PL-900 Demonstrate the capabilities of Power Apps Practice Question
A team is creating a model-driven app to manage customer service cases. They want to ensure that only users with a specific security role can delete cases. What should they configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security roles
Security roles in model-driven apps define permissions, including the ability to delete records. Option B is wrong because business rules define business logic and form behavior, not security permissions. Option C is wrong because the SharePoint connector is used for integration with SharePoint, not for security. Option D is wrong because app properties control settings like appearance and ownership, not security permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security roles
Why this is correct
Security roles in Microsoft Dataverse define privileges at table and record level, including the Delete permission. Assigning a role without delete rights to the relevant users prevents case deletion while preserving read and update access.
- ✗
Business rules
Why it's wrong here
Business rules apply server-side logic and field validation within a table; they cannot grant or restrict delete privileges by security role. It is tempting because business rules do control record behaviour conditionally, but authorisation is enforced by Dataverse security roles, which define table-level privileges such as Delete.
- ✗
SharePoint connector
Why it's wrong here
A SharePoint connector integrates external SharePoint data into Power Apps; it enforces no Dataverse table privileges. It is tempting because connectors control data access for the app, but delete permission on the Case table is governed by Dataverse security roles, not by which connector the app uses.
- ✗
App properties
Why it's wrong here
App properties configure presentation settings such as icon, name and client type; they carry no security-role enforcement. It is tempting because app-level settings appear to govern who can use the app, but delete permission on Case records is a Dataverse table privilege, assigned through security roles rather than app metadata.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.