Courseiva

PL-900 Practice Question: Manage the Microsoft Power Platform environment

A non-profit organization uses Power Platform to manage donor information. The organization wants to ensure that only users in the ‘Donor Managers’ security group can edit records in the ‘Donations’ table. What is the best way to achieve this?

⚠ Common exam trap

Watch out — candidates often confuse app-level sharing (Option C) with data-level security, forgetting that a canvas app's sharing settings only control access to the app interface, not the underlying Dataverse record permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign a custom security role that grants edit permissions on the Donations table to the security group

The most direct and secure method to control record-level permissions in Dataverse is to assign a custom security role with specific edit privileges on the Donations table to the 'Donor Managers' security group. This leverages Dataverse role-based security, which governs CRUD operations at the table level, ensuring that only members of that group can edit records without affecting other tables or users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a DLP policy to restrict edit connectors

    Why it's wrong here

    Data loss prevention policies govern which connectors and actions makers may use across environments; they do not control record-level editing rights in Dataverse. DLP suits blocking connector combinations, such as preventing SharePoint and Outlook sharing in one environment.

  • ✗

    Use a business process flow to require approval

    Why it's wrong here

    Business process flows guide users through defined stages and can enforce approvals, but they do not restrict who may edit a record. Table permissions govern that. Approval routing suits enforcing sign-off steps within a process, not row-level edit authorisation.

  • ✗

    Share the canvas app only with the security group

    Why it's wrong here

    Sharing a canvas app controls who can open and run that app, not who can edit the underlying Dataverse table; users could still edit via other apps or directly. App sharing suits distributing a finished app to a defined audience.

  • ✓

    Assign a custom security role that grants edit permissions on the Donations table to the security group

    Why this is correct

    Power Platform table permissions are granted through security roles, not group membership alone. Assigning a custom role with edit privileges on the Donations table to the Donor Managers group restricts editing to those users, meeting the least-privilege requirement.

About these practice questions

Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.