The technicians need to view their assigned work orders, create new issue reports, and update the status of their own repairs, but they should not be able to delete records or access records from other regions. Which approach should the company take?

⚠ Common exam trap

Candidates often think creating separate apps or using basic roles is sufficient, but they overlook the need for both row-level security and individual user accounts to enforce least privilege and data isolation across regions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement row-level security in Dataverse to restrict technicians to their own records and region, assign appropriate role-based access (create, read, update, no delete), and use individual user accounts.

It applies the principle of least privilege by using individual user accounts with Dataverse role-based security and row-level security (RLS). This ensures each technician can only create, read, and update their own assigned records within their region, while explicitly denying delete permissions. This approach eliminates the shared, over-privileged service account and enforces granular data isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace the Power Apps app with a Power Automate flow that technicians trigger via email to submit and update records.

    Why it's wrong here

    Email-triggered flows remove the mobile app entirely, so technicians lose the interface for viewing assigned work orders and updating repairs, and flows still execute under a connection's privileges. It is tempting because it eliminates the vulnerable app, and it would be correct if technicians only needed to submit data without interactive record access.

  • ✗

    Configure each technician's individual user account with a basic user role in Dataverse, and remove the service account.

    Why it's wrong here

    A basic user role grants organisation-wide read on Dataverse tables, so technicians could still view other regions' records, and it lacks the record-level scoping the stem demands. Basic roles suit simple environments where all users legitimately share the same data access.

  • ✓

    Implement row-level security in Dataverse to restrict technicians to their own records and region, assign appropriate role-based access (create, read, update, no delete), and use individual user accounts.

    Why this is correct

    Row-level security in Dataverse filters records per user, so technicians see only their own and their region's rows, while role-based privileges grant create, read and update but withhold delete. Individual accounts replace the shared elevated service account, directly satisfying least privilege without breaking technician workflows.

  • ✗

    Create a separate Power Apps app for each region, each with its own service account that has restricted permissions to that region's data.

    Why it's wrong here

    Per-region apps with separate service accounts still run every technician's operations under shared elevated credentials, so least privilege is not enforced per user and deletion remains possible. It is tempting because it scopes data by region, and it would be correct if isolation between regions, not per-user authorisation, were the only requirement.

About these practice questions

This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.