Courseiva

Microsoft Power Platform Fundamentals PL-900 (PL-900) — Questions 376–450

701 questions total · 10pages · All types, answers revealed

Page 5

Page 6 of 10

Page 7
376
MCQmedium

A company is using Power Automate flows that connect to multiple third-party services. The security administrator wants to ensure that no sensitive data is sent to unauthorized external services. Which feature should be used to enforce this requirement?

A.Create and apply Data Loss Prevention (DLP) policies.
B.Enable audit logging in the Power Platform admin center.
C.Configure environment routing rules.
D.Use the Power Platform Copilot to monitor flows.
AnswerA

DLP policies in Power Platform define connector classification into Business, Non-Business and Blocked groups, then enforce which connectors a flow may combine. This directly prevents sensitive data reaching unauthorised external services, satisfying the administrator's requirement to block exfiltration across third-party connections.

Why this answer

Data Loss Prevention (DLP) policies in Power Platform define which connectors are Business, Non-Business, or Blocked, and prevent flows from combining connectors across groups — thereby stopping sensitive data from flowing to unauthorized external services. This is the purpose-built governance control for restricting connector usage across flows and apps.

Exam trap

The trap is confusing monitoring/auditing features (which detect after the fact) with preventive controls like DLP that actually block unauthorized connector combinations.

How to eliminate wrong answers

Option B is wrong because audit logging only records activity for later review; it does not prevent data from being sent to unauthorized services. Option C is wrong because environment routing rules govern how makers are directed to environments during creation, not connector-level data flow restrictions. Option D is wrong because Copilot is an assistive AI feature for authoring and does not enforce connector governance or DLP.

377
MCQmedium

A sales team uses Power BI dashboards to track quarterly revenue. They notice that the data in the dashboard is not updating as expected. The data source is a SharePoint list. What should the administrator check first?

A.Check the scheduled refresh settings in the Power BI dataset.
B.Install the on-premises data gateway.
C.Verify that all sales team members have edit permissions on the SharePoint list.
D.Ensure that the SharePoint list has no hidden columns.
AnswerA

Power BI datasets refresh on a schedule configured in the dataset settings, so stale SharePoint data usually means the refresh schedule is disabled, misconfigured, or failing. Checking that schedule first satisfies the scenario's requirement to identify why dashboard data is not updating.

Why this answer

Power BI datasets connected to SharePoint lists require a scheduled refresh to update the dashboard with the latest data from the list. If the refresh is not configured or fails, the dashboard will display stale data. The administrator should first check the scheduled refresh settings in the Power BI service to ensure it is enabled and running successfully.

Exam trap

The trap here is that candidates might assume the issue is related to permissions or data structure (options C or D) rather than recognizing that Power BI dashboards do not automatically refresh cloud data sources without a configured schedule.

How to eliminate wrong answers

Option B is wrong because an on-premises data gateway is only needed when connecting to on-premises data sources (e.g., SQL Server on a local network), not to SharePoint Online, which is a cloud service. Option C is wrong because edit permissions on the SharePoint list are not required for Power BI to read data; read permissions are sufficient, and the issue is about data freshness, not access. Option D is wrong because hidden columns in a SharePoint list do not affect Power BI's ability to refresh or display data; they are simply not included in the dataset unless explicitly added.

378
MCQmedium

A Power Platform admin needs to ensure that all environments have a backup policy that automatically creates backups every 24 hours. What is the default backup frequency for Dataverse environments?

A.Every 24 hours
B.Only for paid environments, there is no default schedule.
C.Every 12 hours
D.Every 48 hours
AnswerA

Dataverse automatically creates system backups every 24 hours.

Why this answer

The default backup frequency for Dataverse environments is every 24 hours, which ensures automatic system backups are created daily without requiring manual configuration. This policy applies to all environments, including trial and production, unless a custom backup schedule is explicitly set by an administrator.

Exam trap

The trap here is that candidates may assume backups are only for paid environments or that the default frequency is shorter (12 hours) due to common industry practices, but Microsoft's default for Dataverse is explicitly 24 hours across all environment types.

How to eliminate wrong answers

Option B is wrong because the default backup schedule applies to all Dataverse environments, not just paid ones; even trial environments receive automatic backups every 24 hours. Option C is wrong because the default interval is 24 hours, not 12 hours; a 12-hour frequency would require custom configuration. Option D is wrong because the default interval is 24 hours, not 48 hours; a 48-hour frequency would leave a longer gap between backups and is not the default.

379
MCQeasy

A company wants to automate sending a welcome email to new employees after they are added to a SharePoint list. Which type of trigger should be used in the Power Automate flow?

A.For a selected item - SharePoint
B.Recurrence
C.Start and wait for an approval
D.When an item is created - SharePoint
AnswerD

The SharePoint 'When an item is created' trigger fires automatically whenever a new list item is added, which is exactly the event that represents a new employee. This event-driven trigger initiates the flow so the welcome email is sent without manual intervention.

Why this answer

The 'When an item is created - SharePoint' trigger is the correct choice because it initiates the flow automatically whenever a new item (in this case, a new employee record) is added to the specified SharePoint list. This event-driven trigger eliminates the need for manual intervention, making it ideal for automating the welcome email process immediately upon creation.

Exam trap

The trap here is that candidates often confuse manual triggers (like 'For a selected item') with event-driven triggers, or mistakenly think a scheduled trigger (Recurrence) can achieve real-time automation, when only a creation trigger directly responds to the SharePoint list event.

How to eliminate wrong answers

Option A is wrong because 'For a selected item - SharePoint' is a manual trigger that requires a user to select an item in SharePoint and then run the flow, which does not automate the process upon creation. Option B is wrong because 'Recurrence' is a scheduled trigger that runs at specified intervals (e.g., every hour), not in response to a specific event like item creation, so it would not send the email immediately when a new employee is added. Option C is wrong because 'Start and wait for an approval' is an action used to initiate an approval process and pause the flow until a response is received, not a trigger to start the flow based on a SharePoint list event.

380
MCQhard

A model-driven app uses a custom business process flow. Users report that they cannot progress beyond a stage even after completing all required fields. What should you check?

A.Whether the stage is locked by an administrator
B.Whether the required fields on the form are marked as business required
C.Whether the user has the correct security role to update the stage
D.Whether the stage has a condition that is not being met
AnswerD

Business process flow stages can carry a condition that gates progression; if its criteria are unmet, the Next button stays disabled regardless of completed fields. Checking that condition identifies why users are blocked at the stage.

Why this answer

Business process flow stages can have conditions that must be satisfied before progressing. If a condition is not met, the user cannot move to the next stage. Option A is incorrect because stages are not locked by administrators in standard configurations.

Option B is incorrect because required fields on the form may not be part of the stage condition; the condition could involve other criteria. Option C is incorrect because security roles control access to records, not the progression within a business process flow.

381
MCQhard

A Power Automate cloud flow uses the 'Apply to each' action to process a large array of items from a Microsoft Dataverse table. The flow is taking longer than expected, and you need to optimize performance. What should you do?

A.Add a 'Delay' action inside the loop to reduce load on the service.
B.Replace the 'Apply to each' action with a 'Do until' loop.
C.Enable concurrency control on the 'Apply to each' action and set a degree of parallelism.
D.Increase the flow's timeout setting in the flow properties.
AnswerC

Enabling concurrency control allows the 'Apply to each' action to process multiple items in parallel, reducing overall execution time. Setting a degree of parallelism (e.g., 10) controls how many iterations run simultaneously. This is the recommended optimization for large arrays when the operations within the loop are independent and can be parallelized.

Why this answer

Concurrency control on 'Apply to each' allows parallel execution of loop iterations, significantly speeding up processing of large arrays when operations are independent. The other options either do not improve speed or worsen it. Increasing timeout only extends allowed duration, and adding delays slows the flow.

Replacing with 'Do until' is not appropriate for iterating a collection.

Exam trap

The trap here is thinking that increasing timeout or adding delays will speed up a slow loop, when actually concurrency is the key optimization.

382
MCQmedium

A company wants to automate the process of sending a welcome email to new employees after their HR record is created in Dataverse. Which component should be used?

A.Power Apps
B.Power Virtual Agents
C.Power Automate
D.Power BI
AnswerC

Power Automate triggers on the Dataverse row-creation event and executes the email action automatically, satisfying the requirement to send a welcome message once the HR record exists. Its native Dataverse connector and Outlook or Exchange actions remove manual intervention, which is precisely the automation the scenario demands.

Why this answer

Power Automate is the correct choice because it is designed to create automated workflows that trigger on events in Dataverse, such as the creation of a new HR record. It can then perform actions like sending a welcome email via connectors (e.g., Office 365 Outlook) without manual intervention.

Exam trap

The trap here is that candidates may confuse Power Apps' ability to trigger flows from within an app with the actual automation component, but Power Automate is the dedicated service for event-driven workflows like sending emails on Dataverse record creation.

How to eliminate wrong answers

Option A is wrong because Power Apps is a low-code platform for building custom apps (canvas or model-driven), not for automating workflows or sending emails based on Dataverse events. Option B is wrong because Power Virtual Agents is used to create conversational chatbots, not to trigger automated email actions from Dataverse record creation. Option D is wrong because Power BI is a business analytics tool for data visualization and reporting, not for workflow automation or email sending.

383
MCQeasy

You need to create a Power Automate flow that sends a daily digest email to the sales team summarizing new leads from the previous day. The flow should run automatically every morning at 8 AM. Which type of trigger should you use?

A.Button trigger
B.When a new email arrives
C.Recurrence
D.When a new tweet is posted
AnswerC

A Recurrence trigger schedules the flow at fixed intervals, such as daily at 8 AM, satisfying the automatic morning run requirement. It requires no external event or manual action, unlike instant or automated triggers tied to specific events.

Why this answer

Recurrence. This trigger runs the flow on a scheduled basis, such as every day at 8 AM, making it ideal for the daily digest email. Option A (Button trigger) requires manual activation, so it cannot run automatically.

Option B (When a new email arrives) triggers on email reception, not time. Option D (When a new tweet is posted) triggers on social media activity, not a daily schedule.

384
MCQhard

Refer to the exhibit. A Power Automate flow runs hourly to retrieve new accounts from Dataverse. However, it sometimes misses records created at the exact hour boundary. What is the most likely reason?

A.The flow runs on a schedule, not triggered by record creation, so it may miss records created between runs.
B.The accounts table has a security filter that hides records from the flow owner.
C.The API connection to Dataverse is not authenticated properly.
D.The filter query uses utcNow() which may not be precise across time zones.
AnswerA

A recurring schedule trigger only queries at fixed intervals, so records created between executions are absent until the next run. This explains the missed hour-boundary records, unlike an event-driven Dataverse trigger that fires on creation.

Why this answer

The flow is configured to run on a recurring schedule (e.g., every hour), not as an instant trigger on record creation. When a record is created at the exact boundary between two scheduled runs, it may not be captured by the previous run (which already completed) and may not yet exist when the next run begins, especially if the flow uses a filter query based on a timestamp. This is a classic limitation of scheduled polling compared to event-driven triggers like 'When a row is added, modified, or deleted' in Dataverse.

Exam trap

The trap here is that candidates often assume utcNow() is the cause of the issue, but the real problem is the fundamental difference between scheduled polling and event-driven triggers in Power Automate.

How to eliminate wrong answers

Option B is wrong because a security filter on the accounts table would consistently hide records from the flow owner, not cause intermittent misses at hour boundaries. Option C is wrong because an authentication issue would cause the flow to fail entirely on every run, not selectively miss records at specific times. Option D is wrong because utcNow() is time-zone agnostic and returns the current UTC time; the precision issue is not about time zones but about the polling interval missing records created between runs.

385
MCQeasy

A Power Pages site needs to allow external users to register and create an account. The organization uses Microsoft Entra ID for internal employee authentication. Which identity provider should be configured for external user self-registration?

A.Microsoft Entra ID
B.SAML 2.0
C.OpenID Connect
D.Local authentication
AnswerD

Local authentication lets Power Pages manage its own contact-based credential store, enabling external users to self-register without an existing directory account. Microsoft Entra ID is reserved for internal employees, so configuring it would block the required external self-registration scenario.

Why this answer

Local authentication in Power Pages allows external users to self-register with an email and password, which is stored in the portal's contact table. This is the standard approach for external self-registration. Option A (Microsoft Entra ID) is incorrect because it is primarily used for internal employee authentication, not for external self-registration.

Option B (SAML 2.0) is an enterprise federation protocol designed for single sign-on with external identity providers, not for direct self-registration. Option C (OpenID Connect) is an authentication protocol, not an identity provider, and is typically used for SSO scenarios, not self-registration. Therefore, only local authentication supports built-in self-registration for external users.

386
MCQeasy

A company wants to build an app that allows external vendors to submit invoices through a web portal. The app must be accessible without signing in with a Microsoft account. Which Power Platform solution should they use?

A.Power Pages site with anonymous access enabled
B.Canvas app shared with everyone
C.Model-driven app with anonymous access
D.Power Automate portal
AnswerA

Power Pages supports anonymous access, letting external vendors reach the portal without any Microsoft account sign-in. This directly satisfies the stem's constraint that users must not authenticate with Microsoft Entra ID credentials, unlike Power Apps portals requiring licensed internal users.

Why this answer

Power Pages (option A) is the correct solution because it enables external-facing websites that can be accessed by anonymous users without requiring a Microsoft account or license. Canvas apps and model-driven apps require authenticated users with appropriate licenses, and Power Automate is an automation service, not a portal for external submissions.

387
Multi-Selecthard

Which THREE of the following are best practices for creating maintainable Power Automate flows?

Select 3 answers
A.Use solution-aware flows to manage application lifecycle
B.Use complex expressions in a single action to reduce steps
C.Use child flows for reusable logic
D.Hardcode values directly in actions for clarity
E.Name actions and steps descriptively to document the flow
AnswersA, C, E

Solution-aware flows live inside a solution, so they can be exported, versioned and moved through dev, test and production environments via managed solutions. This satisfies the maintainability requirement by enabling proper application lifecycle management rather than leaving flows unmanaged in a single environment.

Why this answer

Option A is correct because solution-aware flows are packaged inside a Power Platform solution, which enables proper application lifecycle management (ALM) — moving flows across development, test, and production environments via managed/unmanaged solutions and export/import. Option C is correct because child flows (invoked via the 'Run a Child Flow' action) encapsulate reusable logic so it can be called from multiple parent flows, reducing duplication and centralizing maintenance. Option E is correct because renaming actions and steps descriptively (instead of leaving defaults like 'Apply to each') documents intent directly in the designer, making flows far easier for others to read and maintain.

Option B does not belong because cramming complex expressions into a single action hurts readability and debugging; breaking logic into well-named, smaller actions is preferred. Option D does not belong because hardcoding values reduces maintainability and portability — environment variables or configuration should be used instead so values can change per environment without editing the flow.

388
MCQeasy

A sales team at a manufacturing company wants a Power Automate cloud flow that automatically posts a message to a Microsoft Teams channel whenever a new record is added to a Microsoft Dataverse table named 'CustomerOrders'. The team does not want to write code. Which trigger should they use in the flow?

A.When an HTTP request is received
B.When a file is created (properties only)
C.Recurrence
D.When a row is added, modified or deleted (Microsoft Dataverse)
AnswerD

The Microsoft Dataverse connector provides the 'When a row is added, modified or deleted' trigger, which fires on create, update, or delete events for a chosen table. Selecting the 'Added' change type and the CustomerOrders table gives the exact no-code trigger needed to start the flow when a new order record appears.

Why this answer

Automating a Teams message from a new Dataverse record requires an event-based Dataverse trigger. The 'When a row is added, modified or deleted' trigger with the Added change type listens to the CustomerOrders table and starts the flow the moment a record is inserted, after which a Teams 'Post message' action can publish to the channel without any code.

Exam trap

The trap here is assuming any 'when something is created' trigger works, when each connector's trigger is bound to its own data source and cannot watch Dataverse tables.

389
MCQhard

You are designing a Power Pages site that requires users to reset their own passwords. The site uses Azure AD B2C for authentication. Which configuration is necessary?

A.Enable the 'Password reset' user flow in Azure AD B2C
B.Add a custom identity provider that supports password reset
C.Enable password reset in Dataverse
D.Configure Microsoft Entra ID self-service password reset
AnswerA

Enabling the 'Password reset' user flow in Azure AD B2C allows users to reset their own passwords, which is the correct configuration.

Why this answer

Azure AD B2C provides a 'Password reset' user flow that allows users to reset their own passwords. Options B, C, and D are incorrect: a custom identity provider may not support password reset natively and is unnecessary; Dataverse is a data storage layer and does not handle authentication; Microsoft Entra ID self-service password reset is intended for organizational accounts, not for external B2C users.

Exam trap

Candidates often confuse Azure AD B2C password reset with the Microsoft Entra ID self-service password reset for employees. For Power Pages with external users, use Azure AD B2C user flows.

390
MCQhard

The exhibit shows a DLP policy configuration for a Power Platform environment. Which connector is allowed for business use?

A.Outlook
B.Twitter
C.Facebook
D.SharePoint
AnswerD

SharePoint is in the Business data group under this DLP policy, so it is allowed for business use.

Why this answer

SharePoint is classified as 'Business' in the DLP policy because it is a Microsoft-owned enterprise service that supports data loss prevention (DLP) actions like blocking, monitoring, or restricting data flow. The exhibit shows SharePoint under the 'Business' data group, meaning it is allowed for business use without triggering policy violations. In contrast, Outlook, Twitter, and Facebook are placed in the 'Non-Business' group, which blocks their connectors from being used in apps and flows within this environment.

Exam trap

The trap here is that candidates assume all Microsoft-owned connectors (like Outlook) are automatically 'Business' by default, but DLP policies are environment-specific and can be customized by administrators to reclassify connectors into Non-Business groups.

How to eliminate wrong answers

Option A is wrong because Outlook is listed under the 'Non-Business' data group in the exhibit, which means its connector is blocked for business use. Option B is wrong because Twitter is also in the 'Non-Business' group, preventing its connector from being used in business flows. Option C is wrong because Facebook is likewise categorized as 'Non-Business', so its connector is disallowed for business purposes.

391
MCQeasy

A company wants to build a Power App that uses AI to extract information from uploaded invoices. Which capability should they use?

A.Power Automate with OCR actions
B.AI Builder invoice processing model
C.Power Virtual Agents
D.Copilot Studio
AnswerB

The AI Builder invoice processing model is prebuilt to extract header and line-item fields such as vendor, total and date from invoice documents. It satisfies the stem's requirement to extract information from uploaded invoices without training a custom model.

Why this answer

AI Builder's invoice processing model is a prebuilt AI capability in Power Platform specifically designed to extract structured data (vendor, total, line items) from invoices using OCR plus machine learning. It integrates directly with Power Apps and Power Automate and requires no custom model training. This is the purpose-built solution for the stated requirement.

Exam trap

PL-900 often tests whether candidates confuse conversational AI tools (Copilot Studio, Power Virtual Agents) with document-processing AI (AI Builder), so match 'extract information from invoices' to AI Builder's prebuilt invoice model.

How to eliminate wrong answers

Option A is wrong because Power Automate with generic OCR actions extracts raw text but does not understand invoice structure or map fields like invoice number and total without significant custom logic. Option C is wrong because Power Virtual Agents is for building chatbots, not document data extraction. Option D is wrong because Copilot Studio is for creating conversational AI assistants, not invoice parsing.

392
MCQhard

A university's IT team has built a Copilot Studio copilot that answers student questions about course registration. During testing, the copilot often fails to recognize variations such as 'How do I enroll in a class' and 'sign me up for a course' even though the topic trigger phrases include 'register for a course'. The team wants to improve recognition without rewriting every topic. What should the team do first?

A.Add more diverse trigger phrases to the registration topic, including the variations students actually use.
B.Switch the copilot's primary language to a different locale and republish.
C.Delete and recreate the registration topic so the model retrains from scratch.
D.Enable the Fallback topic to always route unmatched input to a human advisor.
AnswerA

Copilot Studio matches user input to topics using trigger phrases and natural language understanding. Adding varied, realistic utterances such as 'enroll in a class' and 'sign me up for a course' gives the model more examples to learn from, improving recognition without rebuilding topics. This is the lowest-effort, targeted fix for the observed recognition gap and aligns with how trigger phrases train topic matching.

Why this answer

Topic matching in Copilot Studio relies on trigger phrases that train the natural language model for each topic. When users phrase requests differently than the authored examples, recognition suffers, so adding realistic variations such as 'enroll in a class' and 'sign me up for a course' is the direct fix. Recreating topics, escalating everything, or changing locale does not improve matching.

Exam trap

The trap here is reaching for fallback routing or topic recreation when the real issue is too few realistic trigger phrase variations for the natural language model.

393
MCQhard

A large enterprise uses Power Platform with multiple environments. They need to enforce a policy that blocks all Canvas apps from using the 'Twitter' connector, but only in the 'Production' environment. What should the administrator do?

A.Create a DLP policy at the tenant level and set the 'Twitter' connector to 'Blocked'
B.Disable the 'Twitter' connector in the Power Platform admin center for the Production environment
C.Create an environment-level DLP policy for the Production environment and set 'Twitter' to 'Blocked'
D.Use the 'Set Connector' API to disable the connector for the Production environment
AnswerC

DLP policies can be scoped to a single environment, so an environment-level policy applied to Production blocks the Twitter connector there while leaving other environments unaffected. This satisfies the stem's constraint of restricting the block to Production only.

Why this answer

Environment-level DLP policies allow administrators to apply connector restrictions to specific environments, such as blocking the 'Twitter' connector only in 'Production' while leaving it available in other environments. This granular control is essential for enforcing governance without affecting development or testing environments.

Exam trap

The trap here is that candidates may assume tenant-level policies are the only option or that connectors can be disabled directly in the admin center, but the correct approach requires understanding that environment-level DLP policies provide the necessary granularity.

How to eliminate wrong answers

Option A is wrong because a tenant-level DLP policy applies to all environments, not just the 'Production' environment, which would block the 'Twitter' connector everywhere. Option B is wrong because the Power Platform admin center does not provide a direct toggle to disable a specific connector per environment; connector blocking is managed through DLP policies, not a simple disable switch. Option D is wrong because the 'Set Connector' API is not a supported method for disabling connectors in Power Platform; DLP policies are the intended mechanism for controlling connector usage.

394
MCQmedium

A sales team uses a canvas app to manage customer leads. The app currently connects to a SharePoint list as its data source. The team wants to move to a more robust data platform that supports complex relationships between leads, accounts, and contacts. They also need to enforce business rules and security at the data level. Which data source should they use?

A.SQL Server on-premises via an on-premises data gateway
B.Microsoft Excel workbook stored in OneDrive
C.Microsoft Dataverse
D.SharePoint list with lookup columns
AnswerC

Dataverse provides relational data storage, rich metadata, and built-in security roles, making it ideal for complex relationships and business rules. It supports table relationships, business rules, and column-level security, which SharePoint lists lack. This aligns with the team's need for a robust data platform.

Why this answer

Dataverse is the only option that natively supports complex relationships, business rules, and security at the data level within the Power Platform. It is designed for scenarios requiring robust data modeling and governance, unlike SharePoint lists or Excel, which are better for simpler data storage.

Exam trap

The trap here is assuming that SharePoint lists with lookup columns can fully replace a relational database for complex business applications.

395
MCQeasy

A logistics company wants a copilot that greets customers on its public website and answers questions about shipping rates. The team wants the fastest way to publish a working copilot without writing code. Which Microsoft Copilot Studio capability should they use to define the conversational flow?

A.Write a custom connector that calls the shipping API from Power Apps.
B.Configure a Dataverse table with shipping rate rows and enable auditing.
C.Author the conversation visually using the Topics canvas with trigger phrases and message nodes.
D.Create a Power Automate cloud flow that sends an adaptive card to the website.
AnswerC

The Topics canvas in Microsoft Copilot Studio lets makers visually build conversation paths by defining trigger phrases and adding message, question, and condition nodes. This requires no code and is the standard way to author a copilot's dialog. For a public shipping-rate copilot, a maker can create a topic that triggers on phrases like 'shipping rates' and respond with configured messages.

Why this answer

Microsoft Copilot Studio's Topics canvas is the no-code authoring surface for conversation flow, using trigger phrases and nodes such as messages, questions, and conditions. Building a public-facing copilot that greets visitors and answers shipping questions is accomplished by creating topics, not by connectors, flows, or tables, which are supporting components rather than the dialog authoring mechanism.

Exam trap

The trap here is assuming that any Power Platform component can define a copilot's dialog, when only Copilot Studio's authoring canvas provides that capability.

396
MCQmedium

A company uses Power Apps to create a canvas app for employee expense reporting. The app needs to integrate with the corporate HR system to fetch employee details such as manager email and cost center. The HR system exposes a REST API that requires an API key in the header. Which approach should the app maker use to securely connect to the HR system?

A.Store the HR data in a SharePoint list and connect the app to SharePoint.
B.Build a Power Automate flow that calls the API and returns data to the app.
C.Create a custom connector with API key authentication and use it in the app.
D.Use the HTTP action in Power Apps to call the API and include the API key in the headers as a static value.
AnswerC

A custom connector lets the maker declare API key authentication, so Power Apps injects the key header on every call without exposing it in formulas. This satisfies the stem's requirement to fetch employee details from a REST API secured by a header key, and the connector can be shared and governed through a Power Platform environment.

Why this answer

Creating a custom connector with API key authentication is the recommended approach because it securely stores the API key in the connector's authentication configuration, and the connector can be reused across apps and flows. This avoids exposing the key in the app's formulas or client-side code.

Exam trap

PL-900 often tests the misconception that storing API keys in app formulas or using HTTP actions is acceptable, when the exam expects you to recognize custom connectors with proper authentication as the secure approach.

How to eliminate wrong answers

Option A is wrong because storing HR data in SharePoint introduces data duplication and does not securely connect to the HR system's API. Option B is wrong because a Power Automate flow can call the API, but it is not the most direct or secure approach for real-time data fetching in the app, and it adds latency and complexity. Option D is wrong because using the HTTP action in Power Apps with a static API key in headers exposes the key in the app, which is a security risk and not supported for production scenarios.

397
Multi-Selectmedium

Which TWO benefits does Power Platform offer to organizations? (Choose two.)

Select 2 answers
A.Provides seamless integration with Microsoft 365 and Azure
B.Enables citizen developers to build apps with minimal coding
C.Is free for all users with an Office 365 license
D.Eliminates the need for any custom development
AnswersA, B

Power Platform connectors natively surface Microsoft 365 services such as SharePoint and Teams, plus Azure services like Logic Apps and Functions. This shared identity and data fabric satisfies the integration benefit, letting organisations reuse existing Microsoft investments rather than building bespoke links.

Why this answer

Option A is correct because Power Platform connectors natively integrate with Microsoft 365 services (SharePoint, Teams, Outlook, Dataverse) and Azure services (Azure Functions, Logic Apps, API Management, Azure AD), allowing apps and flows to use existing identity, data, and cloud resources without custom middleware. Option B is correct because Power Apps, Power Automate, and Power Virtual Agents provide low-code/no-code visual designers, prebuilt templates, and drag-and-drop components that let citizen developers (business users outside IT) create solutions with minimal or no traditional programming. Option C is not correct because Power Platform requires standalone Power Apps/Power Automate per-user or per-app licenses; an Office 365 license alone does not grant full Power Platform capabilities beyond limited seeded rights.

Option D is not correct because Power Platform augments rather than eliminates custom development—complex scenarios still require pro-code extensions, custom connectors, plug-ins, or Azure services.

Exam trap

The trap here is that candidates assume Power Platform is entirely free with Office 365 or that it completely replaces custom development, but Microsoft explicitly requires additional licensing for premium features and encourages hybrid solutions where custom code handles edge cases.

398
MCQeasy

A company wants to create a dashboard that shows real-time sales data from their ERP system and allows managers to drill down into individual transactions. Which Power Platform component should they use?

A.Power BI
B.Power Apps
C.Power Automate
D.AI Builder
AnswerA

Power BI provides interactive dashboards with drill-down from summary visuals into underlying transaction detail, and its connectors can refresh directly from ERP sources for near real-time reporting. This satisfies the stem's requirements for both live sales data and transaction-level exploration, unlike Power Apps or Power Automate.

Why this answer

Power BI is the correct choice because it is designed for data visualization and business intelligence, enabling real-time dashboards with drill-through capabilities. It can connect directly to an ERP system via connectors or DirectQuery to display live sales data, and managers can use the drill-down feature to navigate from summary metrics to individual transaction details.

Exam trap

Microsoft often tests the misconception that Power Apps can build dashboards because it includes canvas apps with charts, but Power Apps lacks native drill-through and real-time data aggregation capabilities required for enterprise dashboards.

How to eliminate wrong answers

Option B (Power Apps) is wrong because Power Apps is a low-code platform for building custom applications, not for creating dashboards with real-time data visualization and drill-down analytics. Option C (Power Automate) is wrong because Power Automate focuses on workflow automation and process orchestration, not on interactive data visualization or dashboard creation. Option D (AI Builder) is wrong because AI Builder provides prebuilt AI models for tasks like form processing or prediction, not for building dashboards or drilling into transactional data.

399
MCQmedium

A company is deploying Power Virtual Agents (now Copilot Studio) chatbots across multiple departments. Each department needs its own environment to manage chatbots independently. However, the company wants to share a common set of entities and workflows across all environments. Which approach should the administrator take?

A.Create a single environment for all departments and use security roles to isolate chatbots
B.Use Power Apps component library to share components across environments
C.Create a shared environment for common components and link each department environment to it
D.Create a separate environment per department and deploy managed solutions containing the common components
AnswerD

Managed solutions are the supported mechanism for distributing common components across environments while preventing downstream modification. Creating one environment per department preserves independent chatbot management, and deploying the shared entities and workflows as a managed solution satisfies the stem's requirement for commonality without sacrificing departmental autonomy.

Why this answer

Managed solutions allow you to package common components (entities, workflows) and deploy them to multiple environments, ensuring consistency while maintaining departmental isolation. Each department gets its own environment for independent chatbot management, and the shared components are installed via managed solutions that cannot be modified, preserving the common baseline.

Exam trap

The trap here is that candidates confuse environment-level isolation with component sharing, assuming a single environment with security roles or a linked environment is sufficient, when the correct pattern requires deploying managed solutions to each environment.

How to eliminate wrong answers

Option A is wrong because using a single environment with security roles does not provide true isolation for chatbot management; security roles control data access but not component-level separation, and all chatbots would share the same entities and workflows, leading to potential conflicts. Option B is wrong because Power Apps component libraries are designed for sharing UI components (e.g., controls, screens) across canvas apps, not for deploying backend entities or workflows across environments. Option C is wrong because Power Platform does not support linking environments to a shared environment for common components; the correct mechanism is to use managed solutions to deploy components into each environment, not a runtime link.

400
MCQmedium

A company wants to build a custom app that allows field technicians to view and update work orders on their mobile devices, with data stored in Dataverse. Which approach minimizes development effort?

A.Create a canvas app in Power Apps
B.Use Power Automate to generate a mobile app
C.Build a custom iOS app using Swift and Xcode
D.Create a model-driven app in Power Apps
AnswerA

Canvas apps provide drag-and-drop screens and native Dataverse connectors, so technicians get mobile work-order views and updates with minimal coding. This directly satisfies the constraint of minimising development effort, unlike model-driven or custom-code approaches that demand more configuration or developer skill.

Why this answer

Canvas apps in Power Apps are designed for rapid, low-code development with drag-and-drop UI and direct Dataverse connectivity, making them the fastest path to a mobile-friendly work order app. They can be published to Power Apps mobile and run on iOS and Android without native development.

Exam trap

PL-900 often tests the distinction between canvas and model-driven apps — candidates must recognize that canvas apps minimize effort for custom mobile UIs, while model-driven apps are better for complex, data-centric processes.

How to eliminate wrong answers

Option B is wrong because Power Automate is a workflow automation service, not an app builder — it cannot generate a mobile UI. Option C is wrong because building a native Swift app requires significant development effort, which contradicts the goal of minimizing effort. Option D is wrong because model-driven apps are optimized for complex data models and desktop-style forms, and they require more setup (sitemap, forms, views) than a canvas app for a simple field technician scenario.

401
MCQmedium

A company is building a Power Apps canvas app that will be used by field technicians on mobile devices. The app must allow technicians to capture photos and store them with related work order records in Microsoft Dataverse. The maker needs to add a control that lets users take a photo using the device camera. Which control should the maker add to the app?

A.Add an Add Picture control and bind it to the work order record.
B.Add an Image control and set its Image property to the camera stream.
C.Add a Camera control and set its OnSelect property to save the photo to Dataverse.
D.Add a Camera control, then use the Patch function to save the photo to the Dataverse table.
AnswerD

The Camera control provides a live preview and allows the user to capture a photo. The captured image is available in the control's Photo property. To save it to Dataverse, you use the Patch function to create or update a record, setting the image column to the Camera control's Photo. This is the standard pattern for capturing and storing photos in a canvas app.

Why this answer

The Camera control is designed to capture photos using the device's camera. After a photo is taken, it is stored in the control's Photo property. To persist the photo with a work order record in Dataverse, the maker uses the Patch function to write the image to the appropriate record.

This combination allows technicians to capture and save photos directly within the app.

Exam trap

The trap here is thinking that the Camera control automatically saves photos to Dataverse; it only captures the image, and a separate action like Patch is required to store it.

402
Multi-Selectmedium

Which Power Platform component can be used to create and deploy a chatbot?

Select 1 answer
A.Power Automate
B.Power BI
C.Power Apps
D.Copilot Studio
E.AI Builder
AnswersD

Copilot Studio creates and deploys chatbots, satisfying the stem's requirement. It provides a low-code canvas for conversational topics, generative answers, and channel publishing, letting makers build bots that connect to Power Platform and external data without custom code.

Why this answer

Copilot Studio (formerly Power Virtual Agents) is the dedicated Power Platform component for creating and deploying chatbots using a no-code graphical interface. It allows you to design conversational topics, trigger flows, and publish the bot to channels like Microsoft Teams or websites without writing code. AI Builder provides AI models that can be integrated into a chatbot solution but cannot create or deploy a standalone chatbot.

Exam trap

The trap is that candidates may mistake AI Builder for a chatbot builder because it offers AI capabilities that can enhance chatbots, but it is not a standalone chatbot creation tool.

403
MCQeasy

A support team at a retail company is building a copilot in Microsoft Copilot Studio to greet customers and collect their email address before handing off to a human agent. The team wants the copilot to ask a question, store the response in a variable, and use that variable later in the conversation without writing code. Which Copilot Studio feature should the team use to accomplish this?

A.Question node with a variable
B.Topic redirect with a fallback topic
C.System topic for conversation start
D.Entity extraction with prebuilt entities
AnswerA

A Question node prompts the user for input and can store the response in a variable, which is exactly what is needed to capture and reuse the email address. This is a built-in, no-code capability in Copilot Studio, so the team can configure it directly in the authoring canvas without writing any code, and reference the variable in later messages or conditions.

Why this answer

Capturing user input and reusing it later requires a Question node configured to save the response into a variable. This is a core no-code authoring feature in Copilot Studio, allowing the copilot to remember the email address and use it in subsequent messages or conditions. Other features like redirects, system topics, or entity extraction do not provide the ask-and-store behavior needed here.

Exam trap

The trap here is confusing entity extraction, which recognizes data already present in an utterance, with a Question node, which actively prompts for and stores input in a variable.

404
MCQmedium

An administrator configures a Data Loss Prevention (DLP) policy with the scope set to 'All environments' and places selected connectors in the 'Blocked' group. What will be the result of this policy?

A.The connectors are allowed but audited
B.The connectors are blocked only in production environments
C.The connectors are blocked in all environments
D.The connectors are blocked except for the default environment
AnswerC

Scoping the DLP policy to 'All environments' applies the connector classification everywhere, so placing connectors in the 'Blocked' group prevents their use across every environment. This satisfies the stem's stated scope, rather than restricting blocking to a single environment.

Why this answer

A DLP policy scoped to 'All environments' applies its connector classification across every Power Platform environment in the tenant. When connectors are placed in the 'Blocked' group, any app or flow using those connectors is prevented from running in any environment, including the default one. The scope setting directly determines where the policy's restrictions take effect.

Exam trap

The trap is misreading the scope — candidates assume 'All environments' excludes the default environment or only applies to production, but it applies to every environment including the default one.

How to eliminate wrong answers

Option A is wrong because 'Blocked' is a restrictive classification, not an audit-only one; audited connectors would be in the 'Business' or 'Non-business' group with audit-only settings. Option B is wrong because 'All environments' explicitly includes every environment, not just production — there is no production-only scope in this policy. Option D is wrong because 'All environments' includes the default environment; there is no exception carved out for the default environment in this configuration.

405
MCQhard

A Power Platform administrator discovers that a developer has deployed a canvas app to production that connects to both SharePoint and an unapproved third-party REST API using a custom connector. The security team requires that custom connectors be reviewed before production use, while still allowing makers to prototype them in a sandbox environment. What should the administrator configure to meet this requirement?

A.Environment security roles that remove the Environment Maker role from the developer in production
B.A Data Loss Prevention policy scoped to the production environment that places the custom connector in the Blocked group and the sandbox environment in a separate policy that allows it
C.Connector consent settings that require admin approval for the custom connector tenant-wide
D.A tenant-wide DLP policy that places the custom connector in the Blocked group for all environments
AnswerB

DLP policies can be scoped to specific environments, so the custom connector can be Blocked in production while a different policy allows it in the sandbox. This prevents the unapproved connector from running in production yet preserves prototyping capability. It directly matches the requirement to review custom connectors before production use while allowing sandbox experimentation.

Why this answer

Data Loss Prevention policies can be scoped to individual environments, allowing the administrator to block the custom connector in production while a separate policy permits it in the sandbox. This enforces the security team's review requirement without eliminating prototyping. A tenant-wide block, role removal, and tenant-level connector consent do not provide the environment-specific control needed, and some do not affect the already deployed app.

Exam trap

The trap here is assuming DLP policies are always tenant-wide, when they can actually be scoped to specific environments, which is exactly what allows blocking a connector in production while permitting it in a sandbox.

406
MCQmedium

A financial services firm wants to automate a monthly approval process. When a department submits a request in a SharePoint list, the request must be routed to the correct approver based on the department name, and the approver must respond by email. The company wants to minimize custom development. Which Power Platform service should the firm use?

A.Power Automate
B.Power Virtual Agents
C.Power BI
D.Power Apps
AnswerA

Power Automate is the workflow automation service in the Power Platform. It can trigger when a SharePoint item is created, use a condition or switch to route by department, and send approval requests through the Approvals connector. This matches the requirement to automate routing and email-based approval with minimal custom code.

Why this answer

Power Automate provides the connectors and logic needed to trigger on a SharePoint item, branch by department, and send approval requests that approvers can act on directly from email. It is the Power Platform service purpose-built for workflow automation with minimal development. The other services handle app creation, reporting, or chat, none of which automate the approval routing described.

Exam trap

The trap here is focusing on the SharePoint submission and assuming an app is needed, when the essential requirement is automated routing and email approval handled by a flow.

407
MCQmedium

A retail company uses Power Apps to build a mobile app for store managers to approve discount requests. The app must work offline and sync when connected. Which type of app should the developer choose?

A.Portal
B.Model-driven app
C.Canvas app
D.Power Automate
AnswerC

Canvas apps support offline capability through the SaveData and LoadData functions, storing data locally on the device and syncing when connectivity returns. This directly satisfies the requirement that store managers approve discount requests without network access.

Why this answer

Canvas apps are the correct choice because they support offline capability by leveraging the Power Apps offline sync feature, which allows data to be cached locally on the device and synchronized with the data source (e.g., Dataverse or SharePoint) when connectivity is restored. This makes them ideal for mobile scenarios like store managers approving discount requests in areas with intermittent connectivity.

Exam trap

The trap here is that candidates often confuse Model-driven apps with offline capability because they see 'mobile' in the question, but Model-driven apps require a constant connection to Dataverse and do not offer built-in offline sync like Canvas apps do.

How to eliminate wrong answers

Option A is wrong because Power Apps Portals are designed for external user access via a web browser and do not natively support offline operation or mobile app deployment. Option B is wrong because Model-driven apps are primarily web-based and rely on continuous connectivity to Dataverse; while they can be used on mobile devices, they lack native offline data caching and sync capabilities without additional custom development. Option D is wrong because Power Automate is a workflow automation tool, not an app-building platform, and cannot be used to create a standalone mobile app with offline functionality.

408
MCQmedium

Fabrikam, Inc. uses Power Apps to create a canvas app for expense reporting. The app is connected to a SharePoint list named Expenses. The app allows users to submit expenses, attach receipts, and view their history. The manager wants to add a feature where users can scan a receipt using the mobile app camera and automatically extract the amount and date using AI Builder. The extracted data should be populated into the form fields. The development team needs to implement this feature. Which steps should they take?

A.Use AI Builder's receipt processing model in Power Apps
B.Create a Power Automate flow that processes the image and returns the data
C.Use the Camera control to capture the image and use a custom formula to extract text
D.Integrate Microsoft Copilot Studio to handle the receipt scanning
AnswerA

The receipt processing model extracts merchant, date and total from scanned receipts, and Power Apps can bind those outputs to form fields. This satisfies the requirement to populate amount and date automatically from a camera capture.

Why this answer

AI Builder provides a prebuilt receipt processing model that can be directly integrated into a Power Apps canvas app. This model allows users to scan a receipt using the camera, automatically extract the amount and date, and populate those values into form fields. Option B is incorrect because while a Power Automate flow could also process the image, it is an unnecessary extra step when AI Builder can be used directly within Power Apps.

Option C is incorrect because the Camera control alone cannot extract text from an image; it requires additional processing like AI Builder. Option D is incorrect because Microsoft Copilot Studio is designed for building chatbots, not for receipt scanning and data extraction.

Exam trap

Candidates may incorrectly think that a Power Automate flow is required to process the receipt image, but AI Builder's receipt processing model can be directly added to Power Apps without additional flows.

409
MCQmedium

A Power Automate cloud flow must run every weekday at 7:00 AM local time to post a summary to a Microsoft Teams channel. The flow currently uses a Recurrence trigger. The administrator needs to ensure the flow runs only on Monday through Friday and uses the correct time zone. What should the administrator configure?

A.Set the Recurrence trigger's Interval to 5 and Frequency to Day, then set the trigger's Start time to Monday at 7:00 AM.
B.Set the Recurrence trigger's Interval to 1 and Frequency to Day, then set the trigger's Time zone and add a Condition action that checks whether the current day is a weekday.
C.Set the Recurrence trigger's Interval to 1 and Frequency to Week, then add a Condition action that checks the day of the week.
D.Replace the Recurrence trigger with a 'When a new channel message is added' trigger and filter the channel for weekday posts.
AnswerB

A daily recurrence with interval 1 fires once per day at the specified time. Setting the Time zone ensures the 7:00 AM trigger aligns with local time. The Condition action can then evaluate whether the day is Monday through Friday and stop the run on weekends. This combination satisfies both the weekday-only and local-time requirements using standard trigger settings and a built-in control action.

Why this answer

A daily Recurrence trigger with interval 1 fires once every day at the configured time. Setting the trigger's Time zone aligns that firing with local time, and a Condition action can filter out Saturday and Sunday. Together these settings deliver a weekday-only 7:00 AM run without external scheduling tools, which directly meets the stated requirement.

Exam trap

The trap here is assuming that a weekly recurrence or a start time alone can restrict a flow to weekdays, when a daily recurrence plus a day-of-week condition is what actually enforces the weekday-only schedule.

410
MCQeasy

A marketing team wants to create a mobile app that allows field representatives to quickly log customer visits, capture photos, and view recent interactions. The team has limited coding experience and wants to use a drag-and-drop interface. Which Power Platform component should they use?

A.Power Apps
B.Power BI
C.Power Automate
D.Power Virtual Agents
AnswerA

Power Apps provides a drag-and-drop designer to build custom business apps for web and mobile. It supports data entry forms, camera integration, and connections to data sources like SharePoint or Dataverse. This allows field representatives to log visits, capture photos, and view interactions without writing code, perfectly matching the team's needs and skill level.

Why this answer

Power Apps is the low-code development platform in the Microsoft Power Platform, enabling users to create custom apps with a drag-and-drop interface. It supports mobile scenarios, camera controls, and integration with various data sources, making it ideal for field representatives to log visits and capture photos. The other components are not designed for building custom data entry apps.

Exam trap

The trap here is underestimating Power Apps' mobile capabilities, assuming that custom app development always requires professional coding.

411
Multi-Selecteasy

Which TWO are examples of using AI Builder within Power Platform? (Select TWO)

Select 2 answers
A.Setting up a Power Automate trigger when a new email arrives.
B.Extracting text from scanned invoices using prebuilt models.
C.Designing a custom screen in a Power Apps canvas app.
D.Creating a Power BI dashboard to visualize sales data.
E.Identifying objects in images using a custom object detection model.
AnswersB, E

AI Builder's form processing extracts text.

Why this answer

AI Builder provides prebuilt models that can extract text and data from scanned invoices without requiring custom machine learning expertise. This capability integrates directly into Power Automate and Power Apps, enabling automated processing of invoice data within the Power Platform.

Exam trap

The trap here is that candidates confuse general Power Platform features (like triggers, screen design, or dashboards) with AI Builder's specific role of providing prebuilt and custom AI models, leading them to select options that are valid Power Platform capabilities but not AI Builder examples.

412
MCQmedium

A company uses Power Apps for a field service app. They notice that the app loads slowly when users access it on mobile devices. What is the most likely cause?

A.The app has too many Power Automate flows
B.The Dataverse environment is in a different region
C.The app uses Microsoft Entra ID for authentication
D.The app contains large images that are not optimized
AnswerD

Large, unoptimised images inflate the app's payload, so each mobile screen must download and render far more data than necessary over constrained bandwidth. Since the stem's constraint is slow loading specifically on mobile devices, image weight is the dominant factor; desktop connections mask it. Optimising or compressing those assets directly reduces load time.

Why this answer

Large, unoptimized images increase the payload size that must be downloaded to the mobile device, directly impacting load times, especially over cellular networks. Power Apps loads all resources, including images, when the app starts, so oversized images cause significant delays. Optimizing images (e.g., compressing, resizing, using modern formats like WebP) reduces bandwidth usage and speeds up app loading.

Exam trap

The trap here is that candidates often confuse server-side latency (e.g., Dataverse region) with client-side resource loading, assuming any performance issue must be related to data or authentication rather than the app's static assets.

How to eliminate wrong answers

Option A is wrong because Power Automate flows run asynchronously and do not block the initial loading of a Power Apps canvas app; they are triggered by events and do not affect startup performance. Option B is wrong while a Dataverse environment in a different region can increase latency for data queries, it does not cause the app itself to load slowly on the device—app loading is primarily a client-side operation. Option C is wrong because Microsoft Entra ID authentication is a standard, lightweight token-based process that adds negligible overhead to app startup; it is not a common cause of slow loading.

413
MCQmedium

A flow fails with the error: 'GatewayTimeout'. The flow connects to an on-premises SQL Server via a data gateway. What is the most likely cause?

A.The SQL login credentials are incorrect
B.The on-premises data gateway is not running or unreachable
C.The SQL table does not exist
D.The flow trigger did not fire
AnswerB

A GatewayTimeout means the cloud service waited for the on-premises data gateway and received no response. If the gateway is stopped or unreachable, the SQL Server connection never completes, producing exactly this timeout rather than an authentication or query error.

Why this answer

The 'GatewayTimeout' error indicates that the flow successfully reached the on-premises data gateway but the gateway did not respond within the expected time frame. This typically occurs when the gateway service is not running, the machine hosting the gateway is offline, or network connectivity between the gateway and the SQL Server is broken. Incorrect credentials or missing tables would produce different errors (e.g., 'Login failed' or 'Invalid object name').

Exam trap

The trap here is that candidates confuse a 'GatewayTimeout' with authentication or data errors, assuming the issue is with credentials or the SQL object rather than the gateway's availability or network path.

How to eliminate wrong answers

Option A is wrong because incorrect SQL login credentials would result in an 'AccessDenied' or 'Login failed' error, not a timeout. Option C is wrong because a missing SQL table would produce a 'Invalid object name' or 'Table not found' error, not a timeout. Option D is wrong because if the flow trigger did not fire, the flow would not execute at all and no error would be generated.

414
MCQeasy

A sales team uses a Power Automate flow that creates a contact in Dynamics 365 Sales whenever a new lead is added to a Salesforce system. The flow has been running successfully for months, but recently it started failing with an authentication error. What is the most likely cause?

A.The flow has exceeded its daily execution quota
B.The lead entity schema in Salesforce has changed
C.The flow is hitting API rate limits
D.The Salesforce connection credentials have expired
AnswerD

Expired Salesforce connection credentials break the stored OAuth token Power Automate uses to authenticate against Salesforce, so the trigger or action fails with an authentication error. Since the flow ran successfully for months before failing, token expiry—not configuration or licensing—is the likely cause.

Why this answer

Authentication errors typically occur when the connection credentials for the connected service (Salesforce) expire or are revoked. Option A is incorrect because exceeding execution quotas would cause flow failures but not specifically authentication errors. Option B is incorrect because schema changes would cause data conversion or mapping errors, not authentication errors.

Option C is incorrect because API rate limits would produce throttling errors (e.g., HTTP 429), not authentication errors.

415
MCQmedium

A non-profit organization wants to automate the process of sending thank-you emails to donors after a donation is recorded in a SharePoint list. Which Power Platform tool should they use?

A.Power Apps
B.Power Virtual Agents
C.Power Automate
D.Power BI
AnswerC

Power Automate triggers on the SharePoint list item creation event and runs an automated cloud flow that sends the thank-you email via an Outlook connector. This delivers the event-driven automation the non-profit needs without manual intervention.

Why this answer

Power Automate is the correct tool because it is designed to create automated workflows that trigger actions based on events, such as a new item being added to a SharePoint list. In this scenario, a Power Automate flow can be configured to run automatically when a donation is recorded, then send a thank-you email via an email connector (e.g., Outlook or SMTP). This directly addresses the need for process automation without manual intervention.

Exam trap

The trap here is that candidates often confuse Power Apps (which can display data and trigger flows) with Power Automate, forgetting that Power Automate is the dedicated tool for event-driven automation without requiring a custom app interface.

How to eliminate wrong answers

Option A is wrong because Power Apps is a low-code platform for building custom apps (canvas or model-driven) that require user interaction, not for automating backend workflows like sending emails. Option B is wrong because Power Virtual Agents is used to create conversational chatbots for customer service or Q&A, not for triggering automated email actions based on data changes. Option D is wrong because Power BI is a business analytics and visualization tool for creating reports and dashboards, not for executing automated processes or sending emails.

416
MCQeasy

A mid-sized logistics company wants to give its drivers a mobile app to log delivery confirmations and capture customer signatures. The company has no professional developers and wants to build the app quickly using a drag-and-drop interface. Which Microsoft Power Platform service should they use?

A.Power Virtual Agents
B.Power BI
C.Power Apps
D.Power Automate
AnswerC

Power Apps provides a low-code, drag-and-drop canvas for building mobile and web apps without professional development. It supports offline data capture, signature controls, and integration with Dataverse or other data sources, making it the right fit for a driver-facing delivery confirmation app built rapidly by non-developers.

Why this answer

Power Apps is the low-code application development service in the Microsoft Power Platform. It enables non-developers to assemble mobile and web apps with drag-and-drop controls, connect to data sources, and include features like signature capture and offline use. The other services focus on automation, analytics, or chatbots, none of which deliver an interactive driver-facing app.

Exam trap

The trap here is assuming that any Power Platform service can build a mobile data-entry app, when only Power Apps provides the low-code UI design surface for that purpose.

417
MCQeasy

You need to create a flow that runs every hour to check a SharePoint list for items with a 'Due Date' that has passed and sends a reminder email to the assigned person. Which type of flow should you create?

A.Desktop flow
B.Automated cloud flow
C.Business process flow
D.Scheduled cloud flow
AnswerD

A scheduled cloud flow uses a recurrence trigger, running automatically at fixed intervals such as every hour. This satisfies the stem's requirement to check the SharePoint list periodically and send reminder emails without manual initiation.

Why this answer

A scheduled cloud flow is designed to run on a recurring schedule, such as every hour. It is triggered by a time-based recurrence, not by an event. This matches the requirement to check a SharePoint list hourly and send reminder emails.

Exam trap

The trap is confusing scheduled flows with automated flows; candidates might pick automated because it sounds automatic, but the key is the time-based recurrence trigger.

How to eliminate wrong answers

Option A is wrong because desktop flows run on a local computer and are triggered manually or by other flows, not on a cloud schedule. Option B is wrong because automated cloud flows are triggered by events (e.g., when an item is created), not by a time schedule. Option C is wrong because business process flows define a sequence of stages for user interaction, not automated scheduled tasks.

418
MCQmedium

You are building a flow to automate the process of copying files from one SharePoint document library to another when a file is added. The flow should also send an email notification to a team. You have created the flow, but it is not triggering when a new file is added. What should you check first?

A.Verify that the flow owner has a valid Power Automate license
B.Confirm that the target library exists and is accessible
C.Ensure that the environment is not in a disabled state
D.Check the trigger configuration to ensure the correct library and site are selected
AnswerD

A SharePoint 'when a file is created' trigger only fires for the specific site and document library named in its configuration. If those fields reference the wrong library, additions elsewhere never start the flow, so verify them first.

Why this answer

When a flow does not trigger on file creation, the most common cause is a misconfigured trigger — the wrong site address, library name, or folder path selected in the 'When a file is created' trigger. Verifying the trigger configuration is the fastest first diagnostic step because it directly controls whether the flow fires. Other checks (licensing, environment state, target library) are valid but less likely to be the root cause of a non-firing trigger.

Exam trap

The trap is overthinking the problem by jumping to licensing or environment issues; the exam expects you to recognize that a non-firing trigger almost always points to trigger configuration (wrong site/library) as the first thing to verify.

How to eliminate wrong answers

Option A is wrong as a first check because a missing license typically prevents the flow from being saved or run at all, not just from triggering on a specific event. Option B is wrong because an inaccessible target library would cause the flow to fail after triggering, not prevent the trigger from firing. Option C is wrong because a disabled environment would block all flows in that environment, which is a broader symptom than a single flow not triggering.

419
MCQmedium

A company wants to create a Power App that allows employees to submit expense reports with receipts. The app must be accessible from both mobile devices and desktop browsers, and must include a workflow for approval. Which combination of Power Platform components should be used?

A.Canvas app with Power Automate flow triggered by form submission.
B.Model-driven app with embedded Power Automate flow for approval.
C.Canvas app with AI Builder to process receipts and Power Automate for approval.
D.Power Pages site with a custom workflow.
AnswerA

A canvas app provides the responsive form and receipt upload across mobile and desktop browsers, while a Power Automate flow triggered on submission routes the report through the approval workflow. Together they satisfy the cross-device and approval requirements.

Why this answer

A canvas app is designed for responsive UI across mobile and desktop, making it suitable for both devices. Power Automate can be triggered from the canvas app (e.g., on form submission) to handle the approval workflow. Option B is incorrect because model-driven apps are not as flexible for custom mobile layouts.

Option C is incorrect because AI Builder is not required for receipt processing in this scenario; while it could be used, it is not necessary. Option D is incorrect because Power Pages is for external-facing websites, not internal apps with approval workflows.

420
MCQeasy

A team lead wants to give a colleague permission to edit the structure of a canvas app, including adding screens and modifying formulas, but not to publish it to end users. Which sharing role should be assigned in Power Apps?

A.System Administrator
B.Co-owner
C.Environment Maker
D.User
AnswerB

The Co-owner role allows a user to edit the app, including adding screens and changing formulas, and also to share it with others, but it does not grant publishing rights to the environment's production apps. This matches the requirement of editing structure without publishing to end users.

Why this answer

App sharing in Power Apps offers Co-owner and User roles. Co-owner lets a colleague edit the app's structure and formulas, while User only allows running the app. Environment Maker and System Administrator are environment or Dataverse roles that do not target per-app editing permissions.

Co-owner is the least-privilege choice that still permits structural edits.

Exam trap

The trap here is confusing environment-level roles such as Environment Maker with app-level sharing roles, when only Co-owner grants edit access to a specific canvas app.

421
MCQmedium

An organization wants to ensure that all Power Platform solutions in production environments are tracked and changes are approved. What should the administrator implement?

A.Data Loss Prevention (DLP) policies
B.Environment security groups
C.Disable the 'Create personal productivity environments' setting
D.Managed solutions with application lifecycle management (ALM)
AnswerD

Managed solutions lock components, preventing unmanaged edits in production, while ALM enforces approval gates through pipelines and environments. This satisfies the requirement that production solutions be tracked and changes approved, since unmanaged customisation bypasses governance entirely.

Why this answer

Managed solutions with application lifecycle management (ALM) ensure that all Power Platform solutions in production environments are tracked and changes are approved by enforcing version control, solution layering, and controlled deployment through environments. This approach uses solution components and environment segmentation to prevent unapproved modifications and maintain an audit trail.

Exam trap

The trap here is that candidates often confuse DLP policies or security groups with change management, but only managed solutions with ALM provide the structured tracking and approval workflow required for production governance.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies control data flow between connectors and prevent data exfiltration, but they do not track or approve changes to solutions. Option B is wrong because environment security groups manage user access and permissions to environments, not the tracking or approval of solution changes. Option C is wrong because disabling the 'Create personal productivity environments' setting only prevents users from creating their own environments, but does not enforce change tracking or approval for production solutions.

422
Multi-Selectmedium

Which TWO features can be used to secure data in Power BI?

Select 2 answers
A.Q&A visuals
B.Bookmarks
C.Drill-through
D.Row-level security (RLS)
E.Sensitivity labels
AnswersD, E

Row-level security in Power BI restricts data at query time by evaluating DAX filter expressions against each user's identity, so recipients see only permitted rows. It satisfies the requirement to secure data by enforcing access within a single semantic model, using Microsoft Entra ID or workspace roles to scope visibility.

Why this answer

Row-level security (RLS) [CORRECT] is a Power BI security feature that restricts data access for given users by applying DAX filter expressions to roles defined in the dataset, so users only see the rows they are permitted to view. Sensitivity labels [CORRECT] are Microsoft Purview Information Protection labels applied to Power BI items (datasets, reports, dashboards) that classify and protect data, enforcing encryption and access policies even when content is exported to Excel, PowerPoint, or PDF. The other options are not security features: Q&A visuals let users ask natural-language questions of data, Bookmarks capture a saved view state of a report page, and Drill-through navigates to a filtered detail page — all are interactive/reporting capabilities, not data-protection mechanisms.

Exam trap

The trap here is that candidates confuse features for data exploration or navigation (Q&A, bookmarks, drill-through) with actual security controls, leading them to select options that enhance user experience rather than protect data.

423
Drag & Dropmedium

Drag and drop the steps to build a model-driven app in Power Apps in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Model-driven apps require first setting up Dataverse tables, then designing forms/views, then building the app with sitemap, and finally publishing with security roles.

424
MCQmedium

A retail chain uses Power BI to analyze sales data from multiple stores. The data is stored in an Azure SQL Database. The company wants to give store managers access to a dashboard that shows their store's sales compared to the company average. However, store managers should not see other stores' data. The company also wants to automate the process of sending a weekly sales report to regional managers via email. The regional managers need to see aggregated data for their region. You need to implement a solution using Power Platform components. What should you do?

A.Create a Power Automate flow that runs a SQL query and sends the results via email, and give store managers access to the Azure SQL Database directly.
B.Create separate Power BI dashboards for each store and each region, and manually share them.
C.Create a Power BI dataset with RLS to filter by store, publish a dashboard, and use a scheduled Power Automate flow to email a paginated report to regional managers.
D.Use Power Apps to build a custom dashboard for each store, and use Power Automate to email reports.
AnswerC

Row-level security on the dataset filters each store manager to their own store's rows, while the scheduled Power Automate flow delivers a paginated report containing regional aggregates to regional managers. This satisfies both the per-store isolation and automated regional email requirements.

Why this answer

It uses Power BI Row-Level Security (RLS) to restrict store managers to only their store's data while allowing regional managers to see aggregated data via a paginated report. The scheduled Power Automate flow automates the weekly email delivery, meeting both security and automation requirements without manual intervention.

Exam trap

The trap here is that candidates often confuse Power BI dashboards with paginated reports, assuming a standard dashboard can be emailed directly, but Power BI requires a paginated report or a subscription feature for scheduled email delivery, and RLS is the only secure way to enforce per-store data isolation without duplicating datasets.

How to eliminate wrong answers

Option A is wrong because giving store managers direct access to the Azure SQL Database bypasses Power BI's RLS and exposes all stores' data, violating the requirement to restrict visibility. Option B is wrong because manually creating and sharing separate dashboards for each store and region is not scalable and fails to automate the weekly email report to regional managers. Option D is wrong because Power Apps custom dashboards are not designed for ad-hoc data exploration and aggregation like Power BI, and the solution does not address the need for a dashboard that compares store sales to company averages.

425
MCQmedium

A Power Platform administrator needs to delegate the ability to create and manage environments to a specific user without granting full Power Platform administrator privileges. The administrator wants to follow the principle of least privilege. What should the administrator do?

A.Assign the Environment Admin role for the environments and the Environment Creator role at the tenant level.
B.Assign the Environment Admin role for each environment the user should manage.
C.Assign the Power Platform Administrator role to the user in Microsoft Entra ID.
D.Assign the Environment Creator role in the Power Platform admin center.
AnswerA

Combining the Environment Creator role at the tenant level with Environment Admin roles for specific environments allows the user to create new environments and manage the ones they are responsible for. This follows least privilege because the user does not receive full Power Platform Administrator rights but can still perform the required tasks.

Why this answer

To delegate environment creation and management without full admin rights, the administrator should assign the Environment Creator role at the tenant level and Environment Admin roles for the specific environments. This combination provides the necessary permissions while adhering to least privilege, as the user cannot manage unrelated environments or tenant-wide policies.

Exam trap

The trap here is assuming that a single role can grant both environment creation and management; in reality, these are separate permissions that must be combined.

426
MCQhard

A company wants to use Power Apps to create a mobile app for field technicians. The app must work offline and sync data when connectivity is restored. Which feature should they use?

A.Offline capability in Dataverse (mobile offline sync)
B.Power Apps portals
C.Power Apps component framework
D.Monitor tool in Power Apps
AnswerA

Dataverse mobile offline sync replicates rows to the technician's device using offline profiles, letting the app read and write locally without connectivity. Once the network returns, queued changes synchronise back to Dataverse, resolving conflicts automatically. This directly satisfies the stem's requirement for offline operation with later data synchronisation.

Why this answer

Dataverse mobile offline sync is the built-in Power Apps capability that lets canvas and model-driven apps download a filtered subset of Dataverse tables to the device, so field technicians can read and write data without connectivity. When the device reconnects, queued changes are synchronized back to Dataverse automatically, resolving conflicts server-side. This directly satisfies the offline-first requirement without custom code.

Exam trap

PL-900 often tests the misconception that any Power Apps feature can work offline; candidates must recognize that only Dataverse mobile offline sync provides true offline data access, while portals, PCF, and Monitor are unrelated capabilities.

How to eliminate wrong answers

Option B is wrong because Power Apps portals are external-facing websites that render live Dataverse data in a browser and require continuous connectivity — they have no offline mode. Option C is wrong because the Power Apps component framework is a pro-dev extensibility model for building custom UI controls (code components), not a data-sync or offline feature. Option D is wrong because Monitor is a diagnostic/tracing tool for inspecting app events, network calls, and performance at runtime; it does not provide offline storage or synchronization.

427
MCQmedium

A company uses Power Apps to manage customer service cases. They want to implement a business rule that automatically sets the priority to 'High' when the customer is a VIP. Where should the business rule be defined?

A.In the SharePoint list settings
B.In a Power Automate flow
C.In the Dataverse table's business rules settings
D.In the canvas app's OnStart property
AnswerC

Dataverse table business rules run server-side whenever a record is created or updated, so the priority field is set to High automatically regardless of which app or form edits the case. This satisfies the requirement for consistent enforcement across all client interfaces.

Why this answer

Business rules in Power Apps that target Dataverse tables are defined in the table's Business Rules settings within the Power Apps maker portal. These rules run server-side on Dataverse, apply across all apps (canvas, model-driven, Power Pages), and can set field values, show errors, or lock fields without requiring code. This is the correct location for a rule that automatically sets Priority to 'High' for VIP customers.

Exam trap

PL-900 often tests confusion between Dataverse business rules and Power Automate flows, causing candidates to pick the flow option when the question asks for a declarative, table-level rule.

How to eliminate wrong answers

Option A is wrong because SharePoint list settings only govern SharePoint-native validation and workflows, not Dataverse tables used by Power Apps. Option B is wrong because Power Automate flows are event-driven automations, not declarative business rules; they can set fields but are not the 'business rule' feature and may run asynchronously. Option D is wrong because the canvas app's OnStart property runs once when the app loads and cannot enforce per-record logic like setting priority based on customer type.

428
MCQeasy

You are reviewing a Power Automate flow that uses an Office 365 Users connector. The exhibit shows a JSON definition of an action. What does this action do?

A.Updates the profile of the user who triggered the flow.
B.Deletes the user profile of the record owner.
C.Creates a new user profile in Office 365.
D.Retrieves the user profile of the record owner.
AnswerD

The Office 365 Users connector's action returns profile data for a specified user, and the JSON binds the record owner's identifier as its input. This satisfies the stem's requirement to resolve the owner's profile rather than the current user's.

Why this answer

The action uses the GetUserProfile operation with a User parameter taken from the trigger output. It retrieves the profile of the user who is the owner of the triggering record. Option A is incorrect because the action does not perform an update; it only retrieves data.

Option B is incorrect because the action does not delete a profile. Option C is incorrect because the action does not create a new profile. Therefore, option D is correct.

429
Multi-Selecteasy

Which TWO are types of apps you can create with Microsoft Power Apps?

Select 2 answers
A.Model-driven app
B.Copilot Studio bot
C.Canvas app
D.Flow app
E.Power BI report
AnswersA, C

Model-driven apps assemble components from Microsoft Dataverse, generating responsive UI automatically from the data model, relationships and business logic. This satisfies the stem's requirement for a Power Apps app type, alongside canvas apps, without requiring manual pixel-level screen design.

Why this answer

A model-driven app (A) is correct because Power Apps supports building model-driven apps that are component-focused and data-driven, based on the Common Data Service (now Microsoft Dataverse), where the UI is largely generated from the data model, relationships, and business logic. A canvas app (C) is also correct because Power Apps lets makers design canvas apps with a drag-and-drop designer, starting from a blank canvas or template, and bind controls to data sources using Power Fx formulas. Copilot Studio bot (B) is not a Power Apps app type; it is a separate conversational AI authoring tool for building copilots/bots.

Flow app (D) is not a Power Apps app type; automation flows are built in Power Automate, not Power Apps. Power BI report (E) is not a Power Apps app type; reports and dashboards are created in Power BI.

Exam trap

PL-900 often tests the confusion between Power Platform products — candidates mix up Power Apps (canvas/model-driven), Power Automate (flows), Copilot Studio (bots), and Power BI (reports), picking a non-Power-Apps artifact as an app type.

430
MCQeasy

A retail company wants to build a copilot that greets customers on its public website and answers common questions about store hours and return policies. The company has no developers available and wants to launch the copilot within a week. Which Microsoft Copilot Studio capability allows a business user to create this copilot without writing code?

A.Write a custom connector that calls an external REST API to retrieve store information.
B.Use the graphical authoring canvas to add topics with trigger phrases and message nodes.
C.Deploy a Power Apps canvas app that displays a static list of return policies.
D.Create a Power Automate cloud flow that sends an email to customers with store hours.
AnswerB

The graphical authoring canvas in Microsoft Copilot Studio lets makers define conversation topics, trigger phrases, and message responses using a visual designer. This directly satisfies the scenario because no code is required and a business user can publish the copilot quickly. Store hours and return policies can be handled with simple message nodes and trigger phrases, making this the most appropriate capability.

Why this answer

Microsoft Copilot Studio provides a no-code graphical authoring canvas where makers create topics, define trigger phrases, and add message nodes to build conversational experiences. For a public website copilot answering common questions, this is the fastest and most appropriate approach. The other options involve development work, background automation, or app interfaces that do not deliver a conversational copilot.

Exam trap

The trap here is assuming that any no-code Power Platform tool can build a copilot, when only Copilot Studio provides the conversational authoring canvas needed for a chat-based copilot.

431
MCQmedium

A Power Automate flow uses the 'HTTP' action to call an external API. The flow fails intermittently with a 429 (Too Many Requests) error. What is the best practice to handle this?

A.Switch to a different API endpoint
B.Add a 'Terminate' action to stop the flow on error
C.Configure retry policy with exponential backoff
D.Reduce the timeout of the HTTP action
AnswerC

A 429 signals the API throttled the flow, so retries must space out over time. Exponential backoff increases the delay between successive attempts, letting the service recover and preventing repeated throttling, which satisfies the intermittent-failure constraint without manual intervention.

Why this answer

The 429 error indicates the API is rate-limiting requests. Configuring a retry policy with exponential backoff allows the flow to automatically retry after increasing delays, reducing server load and respecting the API's rate limits. This is the standard best practice for handling transient throttling errors in Power Automate.

Exam trap

PL-900 often tests the misconception that any error should be handled by stopping the flow or changing the endpoint, rather than implementing resilient retry logic for transient issues like throttling.

How to eliminate wrong answers

Option A is wrong because switching endpoints does not address the rate-limiting issue and may introduce other problems. Option B is wrong because terminating the flow on error stops execution without attempting recovery, which is not a best practice for transient errors. Option D is wrong because reducing the timeout does not prevent rate limiting and may cause premature failures.

432
MCQhard

A company's copilot in Microsoft Copilot Studio answers HR questions from a SharePoint knowledge source. Users report that answers are sometimes wrong or outdated even though the SharePoint pages were recently edited. The copilot uses generative answers. What should you do first to improve answer accuracy?

A.Change the copilot's authentication setting to require sign-in for all users.
B.Switch the copilot to use only authored topics for all HR questions.
C.Increase the number of trigger phrases on each HR topic.
D.Verify that the SharePoint knowledge source is configured with the correct site and that content has been reindexed or refreshed.
AnswerD

When answers are wrong or stale despite page edits, the first check is whether the correct site is connected and whether the knowledge index reflects the latest content. Reindexing or refreshing the knowledge source ensures the copilot retrieves current pages, addressing the most likely cause before changing prompts or channels.

Why this answer

Stale or incorrect generative answers often trace to the knowledge source not reflecting recent changes. Confirming the correct SharePoint site is connected and refreshing or reindexing the content is the appropriate first step. Switching to authored topics, changing authentication, or adding trigger phrases does not address outdated knowledge retrieval.

Exam trap

The trap here is jumping to prompt or topic changes when the symptom of wrong answers after recent edits points to the knowledge index not being refreshed.

433
MCQmedium

A Power Apps canvas app uses a SharePoint list as its data source. Users report that the app is slow to load when the list contains over 10,000 items. What is the best approach to improve performance?

A.Increase the data row limit in the app settings.
B.Switch to a Microsoft Dataverse data source.
C.Reduce the number of columns in the SharePoint list.
D.Use delegation-compatible functions and filters in the app.
AnswerD

SharePoint connectors cap non-delegable queries at 500 or 2000 records, so the app retrieves only a subset and processes the rest locally, causing slowness. Delegation-compatible functions and filters push filtering to SharePoint, satisfying the need to handle over 10,000 items efficiently.

Why this answer

Delegation allows queries to be processed on the data source side, reducing the amount of data transferred and improving performance. Option D is correct because delegation-compatible functions (e.g., Filter, LookUp) ensure only relevant data is retrieved. Option A is wrong because increasing the data row limit loads more data, worsening performance.

Option B is wrong because switching to Dataverse might help but is not the best approach—it requires migration and may not always be feasible. Option C is wrong because reducing columns only marginally reduces data size, but without delegation, performance issues persist due to large row counts.

434
MCQeasy

A small business wants to create a simple public-facing website to showcase their services and allow customers to book appointments. They have no existing IT infrastructure and want to use a low-code solution that integrates with Microsoft 365 for email notifications. They also need to manage appointment data without building a custom database. You recommend Power Pages. What is the most efficient way to set up the appointment booking feature?

A.Build a Power Automate portal that accepts form submissions and writes to a Dataverse table.
B.Use SharePoint lists to store appointments and embed the list in a Power Pages page using an iframe.
C.Use Excel Online as the backend and connect via Power Automate to create appointments from the portal.
D.Create a new Dataverse table for appointments, then use the Power Pages 'List and Form' template to allow users to view available slots and submit bookings.
AnswerD

Dataverse supplies the managed data store, removing the need to build a custom database, while the List and Form template renders available slots and captures bookings with minimal configuration. This satisfies the low-code, Microsoft 365-integrated requirement most efficiently.

Why this answer

Power Pages integrates natively with Dataverse, and the 'List and Form' template provides prebuilt components for displaying records and capturing submissions without custom code. Creating a Dataverse table for appointments and using the template gives a low-code, integrated booking experience with data stored in the platform's native data store. This satisfies the no-custom-database and Microsoft 365 integration requirements.

Exam trap

PL-900 often tests the misconception that SharePoint or Excel can serve as the backend for Power Pages — the supported and recommended backend is Dataverse.

How to eliminate wrong answers

Option A is wrong because Power Automate is a workflow engine, not a portal-building tool — it cannot host a public-facing booking page, and 'Power Automate portal' is not a product. Option B is wrong because embedding a SharePoint list via iframe is unsupported, breaks the Power Pages security model, and does not provide a proper booking form. Option C is wrong because Excel Online is not a supported backend for Power Pages forms and lacks the relational integrity and security needed for appointment data.

435
MCQmedium

A mid-sized logistics company wants to replace its manual, paper-based expense approval process with a digital workflow. The IT team wants to minimize custom development and leverage built-in connectors to services like Outlook, SharePoint, and Dynamics 365. Which Power Platform component should they use to automate the approval process?

A.Power BI
B.Power Automate
C.Power Apps
D.Power Virtual Agents
AnswerB

Power Automate is designed to create automated workflows between services using connectors. It can trigger on events like a new file in SharePoint or an email in Outlook, and then route approval requests, send notifications, and update records. This directly addresses the need to replace manual approvals with a digital, connector-based process without custom code.

Why this answer

Power Automate is the service within the Microsoft Power Platform specifically built for automating workflows across applications and services. It provides hundreds of connectors, including Outlook, SharePoint, and Dynamics 365, enabling the logistics company to digitize the expense approval process without writing code. The other components serve different purposes: Power Apps for app development, Power BI for analytics, and Power Virtual Agents for chatbots.

Exam trap

The trap here is confusing the roles of Power Apps and Power Automate, assuming that building an app is necessary for any process automation.

436
MCQeasy

A company wants to build an app that allows employees to submit expense reports. The app must include approval workflow. Which Power Platform component should be used to define the approval process?

A.Power Virtual Agents
B.Power Apps
C.Power Automate
D.Power BI
AnswerC

Power Automate provides approval actions with configurable approvers, outcomes and notifications, and canvas apps can trigger these flows. It satisfies the stem's requirement to define the expense report approval process, which Power Apps alone cannot orchestrate.

Why this answer

Power Automate is the Power Platform component specifically designed for workflow automation and approvals. It provides built-in approval actions and templates that allow you to define multi-step approval processes, send approval requests, and track responses. Power Apps is for building the user interface, Power BI for analytics, and Power Virtual Agents for chatbots, none of which natively handle approval workflows.

Exam trap

PL-900 often tests the distinction between Power Platform components, and candidates may confuse Power Apps (for building apps) with Power Automate (for automation). The trap is thinking that because the app includes an approval workflow, Power Apps alone can handle it, but Power Apps requires Power Automate for backend logic.

How to eliminate wrong answers

Option A is wrong because Power Virtual Agents is used to create conversational chatbots, not to define approval processes. Option B is wrong because Power Apps is a low-code app development service for building user interfaces, not for orchestrating workflows. Option D is wrong because Power BI is a business analytics service for visualizing data, not for implementing approval logic.

437
MCQmedium

You are building a Microsoft Copilot Studio copilot for a facilities team. Employees must be able to start a conversation by typing 'book a meeting room' or by clicking a button labeled 'Room booking' inside Microsoft Teams. You need the copilot to present the 'Room booking' button automatically when the conversation opens. What should you configure?

A.Publish the copilot and configure a Power Automate cloud flow that posts an adaptive card to the user when the session starts.
B.Add a Suggested Action in the Conversation Start topic that displays the 'Room booking' button.
C.Create an entity named 'Room booking' and bind it to the Conversation Start topic as a required input.
D.Add 'book a meeting room' as a trigger phrase to the Room booking topic and enable the 'Show in Teams' channel option.
AnswerB

The Conversation Start topic runs automatically when a session begins, so placing a Suggested Action there surfaces the 'Room booking' button to every user immediately. Suggested Actions render as clickable buttons that map to a topic trigger phrase, letting employees bypass typing and still reach the same booking topic. This satisfies the requirement that the button appear on conversation open without altering the topic's trigger phrases or authentication settings.

Why this answer

The Conversation Start topic is the system topic that fires at the beginning of every session, making it the correct place to present entry-point buttons. A Suggested Action added there renders clickable buttons tied to topic trigger phrases, so employees can either type 'book a meeting room' or click 'Room booking'. Trigger phrases, entities, and external flows do not produce an automatic button in the chat canvas.

Exam trap

The trap here is assuming that adding trigger phrases or enabling a channel makes a button appear, when only Suggested Actions in the Conversation Start topic render clickable buttons automatically.

438
MCQmedium

A Power Automate cloud flow is configured to use the 'When a file is created (properties only)' trigger for a SharePoint document library. The flow needs to retrieve the file content and send it as an email attachment. Which action should be used to get the file content?

A.Get file properties
B.Get item
C.Get file content
D.Get file metadata
AnswerC

The 'Get file content' action in the SharePoint connector retrieves the binary content of a file using its identifier. It is specifically designed to fetch file content for further processing, such as attaching to an email. This action is the correct choice to obtain the file for email attachment.

Why this answer

To attach a file from SharePoint to an email, the flow must retrieve the file's binary content. The 'Get file content' action does exactly that, using the file identifier from the trigger. Other actions only provide metadata or are for list items, not file content.

Therefore, 'Get file content' is the correct action.

Exam trap

The trap here is confusing actions that return metadata with those that return actual file content. 'Get file metadata' and 'Get file properties' sound similar but do not provide the binary data.

439
Multi-Selectmedium

A company wants to enforce data loss prevention (DLP) policies for Power Automate flows. Which TWO actions can the administrator perform?

Select 2 answers
A.Allow users to bypass DLP policies with administrator approval
B.Block specific connectors from being used in flows
C.Create a custom DLP policy for a specific environment
D.Assign DLP policies to specific users
E.Inherit the tenant-level DLP policy for all environments
AnswersB, C

Blocking connectors is a common DLP action.

Why this answer

Administrators can block specific connectors from being used in Power Automate flows as part of a DLP policy, preventing data from being shared with unauthorized services. Option C is correct because DLP policies can be scoped to a specific environment, allowing granular control over connector usage within that environment. This enables the administrator to enforce data protection rules tailored to different business contexts.

Exam trap

The trap here is that candidates often confuse environment-level DLP policy assignment with user-level assignment, or assume that tenant-level policies are automatically inherited by all environments, when in fact each environment can have its own independent DLP policy.

440
MCQmedium

An organization uses Microsoft Power Platform and wants to enforce data loss prevention (DLP) policies across all environments. They need to block the use of a specific third-party connector in all environments. What should the administrator do?

A.Create a DLP policy for each environment and block the connector
B.Create a custom connector with the same name and block it
C.Remove the connector from the default solution
D.Create a tenant-level DLP policy that blocks the connector
AnswerD

A tenant-level DLP policy applies across every environment within the tenant, so blocking the third-party connector there satisfies the requirement to restrict it everywhere. Environment-scoped policies would only cover individual environments, leaving others unprotected. Tenant-wide scope is the mechanism that enforces the block universally.

Why this answer

DLP policies in Microsoft Power Platform can be configured at the tenant level to apply across all environments. By creating a tenant-level DLP policy and blocking the specific third-party connector, the administrator ensures consistent enforcement without needing to manage individual environment policies. This approach centralizes control and prevents the connector from being used in any environment.

Exam trap

The trap here is that candidates often assume DLP policies must be created per environment, overlooking the tenant-level scope that provides centralized enforcement across all environments.

How to eliminate wrong answers

Option A is wrong because creating a DLP policy for each environment is inefficient and error-prone; it requires manual replication across environments and does not guarantee uniform enforcement if environments are added or missed. Option B is wrong because creating a custom connector with the same name does not block the original third-party connector; custom connectors are separate entities and blocking a custom connector does not affect the built-in or certified connector. Option C is wrong because removing a connector from the default solution does not block its use; connectors are not managed through solutions in that way, and removal from a solution only affects solution components, not connector availability in environments.

441
Matchingmedium

Match each Microsoft Power Platform component to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Build custom apps with low code

Automate workflows and processes

Visualize and analyze data

Create AI-powered chatbots

Build external-facing websites

Why these pairings

Power Apps builds custom apps, Power Automate automates workflows, Power BI analyzes data, and Power Virtual Agents creates chatbots. Common confusions include swapping these definitions.

442
MCQeasy

A business analyst wants to build an app quickly using a pre-built template. Which Power Apps capability should they use?

A.Create a Model-driven app from a Dataverse table
B.Use Power Automate to generate the app
C.Use a Power Apps template from the template gallery
D.Create a Canvas app from blank
AnswerC

The template gallery provides pre-built apps with predefined screens, data connections and layouts, letting the analyst start from an existing design. This satisfies the stem's requirement to build an app quickly using a pre-built template.

Why this answer

Power Apps offers templates for common scenarios. Canvas apps from blank require more effort. Model-driven apps are not template-based.

Power Automate is for workflows.

443
Drag & Dropmedium

Drag and drop the steps to configure a Power Virtual Agents chatbot in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for configuring a Power Virtual Agents chatbot is: first create the bot, then define topics to handle user intents, add nodes to each topic to define the conversation flow, test the bot in the test pane to verify behavior, and finally publish the bot to make it available to users. Publishing before testing risks deploying unresolved issues.

444
MCQmedium

A manufacturing company wants to give shop-floor supervisors a way to report equipment issues from a tablet. Supervisors are not programmers, and the company wants the solution to use a governed data service with role-based security so that only authorized staff can view sensitive maintenance records. Which Power Platform component should the company use to build the issue-reporting app?

A.Power Apps
B.Power Pages
C.Power BI
D.Power Automate
AnswerA

Power Apps is the Power Platform service for building canvas and model-driven applications with a low-code designer. It supports tablet layouts, connects to Dataverse for governed storage with role-based security, and lets non-programmers create the issue-reporting experience. This matches the requirement for an internal app built by business users against a secured data service.

Why this answer

Power Apps is the appropriate component because it provides a low-code app designer for tablet-friendly interfaces and integrates with Dataverse, which supplies governed storage and role-based security. Supervisors can report issues through the app, and authorized staff can be granted access through security roles. Power BI, Power Pages, and Power Automate serve analytics, external websites, and automation respectively, not internal app creation.

Exam trap

The trap here is selecting Power Pages for an internal tablet app because it also supports forms, when Power Pages is intended for external-facing websites and Power Apps is the internal app builder.

445
Multi-Selectmedium

Which TWO actions can be used to implement error handling in a Power Automate flow?

Select 2 answers
A.Use a Scope action to group actions and configure error handling
B.Add a Condition action to check for errors
C.Use a Compose action to store error details
D.Configure Run After settings
E.Add an Apply to Each action
AnswersA, D

A Scope action groups actions into a block, and its 'Configure run after' settings let subsequent actions run on failure or timeout, enabling structured error handling. This satisfies the requirement for implementing error handling within a Power Automate flow.

Why this answer

Option A is correct because the Scope action groups a set of actions into a single block, and its Run After settings can be configured so that a subsequent action (such as a Terminate or a notification) runs only when the Scope fails, times out, or is skipped, which is the standard pattern for try/catch-style error handling in Power Automate. Option D is correct because Run After settings define the dependency and outcome conditions (is successful, has failed, is skipped, has timed out) under which an action executes, and configuring an action to run after a previous action 'has failed' is the core mechanism for branching into error-handling logic. Option B is not the intended answer because a Condition action only evaluates data expressions at runtime and cannot by itself detect whether a prior action failed; failure detection is driven by Run After, not by Condition.

Option C is not the intended answer because Compose merely outputs a value or expression for later use and does not provide any error-detection or error-handling behavior. Option E is not the intended answer because Apply to Each is a looping construct for iterating over arrays and does not implement error handling.

Exam trap

PL-900 often tests the misconception that Condition or Compose actions handle errors — candidates overlook that Run After settings and Scope actions are the actual error-handling constructs.

446
Multi-Selecthard

A company is building a customer-facing copilot in Microsoft Copilot Studio. The copilot must escalate unresolved conversations to a live agent in Microsoft Dynamics 365 Customer Service and must gather the customer's email address before escalation. Which TWO Copilot Studio features should the maker configure to meet these requirements? (Choose two.)

Select 2 answers
A.Use a handoff node or the transfer-to-agent capability to route the conversation to Dynamics 365 Customer Service.
B.Create a knowledge source from the company's public FAQ page.
C.Enable the copilot's sentiment analysis to detect frustration and auto-close the conversation.
D.Publish the copilot to the Microsoft 365 Copilot channel only.
E.Add a question node that stores the customer's response in a variable for the email address.
AnswersA, E

Copilot Studio supports handing off a conversation to a live agent through engagement hub integration, including Dynamics 365 Customer Service. Configuring the handoff routes the full conversation context to the agent. This directly satisfies the requirement to escalate unresolved conversations, and it works alongside question nodes that collect user details before transfer.

Why this answer

Meeting the requirements needs two distinct capabilities: a handoff mechanism that routes the conversation to a live agent in Dynamics 365 Customer Service, and a question node that captures and stores the customer's email in a variable. Together they ensure unresolved chats reach an agent with the email already collected. Sentiment analysis, channel publishing, and FAQ knowledge sources do not provide escalation or email capture.

Exam trap

The trap here is conflating conversation-quality features like sentiment analysis or knowledge sources with the actual handoff and data-collection mechanisms required for live-agent escalation.

447
Multi-Selectmedium

A Power Platform administrator is configuring a new environment for a team that will use both Power Apps and Power Automate. The administrator needs to ensure that the team can only use a specific set of connectors and that data cannot be shared between certain connectors. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Configure the environment's security group to include only the team members who need access.
B.Use the Power Platform admin center to set the environment's region to a specific geography.
C.Apply the DLP policy to the environment so that it enforces the connector restrictions for all apps and flows within it.
D.Create a data loss prevention (DLP) policy that defines connector groups and blocks connectors from different groups from being used together.
E.Assign the Environment Maker security role to all team members.
AnswersC, D

After creating a DLP policy, you must apply it to the specific environment to enforce the connector groupings and restrictions. Applying the policy ensures that the rules are active for all apps and flows in that environment, thereby preventing data sharing between the defined connector groups as required.

Why this answer

To restrict connector usage and prevent data sharing between certain connectors, the administrator must create a DLP policy that defines connector groups and blocks cross-group usage, and then apply that policy to the environment. These two actions together enforce the desired governance. Other actions, such as assigning roles or setting region, do not address connector-level restrictions or data flow control.

Exam trap

The trap here is thinking that assigning security roles or setting region can control connector usage, when only DLP policies applied to the environment govern which connectors can be used together.

448
MCQmedium

A Power Pages site has a page that displays a chart summarizing sales data. The chart is built using a Dataverse view. The sales data changes frequently. What must be configured to ensure the chart updates automatically?

A.No additional configuration is needed; the chart updates automatically
B.Set the chart's cache duration to 0 in the site settings
C.Schedule a Power Automate flow to refresh the chart every hour
D.Configure the chart to use a real-time data stream via Power Automate
AnswerA

Charts bound to Dataverse views render live data on each page load, so no caching or refresh configuration is required. Because the underlying view queries Dataverse directly, frequent sales changes appear automatically whenever the page is requested.

Why this answer

Power Pages charts built from Dataverse views are rendered dynamically at page load and reflect the current data in the underlying view — no caching layer or scheduled refresh is required. Because the chart queries Dataverse each time the page is rendered, changes to sales data appear automatically on the next page load without any additional configuration.

Exam trap

PL-900 often tests whether candidates over-engineer solutions — the trap is assuming that 'frequently changing data' requires a scheduled refresh or streaming integration, when in fact Power Pages charts query Dataverse on every page load and need no extra configuration.

How to eliminate wrong answers

Option B is wrong because there is no 'chart cache duration' site setting in Power Pages — charts are not cached in a way that requires manual invalidation. Option C is wrong because Power Automate cannot 'refresh' a client-side chart; the chart re-queries Dataverse on each render, so a scheduled flow is unnecessary and would not affect chart display. Option D is wrong because Power Pages charts do not use a real-time streaming model via Power Automate — they use standard Dataverse view queries rendered server-side/client-side at page load.

449
MCQhard

Refer to the exhibit. The JSON describes a Power Apps function. What is the correct usage of this function to return a date 7 days from today?

A.AddDays(7; Today())
B.AddDays(Today(), 7)
C.AddDays(7, Today())
D.AddDays('7', Today())
AnswerB

AddDays accepts a date and a number of days, returning that date offset forward. Passing Today() with 7 yields the date one week from now, matching the stem's requirement exactly; the function's argument order is date first, increment second.

Why this answer

The AddDays function in Power Apps (Power Fx) uses the syntax AddDays(DateTime, NumberOfDays). So AddDays(Today(), 7) returns the date 7 days from today. Option A uses a semicolon and has the arguments reversed.

Option C also reverses the arguments (days first, then date). Option D uses a string for the number of days, which is invalid.

450
MCQhard

Refer to the exhibit. A Power Pages site has a web role called 'Partner' with permissions to read the Proposal table and read/write the Invoice table. A user assigned the Partner role attempts to create a new record in the Proposal table. What will happen?

A.The user is denied access because the Partner role does not exist
B.The user is allowed to create the record because the Partner role implicitly includes Write on all tables
C.The user is denied access because the Partner role has only Read permission on the Proposal table
D.The user is allowed to create the record because Write permission is granted on the Invoice table
AnswerC

Web role permissions are additive per table, and the Partner role grants only Read on Proposal. Creating a record requires the Create privilege, which the role does not hold, so Dataverse rejects the insert regardless of the user's other roles.

Why this answer

In Power Pages, web roles grant table permissions that are explicit and granular. The Partner role has only Read permission on the Proposal table, so a user with that role cannot create (Write) a new Proposal record. Power Pages enforces table-level CRUD permissions, and lacking Write on Proposal results in access denial for the create operation.

Exam trap

The trap is assuming permissions are global or inherited across tables — candidates may think Write on one table grants Write elsewhere, but Power Pages table permissions are strictly per-table and per-operation.

How to eliminate wrong answers

Option A is wrong because the scenario states the Partner role exists and is assigned to the user, so the denial is not due to a missing role. Option B is wrong because web roles do not implicitly grant Write on all tables — permissions must be explicitly configured per table, and no implicit global Write exists. Option D is wrong because permissions are scoped per table; having Write on the Invoice table does not grant any permission on the Proposal table, so the user cannot create a Proposal record.

Page 5

Page 6 of 10

Page 7

All pages