Courseiva

Microsoft Power Platform Fundamentals PL-900 (PL-900) — Questions 451–525

701 questions total · 10pages · All types, answers revealed

Page 6

Page 7 of 10

Page 8
451
MCQeasy

You need to create a flow that sends a push notification to a user's mobile device when a high-priority email arrives in their inbox. Which trigger and action combination should you use?

A.When an item is created trigger and Post message action
B.When a new email arrives trigger and Send push notification action
C.When an approval request is triggered and Send email action
D.Recurrence trigger and Send email action
AnswerB

The 'When a new email arrives' trigger fires on inbox events and exposes priority, enabling a condition on high priority. The 'Send push notification' action then delivers the alert to the user's mobile device, matching both the trigger and delivery requirements.

Why this answer

The 'When a new email arrives' trigger is designed to monitor an inbox for incoming messages, and the 'Send push notification' action sends a notification directly to a mobile device via the Power Automate mobile app or Microsoft Teams. This combination directly fulfills the requirement to react to a high-priority email and deliver a push notification to the user's device.

Exam trap

The trap here is that candidates often confuse 'Send push notification' with 'Send email' or 'Post message', not realizing that push notifications are device-specific and require the Power Automate mobile app, while email actions send traditional email messages.

How to eliminate wrong answers

Option A is wrong because the 'When an item is created' trigger is specific to a data source like SharePoint or Dataverse, not an email inbox, and the 'Post message' action sends a message to a channel or chat, not a push notification to a mobile device. Option C is wrong because the 'When an approval request is triggered' trigger waits for an approval action, not an incoming email, and the 'Send email' action sends an email, not a push notification. Option D is wrong because the 'Recurrence' trigger runs on a schedule, not in response to an email event, and the 'Send email' action sends an email, not a push notification.

452
MCQeasy

An organization needs a Power App that allows employees to submit expense reports by filling out a form and attaching receipts. Which type of app should you create and why?

A.Canvas app, because it provides flexible form design and supports file attachments
B.Model-driven app, because it uses standard Dataverse forms
C.AI Builder app, because it can process receipts automatically
D.Power Apps portal, because it allows external users to submit expenses
AnswerA

Canvas apps provide pixel-level control over form layout and include the Attachments control, letting employees attach receipt files to the submitted expense report. This satisfies both the flexible form design and file attachment requirements, which model-driven forms handle less flexibly.

Why this answer

A canvas app is correct because it gives the maker full control over the layout and controls, allowing a custom form with a file attachment control (e.g., the Attachments control or the Add Picture control) bound to a data source like SharePoint or Dataverse. Canvas apps are ideal for task-specific, form-based scenarios where the UI must be tailored to the user's needs, such as submitting expense reports with receipts. Model-driven apps use standard forms that are less flexible for custom attachment handling, and AI Builder is an add-on capability, not an app type.

Power Apps portals are for external users, not employees.

Exam trap

PL-900 often tests the distinction between canvas and model-driven apps, and candidates may incorrectly assume that model-driven apps are always better because they are 'standard' or that AI Builder is a separate app type, when in fact AI Builder is a feature that can be integrated into either app type.

How to eliminate wrong answers

Option B is wrong because model-driven apps generate forms from Dataverse tables and do not provide the same level of UI flexibility for custom attachment controls; they are better for complex business processes with relationships, not simple form submissions. Option C is wrong because AI Builder is a component that can be added to a canvas or model-driven app to process receipts, but it is not an app type itself; the question asks for the type of app to create. Option D is wrong because Power Apps portals are designed for external users (e.g., customers, partners) to access data, not for internal employees submitting expense reports; employees would typically use an internal app.

453
Multi-Selecthard

Which THREE components are part of the Power Platform environment lifecycle management?

Select 3 answers
A.Environment creation
B.Environment deletion
C.Creating users in Microsoft Entra ID
D.Environment backup and restore
E.Publishing Power BI reports
AnswersA, B, D

Creating environments is a key lifecycle operation.

Why this answer

Environment creation is a core component of Power Platform environment lifecycle management because it establishes the isolated container where apps, flows, and data reside. The lifecycle begins when an administrator provisions a new environment, which sets up a dedicated Dataverse database, security boundaries, and resource limits. Without creation, no subsequent lifecycle operations (backup, restore, deletion) can occur.

Exam trap

The trap here is that candidates confuse operational tasks (like creating users or publishing reports) with environment lifecycle management, which strictly covers the creation, deletion, backup, and restore of the environment itself, not activities that occur within it.

454
MCQeasy

A Power Pages site needs to display a map showing the locations of company offices stored in Dataverse. Which component should be used to embed the map?

A.A custom JavaScript component using a mapping API
B.A Power Automate flow that generates an image
C.A Power Virtual Agents chatbot
D.A Power BI report embedded in the page
AnswerA

Power Pages supports embedding custom code, so a JavaScript component calling a mapping API renders the office locations dynamically. Dataverse stores the coordinates, and the script satisfies the requirement to display an interactive map rather than a static list.

Why this answer

Power Pages allows embedding custom JavaScript and integrating with external mapping APIs (such as Azure Maps, Google Maps, or Bing Maps) to render dynamic maps. Since the office locations are stored in Dataverse, a custom JavaScript component can query Dataverse via the Power Pages Web API and pass the coordinates to the mapping API to display markers.

Exam trap

PL-900 often tests whether candidates understand that Power Pages supports custom code for specialized UI needs — the trap is assuming a Power BI report or Power Automate flow is the right tool for embedding a map, when custom JavaScript is the correct extensibility path.

How to eliminate wrong answers

Option B is wrong because Power Automate flows can generate images but are not designed to render interactive maps on a web page in real time. Option C is wrong because Power Virtual Agents is a chatbot platform and has no mapping capability. Option D is wrong because a Power BI report can include map visuals, but embedding it in Power Pages is a heavier, less flexible approach and is not the intended component for a simple map display of Dataverse records.

455
MCQhard

A financial services firm wants to ensure that its Power Platform solutions comply with industry regulations. They need to monitor which users are creating apps, enforce data loss prevention policies, and manage environments. Which Power Platform capability should they use?

A.Power BI
B.Power Platform admin center
C.Power Apps
D.Power Automate
AnswerB

The Power Platform admin center provides a unified portal for administrators to manage environments, view analytics, set data loss prevention (DLP) policies, and monitor user activities. It allows the firm to enforce compliance, govern app creation, and manage the lifecycle of Power Platform resources, directly addressing the regulatory requirements.

Why this answer

The Power Platform admin center is the dedicated administrative portal for managing Power Platform environments, setting data loss prevention policies, and monitoring usage. It provides the governance and compliance features necessary for the financial services firm to meet regulatory requirements. The other components are for building solutions, not for administration.

Exam trap

The trap here is assuming that any Power Platform component can be used for administration, overlooking the specialized admin center.

456
MCQhard

A Power Pages site is experiencing slow load times for a page that displays a list of products from a Dataverse table. The page uses a Liquid template with a fetch query that retrieves all products without filtering. Which change would most improve performance?

A.Enable the content delivery network (CDN) for the site.
B.Adjust the page caching settings in the Power Pages admin center.
C.Replace the Liquid template with the out-of-the-box list component.
D.Modify the fetch query in the Liquid template to include a filter, such as only active products.
AnswerD

Adding a filter to the fetch query reduces the number of rows Dataverse returns and Liquid renders, cutting server-side processing and payload size. This directly addresses the unfiltered retrieval causing slow load times for the product list.

Why this answer

The Liquid template's fetch query retrieves all products from Dataverse without filtering, which means the server must query and render the entire table on every page load. Adding a filter such as 'only active products' reduces the result set returned by Dataverse, cutting query execution time and the amount of data transferred and rendered. This directly addresses the root cause of the slow load time — an inefficient, unbounded data retrieval — rather than masking it with caching or CDN.

Exam trap

The trap is reaching for infrastructure-level fixes (CDN, caching) when the question explicitly describes an inefficient query — candidates must identify that the root cause is the unfiltered fetch, not delivery or caching.

How to eliminate wrong answers

Option A is wrong because a CDN caches static assets at edge locations; it does not optimize dynamic Dataverse queries executed server-side by Liquid templates, so the slow query would still run on cache misses. Option B is wrong because page caching can reduce repeated load times but does not fix the underlying inefficient query — the first load and any cache invalidation would still be slow, and stale data risks are introduced. Option C is wrong because replacing Liquid with the out-of-the-box list component may improve rendering but does not guarantee the underlying query is filtered; the list component can still retrieve all records if not configured with a filter, so it does not address the root cause.

457
MCQmedium

A company has a canvas app that connects to a Microsoft Dataverse table containing sensitive customer information. The app is shared with a group of users, but the security team wants to ensure that users can only see records that they own and cannot modify records owned by others. The maker needs to implement record-level security. What should the maker do?

A.Set the app's sharing permissions to only allow users to run the app but not edit it.
B.Configure column-level security on the Dataverse table to hide sensitive fields.
C.Create a Dataverse security role that grants User-level read and write privileges on the table and assign it to the users.
D.Use the Filter function in the canvas app to show only records where the owner equals the current user.
AnswerC

Dataverse security roles define privileges at the table level with access scopes such as User, Business Unit, or Organization. Setting the read and write privileges to User scope means users can only access records they own. Assigning this role to the group enforces record-level security directly in Dataverse, which the canvas app respects because it uses the user's credentials. This is the correct way to restrict access to owned records.

Why this answer

Record-level security in Dataverse is enforced through security roles with access scopes. Assigning a role with User-level read and write privileges ensures users can only access records they own. This is enforced at the data layer and applies regardless of the app used.

Client-side filtering or app-sharing settings do not provide true security, and column-level security addresses a different requirement.

Exam trap

The trap here is thinking that filtering records in the app or restricting app editing permissions provides security, when actual record-level security must be enforced by Dataverse security roles.

458
MCQmedium

A multinational corporation uses Power Platform extensively. They have multiple environments: DEV, TEST, UAT, STAGING, and PROD. A developer accidentally published a Power App that connects to a SQL Server database using an unapproved connector in the PROD environment. The organization has strict data governance policies that require all connections to use approved connectors only. The admin needs to block this connector in PROD while still allowing it in other environments. What should the admin do?

A.Create a tenant-level DLP policy that blocks the connector for all environments.
B.Remove the developer's permissions to the PROD environment.
C.Delete the Power App from PROD.
D.Create an environment-level DLP policy for PROD that blocks the connector.
AnswerD

Environment-level DLP policies scope connector blocking to a single environment, so PROD can block the unapproved SQL connector while DEV, TEST, UAT and STAGING remain unaffected. Tenant-level policies would apply everywhere, failing the requirement to allow it elsewhere. This satisfies the stem's constraint of blocking in PROD only.

Why this answer

Environment-level DLP policies in Power Platform apply only to a specific environment, so creating one for PROD that blocks the unapproved connector restricts it there while leaving DEV, TEST, UAT, and STAGING unaffected. This precisely meets the requirement to block the connector only in PROD. Tenant-level policies would affect all environments, which is too broad.

Exam trap

The trap is defaulting to a tenant-level DLP policy because it's the most familiar control; candidates overlook that environment-level policies are required when governance must differ between PROD and non-PROD environments.

How to eliminate wrong answers

Option A is wrong because a tenant-level DLP policy applies across all environments, blocking the connector everywhere and violating the requirement to allow it in non-PROD environments. Option B is wrong because removing the developer's PROD permissions does not block the connector for other users and is a personnel control, not a data governance control. Option C is wrong because deleting the app removes the symptom but does not prevent the connector from being used again in PROD, and it destroys a business app rather than enforcing policy.

459
MCQmedium

Your organization uses Power Automate to automate the creation of support tickets in ServiceNow when a critical alert is triggered in Microsoft Sentinel. The flow uses the 'When a new alert is created' trigger from Sentinel. The flow runs but no tickets are created. You check the Sentinel log and see that alerts are being generated. What should you investigate first?

A.Verify that the flow is enabled.
B.Ensure that the Sentinel data connector is properly installed.
C.Review the trigger condition or filter query.
D.Check if the ServiceNow connector is configured with the correct instance.
AnswerC

The Sentinel trigger fires only when an alert matches its configured conditions. If a filter query or trigger condition excludes the generated alerts, the flow never starts, so no ServiceNow tickets appear despite alerts existing. Reviewing these settings first confirms whether the trigger is actually firing.

Why this answer

The flow runs successfully but produces no tickets, which means the trigger is firing but the condition inside the flow is filtering out the alerts. Since Sentinel confirms alerts are being generated, the most likely cause is that the trigger's condition or filter query (e.g., severity = High, or a specific analytics rule name) does not match the alerts being produced. Reviewing the trigger condition is the correct first step because it isolates whether the flow logic is excluding the alerts before the ServiceNow action ever executes.

Exam trap

PL-900 often tests the distinction between 'the flow runs but nothing happens' (trigger condition/filter problem) versus 'the flow fails' (connector or action problem) — candidates incorrectly jump to connector configuration when the flow is actually running.

How to eliminate wrong answers

Option A is wrong because the question states the flow runs, which means it is already enabled — a disabled flow would not execute at all. Option B is wrong because the Sentinel data connector is clearly working since alerts are being generated and visible in the Sentinel log. Option D is wrong because a misconfigured ServiceNow connector would cause the flow run to fail at the action step, not silently produce zero tickets while the flow itself runs successfully.

460
MCQeasy

A manufacturing company wants to give its shop-floor supervisors a way to report equipment issues from a tablet, with no coding. The solution must work on a touch screen and use a SharePoint list as the data source. Which Power Platform service should the company use?

A.Power Automate
B.Power BI
C.Power Apps
D.Power Virtual Agents
AnswerC

Power Apps is the low-code application development service in the Microsoft Power Platform. It provides a canvas app designer where makers can drag controls, connect directly to a SharePoint list, and publish a touch-friendly app to tablets. This directly satisfies the requirement of a no-code, touch-screen issue reporting solution backed by SharePoint data.

Why this answer

The requirement is a no-code app for tablet data entry, and Power Apps is the Power Platform service designed for building such apps. It connects natively to SharePoint lists and supports touch controls, letting supervisors submit equipment issues directly. The other services handle automation, analytics, or conversational bots, none of which provide the required form-based data capture experience.

Exam trap

The trap here is assuming that any Power Platform tool can collect structured data, when only Power Apps is built for creating a touch-friendly data entry app on SharePoint.

461
MCQmedium

A model-driven app includes a custom entity 'Project' with a lookup to 'Account'. Users need to see the account name and phone number on the Project form. What is the best way to display these fields?

A.Use a calculated field on the Project entity
B.Create a new main form for the Project entity
C.Add the account fields directly to the Project entity
D.Add a quick view form for the Account entity
AnswerD

A quick view form on the Project form surfaces read-only Account fields, such as name and phone number, from the related record via the lookup. This satisfies the requirement without duplicating data or altering the Account entity.

Why this answer

A quick view form on the Account entity allows users to see read-only account information (such as account name and phone number) directly on the Project form without duplicating data. When a lookup to Account is added to the Project form, the quick view form can be configured to display those fields, providing a seamless view of related data.

Exam trap

PL-900 often tests the misconception that related data should be duplicated onto the primary entity; candidates must recognize quick view forms as the correct way to display related fields.

How to eliminate wrong answers

Option A is wrong because a calculated field on the Project entity would compute a value based on other fields, but it cannot pull data from a related Account record. Option B is wrong because creating a new main form for the Project entity does not inherently display account fields; it would still require a quick view form or other mechanism. Option C is wrong because adding account fields directly to the Project entity would duplicate data and create synchronization issues, violating normalization best practices.

462
MCQmedium

A company uses Power Automate to send approval emails when a new employee is added to Microsoft Entra ID. The approval flow fails intermittently with a '403 Forbidden' error. What is the most likely cause?

A.The Microsoft Entra ID license has expired.
B.The flow is exceeding the API request throttle limit.
C.The connection used in the flow lacks appropriate permissions.
D.The Power Automate connector for Microsoft Entra ID is deprecated.
AnswerC

A 403 Forbidden response indicates the flow's connection is authenticated but not authorised, so the account behind the Microsoft Entra ID connection lacks the permissions the approval action requires. Granting the connection suitable rights resolves the intermittent failure.

Why this answer

A 403 Forbidden error in Power Automate typically indicates that the connection used by the flow does not have the necessary permissions to perform the action, such as reading from Microsoft Entra ID or sending approvals. The most likely cause is an insufficiently privileged connection or an expired credential.

Exam trap

The trap is assuming a 403 is a licensing or throttling issue; candidates must recognize that 403 specifically means 'authenticated but not authorized,' pointing to permissions.

How to eliminate wrong answers

Option A is wrong because an expired Microsoft Entra ID license would typically cause a licensing error or block user sign-in, not a 403 on a specific flow action. Option B is wrong because throttling returns HTTP 429 Too Many Requests, not 403 Forbidden. Option D is wrong because the Microsoft Entra ID connector is actively supported and not deprecated; deprecation would produce a different error.

463
MCQmedium

Refer to the exhibit. A Power BI report connecting to the SalesDB database is slow. The exhibit shows a SQL Server activity snapshot. What is the most likely cause of the performance issue?

A.The database server has insufficient memory
B.SPID 55 is blocked by SPID 54, causing delays
C.The SELECT query (SPID 55) is performing a table scan
D.The sleeping session (SPID 54) is using too much CPU
AnswerB

SPID 55 waits on a lock held by SPID 54, so its query stalls until the blocking transaction commits or rolls back. This blocking chain, visible in the activity snapshot, directly explains the slow Power BI report rather than CPU, memory or network pressure.

Why this answer

The exhibit shows SPID 55 (a SELECT query) in a 'suspended' state with a non-zero 'blocked_by' column value of 54, indicating it is waiting for a lock held by SPID 54. SPID 54 is in a 'sleeping' state but still holds locks, which blocks SPID 55 from proceeding. This blocking chain directly causes the report's slow performance, as the Power BI query cannot complete until the blocking session releases its locks.

Exam trap

The trap here is that candidates see SPID 54 as 'sleeping' and assume it is idle and harmless, missing that it still holds locks that block other queries, which is the root cause of the performance issue.

How to eliminate wrong answers

Option A is wrong because insufficient memory would typically manifest as high page life expectancy or memory pressure counters, not as a specific SPID being blocked by another; the exhibit shows no memory-related metrics. Option C is wrong because while a table scan could cause slow performance, the exhibit explicitly shows SPID 55 is 'suspended' due to being blocked (blocked_by = 54), not actively running a scan; a table scan would appear as a 'runnable' or 'running' state with high logical reads. Option D is wrong because a sleeping session (SPID 54) uses negligible CPU; the issue is that it holds locks that block other sessions, not its CPU consumption.

464
MCQmedium

Refer to the exhibit. A Power Pages site is configured with the given authentication settings. When a user clicks 'Sign In', they are redirected to Microsoft Entra ID, but after successful login, they are redirected back to the site and see an error. What is the most likely cause?

A.The clientId is invalid.
B.The tenantId is incorrect.
C.The redirectUrl is not registered in the Microsoft Entra ID app.
D.The site requires HTTPS but is using HTTP.
AnswerC

After successful authentication, Microsoft Entra ID only returns the user to a redirect URI registered on the app registration. An unregistered redirectUrl causes the post-login redirect to fail, producing the error the user sees on returning to the site.

Why this answer

The correct answer is C because the redirect URL must be registered in the Microsoft Entra ID app registration. If it is not, after successful authentication, Entra ID will not redirect back to the Power Pages site, causing an error. The clientId and tenantId are likely correct if the user is redirected to Entra ID and can sign in.

HTTPS is required but the error occurs after login, so it's not the cause.

Exam trap

PL-900 often tests authentication configuration; candidates may focus on clientId or tenantId, but the redirect URI mismatch is a common cause of post-login errors.

How to eliminate wrong answers

Option A is wrong because an invalid clientId would prevent the initial redirect to Entra ID. Option B is wrong because an incorrect tenantId would also prevent the initial redirect or cause an error before login. Option D is wrong because if HTTPS were required and not used, the site would not load or the redirect would fail earlier, not after successful login.

465
MCQmedium

An organization uses a Canvas app to capture customer feedback. The app writes data to a Dataverse table. Recently, users have been submitting duplicate records due to double-clicking the submit button. What is the best way to prevent duplicates?

A.Set the form to require a unique ID before submission
B.Disable the submit button after the first click using the DisplayMode property
C.Add a business rule to check for duplicates before saving
D.Use a Power Automate flow to delete duplicates after creation
AnswerB

Setting the button's DisplayMode to Disabled after submission blocks further clicks, so the OnSelect patch runs once and duplicate Dataverse records are prevented. This directly addresses the double-click cause rather than filtering duplicates after they are created.

Why this answer

Setting the submit button's DisplayMode property to Disabled after the first click prevents the user from triggering the OnSelect logic a second time, which directly stops duplicate records at the source. This is the standard Power Apps pattern for idempotent form submission because it blocks the second event before it can create another Dataverse row.

Exam trap

PL-900 often tests the confusion between preventing duplicates at the UI layer (DisplayMode) versus detecting them after the fact (business rules or flows), and candidates wrongly pick reactive cleanup over proactive prevention.

How to eliminate wrong answers

Option A is wrong because requiring a unique ID before submission does not stop double-clicks — the same ID would simply be submitted twice, and Dataverse would still create duplicates unless a unique constraint exists. Option C is wrong because a business rule checking for duplicates runs after the user has already initiated the save and does not reliably prevent rapid double submissions. Option D is wrong because using Power Automate to delete duplicates is a reactive cleanup that leaves bad data temporarily and adds unnecessary complexity instead of preventing the issue.

466
MCQmedium

A retail company wants to reduce the time store managers spend on manual inventory reporting. Currently, managers use paper forms and email to submit daily stock counts, which then need to be manually entered into a central system. This process is error-prone and delays replenishment. The company wants a solution that automates data entry, provides real-time dashboards, and allows managers to submit reports from their phones without installing any software on the phones. Which combination of Microsoft Power Platform tools should the company use?

A.Power Automate only
B.Power Apps only
C.Power Apps, Power Automate, and Power BI
D.Power BI only
AnswerC

Power Apps delivers a phone browser-based canvas app requiring no installation, Power Automate replaces manual entry by writing counts into the central system, and Power BI supplies real-time dashboards. Together they satisfy automation, dashboards and no-install mobile submission.

Why this answer

The scenario requires a combination of Power Apps (for mobile-friendly report submission without installing software), Power Automate (to automate data entry into the central system), and Power BI (to provide real-time dashboards). Power Apps alone cannot automate data entry or provide dashboards; Power Automate alone cannot provide a mobile input interface or dashboards; Power BI alone cannot capture data or automate workflows. Only the trio covers all requirements: mobile input, automated processing, and real-time visualization.

Exam trap

The trap here is that candidates think a single tool can cover all requirements, but the question explicitly demands three distinct capabilities (mobile input, automation, dashboards) that map to three separate Power Platform components, not one or two.

How to eliminate wrong answers

Option A is wrong because Power Automate only handles workflow automation but cannot provide a mobile-friendly input form or real-time dashboards. Option B is wrong because Power Apps only provides the mobile input interface but cannot automate data entry into the central system or generate dashboards. Option D is wrong because Power BI only provides dashboards but cannot capture inventory submissions from phones or automate data entry.

467
MCQeasy

A small retail chain wants to analyze sales data from its point-of-sale system and create interactive dashboards that show trends by store and product category. The company has business analysts who are familiar with Excel but not with programming. Which Power Platform service should the company use?

A.Power BI
B.Power Virtual Agents
C.Power Automate
D.Power Apps
AnswerA

Power BI is the business analytics service in the Power Platform. It connects to data sources, lets analysts build interactive reports and dashboards with a drag-and-drop experience similar to Excel, and supports sharing across the organization. This matches the retail chain's need to analyze sales data and visualize trends by store and category without programming.

Why this answer

Power BI is designed for business analysts to connect to data, model it, and build interactive reports and dashboards. Its familiar, Excel-like authoring experience lowers the learning curve for users without programming skills. By using Power BI, the retail chain can analyze point-of-sale data and visualize trends by store and product category, which is exactly the analytical outcome described.

Exam trap

The trap here is assuming that any Power Platform service can visualize data, when interactive dashboards and trend analysis are specifically the domain of Power BI.

468
MCQeasy

Your organization wants to allow employees to submit help desk tickets through a mobile app. The solution must be low-code and integrate with Microsoft Teams. Which Microsoft Power Platform component should you use?

A.Power Apps
B.Power Virtual Agents
C.Power Automate
D.Power BI
AnswerA

Power Apps is the low-code component for building interactive apps, including mobile ones, and its Teams integration lets employees submit tickets inside Teams. This satisfies both the low-code and Microsoft Teams constraints in the scenario.

Why this answer

Power Apps is the correct component because it enables the creation of custom mobile apps with low-code development, allowing employees to submit help desk tickets directly from their mobile devices. It integrates natively with Microsoft Teams through the Power Apps app in Teams, enabling users to access and submit tickets without leaving the Teams interface. This aligns with the requirement for a low-code solution that works within the Teams ecosystem.

Exam trap

The trap here is that candidates often confuse Power Automate (automation) with Power Apps (app creation), assuming any integration with Teams must involve a workflow, but the question specifically asks for a component to build the mobile app itself, not the backend automation.

How to eliminate wrong answers

Option B is wrong because Power Virtual Agents is designed for building conversational chatbots, not for creating custom mobile apps; it could handle ticket submission via chat but does not provide a mobile app interface. Option C is wrong because Power Automate is an automation and workflow tool, not an app-building platform; while it can trigger actions like sending notifications, it cannot create the mobile app UI for ticket submission. Option D is wrong because Power BI is a data visualization and analytics tool, not a platform for building custom applications or forms; it cannot be used to submit help desk tickets.

469
MCQmedium

A company wants to reduce manual data entry by automatically extracting information from invoices and updating a SharePoint list. Which combination of Power Platform components should they use?

A.Power BI and Power Virtual Agents
B.Power Apps and Power Automate
C.Power Automate and AI Builder
D.Power Apps and Power BI
AnswerC

AI Builder's form processing extracts invoice fields, and Power Automate triggers on receipt, passes the document to the model, then writes extracted values into SharePoint. This satisfies the requirement to remove manual data entry by combining document extraction with automated list updates.

Why this answer

AI Builder provides prebuilt invoice processing models that can extract key fields (e.g., invoice number, date, total) from documents, and Power Automate can trigger a flow to write that extracted data directly into a SharePoint list. This combination eliminates manual data entry by automating the extraction and storage pipeline.

Exam trap

The trap here is that candidates often assume Power Apps is needed for any data entry scenario, but in this case the automation is purely backend (no user interface required), so Power Automate combined with AI Builder is the correct and minimal solution.

How to eliminate wrong answers

Option A is wrong because Power BI is a data visualization and analytics tool, not a data extraction or automation tool, and Power Virtual Agents is for building conversational chatbots, not for processing invoices. Option B is wrong because Power Apps alone cannot extract data from invoices; it requires AI Builder or another OCR service to perform the extraction, and while Power Automate can orchestrate the flow, the combination lacks the AI extraction capability. Option D is wrong because Power BI is for reporting and analytics, not for data extraction or automation, and Power Apps cannot extract invoice data without an AI service.

470
MCQmedium

A marketing department wants to create a custom portal where external partners can submit project proposals and track their status. Which Power Platform product should they use?

A.Power Automate
B.Power Apps portal (now Power Pages)
C.Power Virtual Agents
D.Power BI
AnswerB

Power Pages (formerly Power Apps portals) provides an external-facing website with Dataverse-backed forms and lists, letting partners authenticate and submit proposals while tracking status. Internal app builders like canvas apps cannot serve anonymous or external partner audiences.

Why this answer

Power Apps portals (now Power Pages) is the correct choice because it enables organizations to create low-code, externally facing websites that allow external users—such as partners—to sign in, submit project proposals, and track their status. It integrates with Microsoft Dataverse to store and manage the proposal data, and supports role-based access control to ensure partners only see their own submissions.

Exam trap

The trap here is that candidates often confuse Power Automate's ability to handle form submissions (e.g., via Microsoft Forms or SharePoint) with the need for a dedicated external-facing portal, overlooking that Power Pages is the only option that provides a customizable, authenticated website for external users.

How to eliminate wrong answers

Option A is wrong because Power Automate is a workflow automation tool that orchestrates processes (e.g., sending approval emails) but does not provide a user-facing portal for external partners to submit or track data. Option C is wrong because Power Virtual Agents is designed for building conversational AI chatbots, not for creating custom web portals with data submission and tracking capabilities. Option D is wrong because Power BI is a business analytics and visualization platform; it can display proposal status dashboards but cannot serve as an interactive submission portal for external users.

471
Multi-Selectmedium

A company uses Power Automate to automate approval processes. They need to create a cloud flow that sends an approval request to a manager when a new item is added to a SharePoint list, and then updates the list item with the approval outcome. Which two actions are required to achieve this? (Choose two.)

Select 2 answers
A.Send an email (V2)
B.Start and wait for an approval
C.Update item
D.Get item
E.Create a record
AnswersB, C

This action is required because it sends the approval request and pauses the flow until a response is received. It provides the outcome (approved or rejected) that can be used in subsequent steps. Without this action, the flow cannot collect the manager's decision, which is central to the scenario.

Why this answer

The two essential actions are 'Start and wait for an approval' to solicit and capture the manager's decision, and 'Update item' to write that decision back to the SharePoint list. These actions together automate the approval workflow from request to record update. Other actions like sending a separate email or creating a new record are not needed because the approval action handles notification and the scenario requires updating an existing item.

Exam trap

The trap here is including redundant actions like sending a separate email, which is already handled by the approval action, or using 'Get item' when the trigger already supplies the item data.

472
MCQmedium

A company has a Microsoft Copilot Studio copilot that answers product questions by searching a public product catalog website. The copilot currently uses generative answers and returns inconsistent results. The company wants the copilot to use only approved content from a specific internal SharePoint site. What should the maker configure to restrict the copilot's generative answers to that SharePoint site?

A.Publish the copilot to Microsoft Teams and configure a Teams channel data loss prevention policy.
B.Disable generative answers entirely and rely on the fallback topic.
C.Add the SharePoint site as a knowledge source in the copilot's generative answers settings.
D.Create a topic with trigger phrases for each product question and hard-code the answers.
AnswerC

Microsoft Copilot Studio allows makers to add specific knowledge sources, such as SharePoint sites, to ground generative answers. By adding only the approved internal SharePoint site as a knowledge source and removing or disabling the public website source, the copilot will generate answers based solely on that content. This directly satisfies the requirement to restrict responses to approved internal material.

Why this answer

Generative answers in Microsoft Copilot Studio are grounded in knowledge sources that the maker configures. Adding a specific SharePoint site as a knowledge source and ensuring no public sources are enabled restricts the copilot to approved internal content. This provides accurate, consistent answers based on the organization's authoritative product information rather than unpredictable public web results.

Exam trap

The trap here is thinking that changing the publishing channel or adding static topics will control generative answer grounding, when knowledge sources are the actual mechanism.

473
Multi-Selecteasy

Which TWO data sources can be used directly in a canvas app without a premium connector? (Choose two.)

Select 2 answers
A.Salesforce
B.Microsoft Dataverse
C.Excel Online (Business)
D.SQL Server
E.SharePoint
AnswersB, E

Microsoft Dataverse requires a premium connector.

Why this answer

Microsoft Dataverse and SharePoint are standard connectors that can be used without a premium license. Salesforce requires a premium connector. Excel Online (Business) is also a standard connector, but the correct answers for this question are Dataverse and SharePoint.

SQL Server requires a premium connector.

474
MCQmedium

A company has a legacy on-premises SQL Server database and wants to integrate it with a Power App without moving data to the cloud. Which connector should they use?

A.SQL Server connector directly
B.Power Automate on-premises agent
C.Dataverse
D.On-premises data gateway with SQL Server connector
AnswerD

The on-premises data gateway creates an outbound channel from Power Platform to on-premises resources, so the SQL Server connector queries the legacy database in place. No data migration to the cloud is required, satisfying the stated constraint.

Why this answer

The On-premises data gateway acts as a secure bridge between cloud services like Power Apps and on-premises data sources such as SQL Server. When combined with the SQL Server connector, it allows live queries and updates to the on-premises database without requiring data migration to the cloud, fulfilling the requirement to keep data on-premises.

Exam trap

The trap here is that candidates often confuse the On-premises data gateway with the Power Automate on-premises agent, mistakenly thinking the agent can serve as a general data connector, when in fact it is only for desktop flow automation.

How to eliminate wrong answers

Option A is wrong because the SQL Server connector alone cannot directly access an on-premises SQL Server from the cloud; it requires a gateway to traverse the firewall and network boundaries. Option B is wrong because Power Automate on-premises agent is a specific component for robotic process automation (RPA) and desktop flows, not for connecting Power Apps to on-premises SQL Server databases. Option C is wrong because Dataverse is a cloud-based data storage service that would require moving data to the cloud, which contradicts the requirement to keep data on-premises.

475
MCQeasy

A travel agency's marketing team creates a copilot in Microsoft Copilot Studio that answers questions about vacation packages. Before releasing it to customers on the agency's website, the team wants to verify that the copilot responds correctly to sample customer messages. What should the team use?

A.The Power Platform admin center's environment analytics page
B.The Test copilot pane in Microsoft Copilot Studio
C.The solution export and import wizard
D.The Microsoft Dataverse auditing configuration page
AnswerB

The Test copilot pane lets makers converse with the copilot in the authoring environment and inspect which topic or knowledge response handled each message. It is designed exactly for validating responses to sample utterances before publishing, so the team can confirm behavior without exposing an unfinished copilot to customers.

Why this answer

The Test copilot pane provides an interactive chat within Microsoft Copilot Studio where makers send sample utterances and see how the copilot routes and responds. It also shows which topic or knowledge source handled each message, making it the right tool for pre-release validation. Analytics, solution packaging, and auditing serve governance or deployment purposes, not conversational testing.

Exam trap

The trap here is confusing post-deployment monitoring tools with the in-authoring test experience that lets you validate a copilot before customers ever see it.

476
Multi-Selecteasy

Which TWO components are required to create a Power Automate flow that sends an email when a new item is added to a SharePoint list? (Choose two.)

Select 2 answers
A.A trigger
B.An approval action
C.A variable
D.A condition
E.A Send an email action
AnswersA, E

Correct. Every flow needs a trigger.

Why this answer

A trigger is required because a Power Automate flow must have a starting event to initiate execution. For a SharePoint list, the 'When an item is created' trigger fires automatically when a new item is added, which is the necessary first step before any actions can run.

Exam trap

The trap here is that candidates often think a condition or approval is needed for any 'smart' automation, but the question only asks for the minimum components to send an email on item creation, which is just a trigger and an action.

477
MCQmedium

A Power Pages site needs to display a list of upcoming events from a Dataverse table. Only events with a start date greater than today should be shown. Which approach should be used to filter the data on the page?

A.Configure a view in Dataverse with a filter for start date > today and use that view on the page.
B.Use a Power Automate flow to remove past events from the table.
C.Use JavaScript on the page to hide past events after loading.
D.Create a calculated column in Dataverse to indicate future events.
AnswerA

A Dataverse view stores the filter condition server-side, so the list component queries only events whose start date exceeds today. This pushes filtering to the data layer rather than retrieving all rows and filtering client-side.

Why this answer

The most straightforward and efficient approach in Power Pages is to use a Dataverse view with a pre-applied filter (start date > today) to display only upcoming events. This offloads filtering to the data source, ensuring that users only see relevant data without relying on client-side logic or flows that might be slower or more complex. While OData filters are possible, using a Dataverse view is simpler and aligns with Power Pages' low-code design.

478
MCQeasy

A company wants to build a custom app that allows employees to submit expense reports from their mobile devices. The app must be easy to customize and deploy without writing code. Which type of Power App should they use?

A.Power Automate
B.Power Pages
C.Canvas app
D.Model-driven app
AnswerC

Canvas apps give pixel-level control over the mobile interface and connect to data through connectors, letting makers build and publish without pro-code development. This satisfies the stem's no-code customisation and deployment requirement, unlike model-driven apps, which are metadata-driven.

Why this answer

Canvas apps are the correct choice because they provide a drag-and-drop, no-code/low-code design surface that lets makers build a custom mobile-friendly UI and connect to data sources like SharePoint, Dataverse, or SQL without writing code. They are ideal for task-oriented apps such as expense submission that need a tailored form and mobile deployment via Power Apps mobile or Teams.

Exam trap

PL-900 often tests the distinction between canvas apps (no-code, custom UI) and model-driven apps (data-model-driven, less UI control), so candidates who focus on 'custom app' may wrongly pick model-driven or Power Pages.

How to eliminate wrong answers

Option A is wrong because Power Automate is a workflow/automation service for triggering actions and approvals, not for building a user-facing custom app UI. Option B is wrong because Power Pages is for building external-facing business websites with Dataverse data, not internal mobile expense apps. Option D is wrong because model-driven apps are generated from Dataverse table metadata and are not easily customized for a bespoke mobile form without code, and they require a defined data model rather than a freeform canvas layout.

479
MCQmedium

A company uses Microsoft Power Platform and requires that all environment creation requests go through an approval process. The security team wants to prevent non-admins from creating trial environments. What should the administrator configure?

A.In Power Platform Admin Center, set 'Disable trial environments created by non-admins' to Yes
B.Assign users to an environment group with restricted permissions
C.In Power Apps settings, disable 'Allow users to create environments'
D.Create a Data Loss Prevention (DLP) policy that blocks trial environments
AnswerA

This setting prevents non-admins from creating trial environments.

Why this answer

The Power Platform Admin Center provides a dedicated tenant-level setting called 'Disable trial environments created by non-admins' that, when set to 'Yes', prevents users without administrative privileges from creating trial environments. This directly addresses the security team's requirement to block non-admins from creating trial environments, as it enforces an approval-based control at the environment creation level.

Exam trap

The trap here is that candidates often confuse DLP policies with environment lifecycle controls, assuming DLP can block environment creation, when in reality DLP only governs data connectors and policies across environments, not provisioning actions.

How to eliminate wrong answers

Option B is wrong because environment groups (or environment routing groups) do not exist in Power Platform; this is a fabricated concept and cannot restrict environment creation permissions. Option C is wrong because the setting 'Allow users to create environments' in Power Apps settings is a legacy control that only applies to the default environment and does not specifically block trial environments; it also does not enforce an approval process. Option D is wrong because Data Loss Prevention (DLP) policies control data movement and connector usage across environments, not environment creation or trial environment provisioning; DLP policies cannot block the creation of environments.

480
MCQeasy

A sales team wants to quickly create a mobile app to track customer visits without writing code. Which Microsoft Power Platform component should they use?

A.Power Automate
B.Power Virtual Agents
C.Power Apps
D.Power BI
AnswerC

Power Apps provides a drag-and-drop canvas and model-driven designer for building mobile apps without code, publishing to phones for field use. This directly satisfies the sales team's requirement to track customer visits quickly with no programming.

Why this answer

Power Apps is the correct choice because it enables users to build custom mobile apps with a low-code or no-code approach, specifically designed for creating data-driven applications like a customer visit tracker. The sales team can connect to data sources (e.g., Dataverse, SharePoint, or Excel) and design a mobile-friendly interface without writing any code, making it ideal for quickly tracking customer visits.

Exam trap

The trap here is that candidates often confuse Power Automate with Power Apps because both are low-code tools, but Power Automate is for automating workflows (e.g., sending an email after a visit), not for building the app interface itself.

How to eliminate wrong answers

Option A is wrong because Power Automate is a workflow automation tool for creating flows between apps and services, not for building mobile app interfaces or tracking customer visits directly. Option B is wrong because Power Virtual Agents is used to create conversational AI chatbots, not for building a mobile app to track visits. Option D is wrong because Power BI is a business analytics and visualization tool for creating reports and dashboards, not for building interactive mobile applications.

481
Multi-Selecteasy

Which TWO data sources can be directly connected to a canvas app without using a premium connector?

Select 2 answers
A.Excel (OneDrive/SharePoint)
B.Microsoft Dataverse
C.SharePoint
D.SQL Server
E.Salesforce
AnswersA, C

Excel workbooks stored in OneDrive for Business or SharePoint use the standard Excel connector, which is included in the Power Apps seeded licence. It therefore connects directly without consuming a premium connector, satisfying the no-premium-connector constraint in the stem.

Why this answer

Option A (Excel in OneDrive/SharePoint) is correct because Excel workbooks stored in OneDrive for Business or SharePoint are accessed through the standard Excel connector, which is a non-premium (Standard) connector included with Power Apps. Option C (SharePoint) is correct because the SharePoint connector is also a Standard connector, allowing canvas apps to read and write SharePoint lists and libraries without a premium license. Option B (Microsoft Dataverse) is incorrect because Dataverse requires premium licensing/connectors.

Option D (SQL Server) is incorrect because the SQL Server connector is a premium connector. Option E (Salesforce) is incorrect because the Salesforce connector is a premium connector.

Exam trap

PL-900 often tests the difference between standard and premium connectors, and candidates frequently mistake Dataverse or SQL Server as standard because they are commonly used in demos, leading to incorrect selections.

482
MCQmedium

A copilot built in Microsoft Copilot Studio must create a record in a Microsoft Dataverse table after a user confirms a request in chat. The team wants the copilot to perform this action during the conversation without leaving the chat. What should you configure?

A.Enable the copilot's voice channel and use speech recognition.
B.Publish the copilot to a custom website and embed it there.
C.Add the Dataverse table as a knowledge source to the copilot.
D.Add a Power Automate flow as an action in the topic and call it from a node.
AnswerD

Calling a cloud flow from a topic action is the supported way to perform back-end operations such as creating a Dataverse record during a conversation. The flow runs when the topic reaches that node, and the copilot can continue the chat afterward. This satisfies the requirement to act within the chat experience.

Why this answer

To perform a back-end write during a chat, the copilot must invoke an action. Cloud flows called from topic nodes are the standard integration pattern, letting the copilot create the Dataverse record after confirmation and then respond to the user. Knowledge sources, channels, and publishing settings do not provide transactional write capability.

Exam trap

The trap here is confusing read-oriented knowledge grounding with write-capable actions, assuming that connecting Dataverse as knowledge also lets the copilot create records.

483
MCQhard

Your organisation has a Power Apps canvas app that uses a custom connector to call an external API. The API key is stored in a global variable. What is the security concern with this approach?

A.The custom connector cannot be used with Power Apps.
B.Global variables cannot store API keys because they are read-only.
C.The API key will expire quickly.
D.The API key can be exposed to end users in the app code.
AnswerD

Global variables are stored client-side in the app, so any user can inspect them at runtime via the browser or Power Apps Studio. Storing the API key there exposes the credential to end users, satisfying the stem's requirement to identify the security concern.

Why this answer

Storing an API key in a global variable within a Power Apps canvas app is insecure because the app's code is accessible to end users. Anyone with access to the app can view the global variable's value through the App object or by inspecting the app's formulas, potentially exposing the API key. The correct answer is D.

Option A is incorrect because custom connectors can be used with Power Apps. Option B is incorrect because global variables in Power Apps are writable, not read-only. Option C is incorrect because API keys typically do not expire quickly; the security concern is exposure, not expiration.

484
MCQmedium

A Power Automate flow uses the 'Apply to each' action to process items from a SharePoint list. The flow is running slowly. What is the most effective way to improve performance?

A.Add a 'Condition' action inside the loop.
B.Use a 'Do until' loop instead.
C.Enable concurrency control on the 'Apply to each' action.
D.Reduce the number of items in the list.
AnswerC

Concurrency control lets the 'Apply to each' action process multiple SharePoint items in parallel rather than sequentially, directly cutting total runtime. This addresses the stem's slow-flow constraint by raising throughput without altering the loop's logic.

Why this answer

Enabling concurrency control on the 'Apply to each' action allows multiple iterations to run in parallel, significantly reducing total processing time. Option A adds a condition inside the loop, which does not improve performance and may even add overhead. Option B replaces the loop with a 'Do until' loop, which still processes items sequentially.

Option D reduces the number of items, which is not always feasible and does not improve the flow's efficiency when processing large lists.

485
MCQmedium

Refer to the exhibit. A Power BI dashboard is configured with the shown data sources. The dashboard fails to refresh automatically. What is the most likely cause?

A.The refresh frequency is set to daily, which is too infrequent
B.The Excel file is stored in an unsupported location
C.The SQL Server data source requires an on-premises data gateway
D.The dashboard uses two data sources, but only one is allowed
AnswerC

On-premises SQL Server cannot be reached directly by the Power BI cloud service, so refreshes fail until an on-premises data gateway bridges the two. This satisfies the exhibit's hybrid connectivity constraint; cloud-only sources would refresh without a gateway, but local SQL Server requires one.

Why this answer

The dashboard refreshes automatically but fails. The data sources shown are an Excel file stored on SharePoint (supported, no gateway needed) and an on-premises SQL Server (server name indicates on-premises). For Power BI service to access on-premises data, an on-premises data gateway must be installed and configured.

Without it, the SQL Server connection will fail during refresh. Options A and D are incorrect because daily frequency and using two data sources are not issues. Option B is incorrect because SharePoint is a supported location for Excel files.

Therefore, the most likely cause is that the SQL Server data source requires an on-premises data gateway.

486
MCQhard

An organization has a model-driven app built on Dataverse. Users report that when they try to save a record, they receive an error about missing required fields, but they believe they filled them in. What is the most likely cause?

A.A business rule is setting a field as required based on conditions
B.The user does not have write permissions to the Dataverse table
C.A Power Automate flow is blocking the save
D.A custom connector is failing to validate data
AnswerA

Business rules can set a column to required dynamically when conditions are met, so the field appears optional on the form yet blocks saving. Users believe they completed the fields, but the rule enforces a requirement the form does not visually indicate.

Why this answer

Business rules can dynamically set field requirements based on conditions, which may cause users to see missing required fields even if they filled in all originally required fields. Option B is incorrect because write permissions would prevent saving entirely, not just show missing required fields. Option C is incorrect because Power Automate flows run after a record is saved, not before, so they cannot block the save.

Option D is incorrect because custom connectors are used for integrating external systems, not for Dataverse field validation.

487
MCQhard

A financial services company uses Microsoft Copilot Studio to build an internal copilot that answers questions about loan policies. The copilot must ensure that only employees in the loan department can access sensitive policy details. The company uses Microsoft Entra ID for authentication. What should the maker configure to enforce this access restriction?

A.Publish the copilot only to the Microsoft Teams channel and rely on Teams membership for access control.
B.Add a question node at the start of each topic that asks the user to type their department name.
C.Enable authentication for the copilot and configure the security group restriction in the copilot's security settings.
D.Use a condition node that checks the user's display name against a list of loan department employees.
AnswerC

Microsoft Copilot Studio supports authentication and can restrict access to specific Microsoft Entra ID security groups. Enabling authentication ensures users sign in, and configuring the security group restriction limits access to loan department employees. This directly enforces the requirement that only authorized personnel can access sensitive policy details, making it the correct configuration.

Why this answer

Enabling authentication in Microsoft Copilot Studio and configuring a security group restriction ties access to Microsoft Entra ID group membership. Only users in the specified loan department security group can interact with the copilot and access sensitive policy details. This provides a secure, manageable, and authoritative access control mechanism that aligns with the company's existing identity infrastructure.

Exam trap

The trap here is believing that publishing to a specific channel or asking users to self-identify provides sufficient access control, when only authentication combined with security group restrictions enforces true authorization.

488
MCQhard

A hospital wants to build a chatbot that answers patients' frequently asked questions about visiting hours, parking, and insurance, and then hands off to a live agent when the bot cannot answer. The hospital wants to minimize development effort and integrate with its existing website. Which Power Platform service should the hospital use?

A.Power Apps
B.Power Virtual Agents
C.Power Automate
D.Power BI
AnswerB

Power Virtual Agents is the Power Platform service for building chatbots with a graphical authoring experience. It supports topics, entities, and variables to answer FAQs, and it can hand off to a live agent through integration with Omnichannel for Customer Service or a custom handoff. This matches the hospital's need for a low-effort, website-integrated chatbot.

Why this answer

Power Virtual Agents is purpose-built for creating conversational bots without extensive coding. It can answer common patient questions through authored topics and can escalate to a human agent when needed. Because it can be published to a website and integrates with handoff mechanisms, it directly addresses the hospital's requirements for FAQ handling and live agent transfer with minimal development effort.

Exam trap

The trap here is assuming that a data-focused service like Power BI can handle conversational FAQs, when chatbot authoring and agent handoff belong to Power Virtual Agents.

489
MCQmedium

A company uses Power Automate to process purchase orders. After a recent update, the flow fails intermittently with a '429 Too Many Requests' error. What is the most likely cause?

A.The flow uses an expired connector authentication.
B.The flow is running an outdated version.
C.The flow is exceeding Power Platform service protection limits.
D.The data source is temporarily unavailable.
AnswerC

HTTP 429 signals throttling, not a malformed expression or expired connection. Power Automate applies per-connection and per-flow service protection limits, so bursts of purchase-order runs exceeding those request thresholds cause intermittent failures until the retry window resets.

Why this answer

The '429 Too Many Requests' error is an HTTP status code indicating rate limiting. In Power Automate, this occurs when a flow exceeds the Power Platform service protection limits, which are designed to prevent resource overconsumption. These limits include API request caps (e.g., 30 requests per 60 seconds per connection) and daily invocation quotas (e.g., 5,000 requests per day for a per-user plan).

The error is not related to authentication expiry, outdated flow versions, or data source availability.

Exam trap

The trap here is that candidates confuse '429 Too Many Requests' with authentication or connectivity issues, but the exam specifically tests knowledge of Power Platform service protection limits as a distinct throttling mechanism.

How to eliminate wrong answers

Option A is wrong because an expired connector authentication would produce a '401 Unauthorized' or '403 Forbidden' error, not a '429 Too Many Requests' error. Option B is wrong because an outdated flow version does not cause HTTP 429 errors; flow versions affect feature availability but not API rate limits. Option D is wrong because a temporarily unavailable data source would return a '503 Service Unavailable' or connection timeout error, not a rate-limiting 429 response.

490
MCQmedium

A company wants to automatically post a message to a Microsoft Teams channel whenever a new item is added to a SharePoint list named 'ProjectTasks'. The Power Automate flow should include the necessary trigger and action. Which trigger and action combination should you use?

A.Trigger: When a new response is submitted (Microsoft Forms); Action: Post message in a chat or channel (Microsoft Teams)
B.Trigger: When an item is created (SharePoint); Action: Post message in a chat or channel (Microsoft Teams)
C.Trigger: When a file is created (SharePoint); Action: Post message in a chat or channel (Microsoft Teams)
D.Trigger: When an item is created (SharePoint); Action: Send an email (Outlook)
AnswerB

This combination is correct because the SharePoint trigger 'When an item is created' fires when a new list item is added, and the Microsoft Teams action 'Post message in a chat or channel' allows posting to a specific channel. This directly meets the requirement to notify a Teams channel upon new SharePoint list items.

Why this answer

The correct trigger must monitor the SharePoint list for new items, and the action must post to a Teams channel. 'When an item is created' is the appropriate SharePoint trigger, and 'Post message in a chat or channel' is the correct Teams action. Other triggers target different event sources, and other actions send emails rather than channel messages.

Exam trap

The trap here is confusing SharePoint file triggers with list item triggers, or selecting an email action when the requirement specifies a Teams channel post.

491
MCQeasy

A small business owner wants to create a customer loyalty program. They want customers to earn points for purchases and redeem them for discounts. The owner has no coding experience and a limited budget. They need a mobile-friendly app for customers to check points and a backend to manage points and redemptions. What should they use?

A.Power BI, Power Automate, and Dataverse
B.Power Apps, Power Automate, and Dataverse
C.Power Apps, AI Builder, and Dataverse
D.Power Pages, Power Automate, and SharePoint
AnswerB

Power Apps delivers the mobile-friendly customer interface with no coding, Power Automate handles points and redemption logic, and Dataverse stores the loyalty data relationally. Together they satisfy the no-code, low-budget constraint whilst providing both app and backend.

Why this answer

Power Apps allows building a mobile-friendly app without coding, Power Automate handles workflow automation for points and redemptions, and Dataverse provides a secure and scalable backend data store. This combination meets the requirements of no coding, limited budget, and mobile app with backend management.

Exam trap

PL-900 often tests the confusion between Power BI (analytics) and Power Apps (app development), or between Power Pages (websites) and Power Apps (mobile apps), leading candidates to choose incorrect components.

How to eliminate wrong answers

Option A is wrong because Power BI is for analytics and visualization, not for building a customer-facing app or managing transactional data. Option C is wrong because AI Builder adds AI capabilities but is unnecessary for a simple loyalty program and may increase cost and complexity. Option D is wrong because Power Pages is for external-facing websites, not mobile apps, and SharePoint may not provide the necessary relational data structure and automation for a loyalty program.

492
MCQeasy

A sales team wants to automate lead assignment based on region without writing code. Which Microsoft Power Platform component should they use?

A.Power Apps
B.Power BI
C.Power Automate
D.Power Virtual Agents
AnswerC

Power Automate provides no-code cloud flows that trigger on record creation and route leads by region, satisfying the requirement to automate assignment without writing code. Its connectors and conditions handle the regional logic declaratively, unlike canvas apps or dashboards.

Why this answer

Power Automate is the correct choice because it enables users to create automated workflows that can assign leads based on region using conditional logic and data from sources like Dynamics 365 or SharePoint, all without writing code. It provides prebuilt connectors and triggers (e.g., 'When a lead is created') to automate business processes seamlessly.

Exam trap

The trap here is that candidates often confuse Power Automate with Power Apps, thinking that building an app is required to automate lead assignment, but Power Automate handles the workflow logic independently without a custom user interface.

How to eliminate wrong answers

Option A is wrong because Power Apps is a low-code platform for building custom apps, not for automating workflows or lead assignment logic. Option B is wrong because Power BI is a business analytics tool for data visualization and reporting, not for triggering automated actions like lead routing. Option D is wrong because Power Virtual Agents is designed for creating conversational chatbots, not for backend process automation or rule-based lead assignment.

493
MCQmedium

A regional health clinic chain wants to reduce the time staff spend manually copying patient intake details from paper forms into its electronic records system. The IT team has no developers available and wants a solution that non-technical clinical staff can build and maintain themselves. The solution must capture the form data, store it in a structured cloud table, and notify the records team automatically. Which combination of Power Platform services should the clinic use?

A.Microsoft Dataverse, Power BI, and Power Pages
B.Power Automate, AI Builder, and Power BI
C.Power BI, Power Virtual Agents, and Power Pages
D.Power Apps, Microsoft Dataverse, and Power Automate
AnswerD

This combination covers all requirements natively: Power Apps provides the low-code intake app clinical staff can build, Dataverse supplies the structured cloud table for patient details, and Power Automate delivers the automatic notification to the records team. No traditional development is required, and all three services share the same connector model, so the clinic's non-technical staff can maintain the solution end to end.

Why this answer

The clinic needs three capabilities: a low-code way to capture intake data, structured cloud storage, and an automated notification. Power Apps delivers the buildable interface, Microsoft Dataverse provides the governed relational table that non-developers can extend, and Power Automate handles the trigger-based notification. The other combinations substitute analytics, chatbot, or portal services that do not fulfill the capture-store-notify chain.

Exam trap

The trap here is assuming any three Power Platform services can be combined interchangeably, when only the app-plus-Dataverse-plus-automation trio actually covers data capture, structured storage, and notification.

494
MCQmedium

An organization wants to allow external partners to access specific Power Apps and data without granting them full access to the tenant. What should they configure?

A.Use Microsoft Intune to manage partner devices.
B.Create a data loss prevention (DLP) policy that allows external sharing.
C.Invite partners as guest users in Microsoft Entra ID and assign them appropriate security roles in the Power Platform environment.
D.Share the app URL with the partners and ask them to sign in with their own accounts.
AnswerC

Guest accounts in Microsoft Entra ID grant external partners scoped access without tenant-wide rights, and Power Platform security roles then limit them to the specific apps and data required, satisfying the constraint of no full tenant access.

Why this answer

Inviting external partners as guest users in Microsoft Entra ID (formerly Azure AD) and assigning them appropriate security roles in the Power Platform environment is the standard method for providing controlled, least-privilege access to specific Power Apps and their underlying data sources. This approach leverages Microsoft Entra B2B collaboration to create guest identities, which can then be granted access to specific environments and resources without giving them full tenant-level permissions.

Exam trap

The trap here is that candidates often confuse sharing the app URL (Option D) with a valid access method, not realizing that Power Apps requires authenticated users with appropriate permissions in the environment, and simply providing a URL does not grant access unless the user is already a guest or member of the tenant.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution for managing devices and apps, not a mechanism for granting external users access to Power Apps or data. Option B is wrong because a data loss prevention (DLP) policy controls how data can be shared between connectors and prevents data exfiltration, but it does not provide authentication or authorization for external users to access Power Apps. Option D is wrong because sharing the app URL and asking partners to sign in with their own accounts would require those accounts to be recognized by the tenant (e.g., as guest users) or the app to be publicly accessible, which would bypass security controls and is not a supported method for secure external access.

495
MCQhard

In a model-driven app, a user wants to see a map of all customer addresses on a form. Which feature should be enabled?

A.Notes section
B.Map control
C.Associated View
D.Timeline control
AnswerB

The map control renders address data from a form's address fields as an interactive map, letting users visualise customer locations directly. Enabling it on the form satisfies the requirement to see all customer addresses plotted geographically.

Why this answer

The Map control in Power Apps model-driven apps renders address fields on a form as an interactive map, plotting customer locations based on latitude/longitude or address data. Enabling it on the form gives users a visual geographic view of all customer addresses without custom development.

Exam trap

PL-900 often tests the confusion between form controls that look similar in the designer — candidates pick Timeline or Associated View when the question specifically asks for geographic/map visualization.

How to eliminate wrong answers

Option A is wrong because the Notes section is for attaching text notes and files to a record, not for geographic visualization. Option C is wrong because an Associated View displays related records in a grid/list format, not a map. Option D is wrong because the Timeline control shows the activity history (emails, calls, appointments) for a record, not address locations.

496
MCQmedium

An organization wants to ensure that when a Power Apps canvas app is shared with a user, the user can run the app but cannot edit it or share it with others. The app is in a production environment. What should the administrator or maker do?

A.Publish the app as a managed solution and assign the user the 'System Customizer' role.
B.Add the user to a security role that has only read access to the app's data source.
C.Share the app with the user and assign the 'Can use' permission only.
D.Share the app with the user and assign the 'Can edit' permission, then remove the user's Environment Maker role.
AnswerC

When sharing a canvas app, you can assign either 'Can use' or 'Can edit' permissions. 'Can use' allows the user to run the app but not modify it or share it. This directly meets the requirement to restrict the user to running the app only, without editing or sharing capabilities.

Why this answer

Canvas app sharing permissions are managed directly when sharing the app. The 'Can use' permission allows users to run the app but not edit or reshare it. 'Can edit' grants modification rights. Security roles and solution packaging do not control app-level sharing permissions, so they are not the correct mechanisms for this requirement.

Exam trap

The trap here is confusing data source security roles or solution types with app sharing permissions; only the 'Can use' permission restricts a user to running the app without editing or sharing.

497
MCQhard

A company has multiple Power Platform environments. They want to automatically apply consistent settings (e.g., DLP policies, audit settings) to all new environments. What should they do?

A.Use PowerShell scripts to configure each environment after creation.
B.Use Azure Blueprints to define and apply a set of Azure resources.
C.Create an environment group in the Power Platform admin center and assign policies to the group.
D.Use Microsoft Intune to enforce settings on Power Platform environments.
AnswerC

Environment groups in the Power Platform admin center let administrators assign DLP policies and audit settings once, with those rules automatically inherited by every environment added to the group, including newly created ones. This satisfies the requirement for consistent automatic configuration.

Why this answer

Environment groups in the Power Platform admin center allow administrators to define a set of policies (such as DLP policies and audit settings) that are automatically applied to all environments within the group, including newly created ones. This provides a centralized, no-code method to enforce consistent governance across multiple environments without manual intervention.

Exam trap

The trap here is that candidates may confuse Azure Blueprints (which manage Azure infrastructure) with Power Platform environment governance, or think that PowerShell scripting is the only way to automate settings, overlooking the built-in environment group feature that provides automatic, policy-driven consistency.

How to eliminate wrong answers

Option A is wrong because using PowerShell scripts to configure each environment after creation is a manual, reactive approach that does not automatically apply settings to new environments as they are created, and it requires ongoing maintenance and scripting expertise. Option B is wrong because Azure Blueprints are designed to orchestrate the deployment of Azure resources (e.g., VMs, databases) and are not applicable to managing Power Platform environment settings like DLP policies or audit configurations. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) tool for managing devices and apps, not for enforcing settings on Power Platform environments.

498
MCQeasy

A company wants to build a Power App that uses AI to analyze survey responses and extract sentiment. Which Power Platform capability should they use?

A.Power BI dashboards
B.Power Automate flows
C.AI Builder sentiment analysis model
D.Power Apps Canvas app with formulas
AnswerC

AI Builder's prebuilt sentiment analysis model classifies text as positive, negative or neutral and returns confidence scores. It plugs into Power Apps and Power Automate, so survey responses can be scored automatically without training a custom model.

Why this answer

AI Builder provides prebuilt AI models, including a sentiment analysis model, that can be invoked directly from Power Apps and Power Automate without custom ML code. For analyzing survey text and extracting sentiment, the AI Builder sentiment analysis model is the purpose-built capability. It returns a sentiment score and label per response, which can then be stored or visualized.

Exam trap

PL-900 often tests the boundary between platform components — candidates confuse Power Automate (orchestration) and Power BI (visualization) with AI Builder (the actual AI model), picking a tool that could call sentiment analysis rather than the capability that performs it.

How to eliminate wrong answers

Option A is wrong because Power BI dashboards visualize data but do not perform sentiment analysis on text — they are a presentation layer, not an AI capability. Option B is wrong because Power Automate flows orchestrate actions and can call AI Builder, but the flow itself does not analyze sentiment; it is the automation engine, not the model. Option D is wrong because a Canvas app with formulas is a UI and expression layer — formulas alone cannot perform natural language sentiment analysis without an underlying AI service such as AI Builder.

499
Multi-Selecthard

Which THREE of the following are capabilities of Power Pages? (Choose three.)

Select 3 answers
A.Integrate with Microsoft Copilot Studio for chatbots
B.Real-time co-authoring in Microsoft Word
C.Schedule data refresh for reports
D.Connect to Microsoft Dataverse as a data source
E.Create low-code, responsive websites
AnswersA, D, E

Power Pages integrates natively with Microsoft Copilot Studio, letting makers embed conversational chatbots directly into external-facing sites. This satisfies the stem's requirement for a genuine Power Pages capability, since Copilot Studio bots can be deployed on portals without custom code, extending site functionality beyond static content.

Why this answer

Option A is correct because Power Pages natively supports embedding a chatbot built with Microsoft Copilot Studio (formerly Power Virtual Agents) into a portal, allowing makers to add conversational AI experiences to external-facing sites. Option D is correct because Power Pages uses Microsoft Dataverse as its primary data platform, letting makers bind forms, lists, and web APIs to Dataverse tables as a data source. Option E is correct because Power Pages is a low-code/no-code site-building tool that produces responsive websites rendered with Bootstrap-based templates, so pages adapt to desktop and mobile browsers.

Option B is not a Power Pages capability; real-time co-authoring in Word belongs to Microsoft 365 document collaboration, not portal authoring. Option C is not a Power Pages capability; scheduled data refresh for reports is a feature of Power BI (dataset scheduled refresh) rather than Power Pages.

Exam trap

PL-900 often tests product boundary confusion — candidates must distinguish Power Pages capabilities from Power BI (report refresh) and Microsoft 365 (Word co-authoring) features.

500
MCQhard

A financial services company uses Power Automate to process loan applications. The flow uses the ‘When a new email arrives’ trigger from a shared mailbox. The flow recently stopped working after an admin changed the mailbox permissions. What is the most likely cause?

A.The mailbox exceeded its storage limit
B.The mailbox connection lost permissions to access the mailbox
C.The flow owner's Power Automate license was deleted
D.The flow was transferred to another owner
AnswerB

The trigger authenticates using the connection's stored credentials against the shared mailbox. When the administrator altered mailbox permissions, the connection principal lost access, so the trigger can no longer poll the mailbox and the flow stops firing.

Why this answer

The flow uses the 'When a new email arrives' trigger, which relies on a connection to the shared mailbox. When an admin changes mailbox permissions, the existing connection loses its authorization to access the mailbox, causing the trigger to fail. This is the most direct cause because the connection object in Power Automate must have valid permissions to read emails from the specified mailbox.

Exam trap

The trap here is that candidates may confuse a permissions issue with a storage limit or license problem, but the trigger's dependency on a valid connection object makes permission changes the immediate and most likely cause.

How to eliminate wrong answers

Option A is wrong because exceeding the mailbox storage limit would cause new emails to be rejected or bounce, but the flow trigger would still attempt to run and fail with a different error (e.g., mailbox full), not a permissions-related failure. Option C is wrong because deleting the flow owner's Power Automate license would disable the flow entirely or prevent it from being saved/run, but the scenario specifies the flow stopped working after a permissions change, not a license change. Option D is wrong because transferring the flow to another owner does not inherently break the mailbox connection; the new owner would need to re-authenticate, but the trigger failure is directly tied to the permissions change, not ownership transfer.

501
MCQmedium

A financial services firm needs to create a compliance dashboard for regulators. The dashboard must display real-time data from multiple sources, including on-premises SQL Server and Dataverse. The firm requires interactive visualizations and the ability to drill down to transaction details. They also need to ensure that sensitive data is masked for certain users. Which Power Platform components should they use?

A.Power Automate, AI Builder, and Power BI
B.Power BI, on-premises data gateway, and Dataverse
C.Copilot Studio, Power BI, and Dataverse
D.Power Apps, Dataverse, and Power Automate
AnswerB

Power BI provides dashboards with RLS, gateway connects to on-premises SQL, Dataverse is another data source.

Why this answer

The scenario requires real-time data from on-premises SQL Server and Dataverse, which necessitates an on-premises data gateway for live connectivity. Power BI provides the interactive visualizations and drill-down capabilities, while Dataverse serves as the unified data source for compliance data. The combination of these components enables real-time dashboards with role-based security for data masking.

Exam trap

The trap here is that candidates often confuse Power Automate or Power Apps as dashboard tools, but the question specifically requires interactive visualizations and drill-downs, which are core Power BI capabilities, not automation or app-building features.

How to eliminate wrong answers

Option A is wrong because Power Automate is a workflow automation tool, not a data visualization or dashboard component, and AI Builder is for AI model integration, not real-time data masking or drill-downs. Option C is wrong because Copilot Studio is designed for building conversational AI bots, not for creating compliance dashboards or handling data masking. Option D is wrong because Power Apps is for building custom applications, not for interactive visualizations or drill-down analytics, and Power Automate does not provide dashboard capabilities.

502
MCQeasy

You need to create a flow that sends an email notification when a new file is added to a OneDrive for Business folder. Which trigger should you use?

A.When a file is created (SharePoint)
B.When a file is modified (OneDrive for Business)
C.When a file is created (OneDrive for Business)
D.When a file is created (OneDrive)
AnswerC

The OneDrive for Business 'When a file is created' trigger fires whenever a new file appears in the specified folder, satisfying the requirement to notify on file addition. It polls the chosen folder and passes file metadata to subsequent actions.

Why this answer

The requirement specifies a OneDrive for Business folder, and the 'When a file is created (OneDrive for Business)' trigger is the only one that directly monitors a OneDrive for Business location for new file additions. This trigger uses the OneDrive for Business connector, which is designed to work with the Microsoft Graph API for OneDrive for Business, and it fires specifically when a new file is created, not modified.

Exam trap

The trap here is that candidates confuse the 'OneDrive' and 'OneDrive for Business' connectors, assuming they are interchangeable, but they target different services with different authentication and API scopes.

How to eliminate wrong answers

Option A is wrong because the 'When a file is created (SharePoint)' trigger monitors SharePoint document libraries, not OneDrive for Business folders; using it would require a SharePoint site and library, which is a different storage service. Option B is wrong because the 'When a file is modified (OneDrive for Business)' trigger fires when an existing file is changed, not when a new file is added, so it does not meet the requirement to trigger on file creation. Option D is wrong because the 'When a file is created (OneDrive)' trigger targets the consumer OneDrive service (personal Microsoft account), not OneDrive for Business (work or school account), and these are separate connectors with different authentication and API endpoints.

503
MCQmedium

You have a model-driven app that includes a custom table. You need to add a field that calculates a value based on other fields (e.g., total price = quantity * unit price). Which type of field should you create?

A.Calculated field
B.Text field
C.Choice field
D.Rollup field
AnswerA

A calculated field derives its value at read time from other columns using a defined formula, so quantity multiplied by unit price updates automatically whenever either source field changes, with no workflow or plug-in required.

Why this answer

A Calculated field in Dataverse computes its value at runtime using a formula that references other columns in the same table, such as quantity * unit price. It is read-only and automatically updates when the referenced fields change. This matches the requirement for a field that derives its value from other fields.

Exam trap

PL-900 often confuses Calculated fields with Rollup fields; candidates may pick Rollup because it also 'calculates', but Rollup aggregates related records, not fields on the same row.

How to eliminate wrong answers

Option B is wrong because a Text field stores static alphanumeric data and cannot perform calculations. Option C is wrong because a Choice field provides a dropdown list of predefined options and does not compute values. Option D is wrong because a Rollup field aggregates data from related records (e.g., sum of child records) rather than performing row-level calculations on the same record.

504
MCQmedium

You are reviewing a Power Automate flow definition. The exhibit shows an action definition. What is the action doing?

A.Sending an email to multiple recipients.
B.Sending an email with an attachment.
C.Checking if a condition is true before sending.
D.Sending an email to a single recipient.
AnswerD

The action definition specifies a single recipient address in its To field, so the connector sends one email to that address. This satisfies the exhibit's requirement, rather than sending to multiple recipients or a distribution list.

Why this answer

The action definition in the exhibit shows a single 'To' field populated with one address, which corresponds to sending an email to a single recipient. Power Automate's 'Send an email' action uses a semicolon-separated list for multiple recipients, and the exhibit does not show multiple addresses or an attachment. Therefore the action is a single-recipient email send.

Exam trap

PL-900 often tests whether candidates can read a flow action definition literally — the trap is assuming an email action must be multi-recipient or include attachments when the exhibit shows only a single To address.

How to eliminate wrong answers

Option A is wrong because sending to multiple recipients would require multiple addresses in the To field (or CC/BCC), which the exhibit does not show. Option B is wrong because sending an attachment requires an 'Attachments' property with file content, which is absent from the action definition. Option C is wrong because a condition check would be represented by a 'Condition' action or an 'If' block, not by an email action definition.

505
MCQeasy

A business analyst wants to create a simple expense report app without writing code. The app should allow users to submit expenses and managers to approve or reject them. Which type of Power App should the analyst use?

A.Canvas app
B.Power Pages
C.Copilot Studio
D.Model-driven app
AnswerA

Canvas apps offer a drag-and-drop designer with no code, and their flexible layout suits a form-based submission and approval flow. This satisfies the requirement for a no-code expense app where users submit and managers approve or reject.

Why this answer

A canvas app is ideal for building a simple expense report app without writing code. It allows the maker to drag and drop controls, connect to data sources, and design a custom user interface. Canvas apps are well-suited for task-specific apps like expense submission and approval.

Exam trap

PL-900 often tests when to use canvas vs model-driven apps, and candidates may choose model-driven because it sounds more robust, but for simple, custom UI apps, canvas is the correct choice.

How to eliminate wrong answers

Option B is wrong because Power Pages is for creating external-facing websites, not for internal expense reporting. Option C is wrong because Copilot Studio is for building conversational AI bots, not for creating data-centric apps. Option D is wrong because model-driven apps are data-first and require a Dataverse data model, which may be overkill for a simple expense app and typically involves more configuration than a canvas app.

506
MCQeasy

A company wants to build a custom copilot that answers questions about its internal travel policy. The policy content already lives in a public-facing website that the company maintains. The copilot must ground its answers in that website's content and require no manual data uploads. What should you configure in Microsoft Copilot Studio?

A.Publish the copilot to Microsoft Teams and enable the Teams channel.
B.Add the website URL as a knowledge source for the copilot.
C.Enable the copilot's authentication setting so users sign in with Microsoft Entra ID.
D.Create a Power Automate cloud flow that emails the policy PDF to users on request.
AnswerB

Copilot Studio supports website knowledge sources, so the copilot can crawl the public site and ground responses in its pages without uploading files. This matches the requirement of using existing website content with no manual data preparation, and it keeps answers current as the site is updated.

Why this answer

Grounding a copilot in existing content is done by adding knowledge sources, and a public website URL is a supported source in Copilot Studio. The copilot can then retrieve relevant passages from the site when users ask travel-policy questions. Publishing channels, sending email, or enabling sign-in do not provide the content needed for accurate answers.

Exam trap

The trap here is assuming that publishing or authentication settings add knowledge, when the copilot only answers from content you explicitly connect as a knowledge source.

507
MCQeasy

A nonprofit organization needs to track donations and volunteers using a custom app without writing code. Which Power Platform tool should they use?

A.Power BI
B.Power Pages
C.Power Automate
D.Power Apps
AnswerD

Power Apps provides a low-code canvas and model-driven designer, letting the nonprofit build a custom donation and volunteer tracking app through drag-and-drop controls and connectors. No traditional coding is required, directly meeting the no-code custom app constraint.

Why this answer

Power Apps is Microsoft's low-code/no-code application development platform, letting makers build canvas or model-driven apps with drag-and-drop controls, connectors to Dataverse/SharePoint/SQL, and no traditional programming. For a nonprofit tracking donations and volunteers, Power Apps provides the data-entry forms, views, and business logic needed without writing code. Power BI, Power Pages, and Power Automate serve analytics, external websites, and workflow automation respectively—not custom app creation.

Exam trap

PL-900 often tests the boundary between the four Power Platform pillars—candidates pick Power Automate or Power Pages because the scenario mentions 'tracking' or 'volunteers,' but only Power Apps is the app-building tool.

How to eliminate wrong answers

Option A is wrong because Power BI is a business analytics and visualization tool for dashboards and reports, not a platform for building data-entry applications. Option B is wrong because Power Pages is for building secure, externally facing business websites (portals) with Dataverse, not internal tracking apps. Option C is wrong because Power Automate is a workflow/RPA engine that automates actions between services; it can support an app but cannot itself be the custom app the nonprofit needs.

508
MCQhard

You are troubleshooting a Power Automate flow that uses an HTTP action to call a REST API. The flow fails with a '429 Too Many Requests' error. The API has a rate limit of 100 requests per minute. Which strategy should you implement to handle this error gracefully?

A.Implement retry logic with exponential backoff in the HTTP action settings.
B.Increase the flow's concurrency setting to process more requests simultaneously.
C.Use a 'Condition' action to check the status code and ignore 429 errors.
D.Use the 'Configure Run After' option to skip the action on failure.
AnswerA

Exponential backoff spaces retries progressively, so the flow waits out the 100-requests-per-minute window rather than hammering the API. This satisfies the rate-limit constraint by letting the HTTP action retry after throttling clears, avoiding repeated 429 failures.

Why this answer

Implementing retry logic with exponential backoff allows the flow to automatically retry the request after a delay that increases with each attempt, which is the standard approach to handle rate limiting (HTTP 429 errors) and reduces server load. Option B is wrong because increasing concurrency would send more requests simultaneously, likely exacerbating the rate limit issue. Option C is wrong because simply ignoring 429 errors means requests are not retried and the action fails.

Option D is wrong because 'Configure Run After' can handle failures but does not implement backoff, so it would not effectively manage rate limits.

509
MCQhard

An organization plans to deploy a Power Platform solution that uses Dataverse as the data source. They need to ensure that users can only see records from their own department. What should they implement?

A.Power Automate to filter records
B.Audit logging
C.Column-level security profiles
D.Business units and security roles with team-based access
AnswerD

Business units partition users and records by department, while security roles grant read, write, and delete privileges at that scope. Team-based ownership then shares records within the department, restricting visibility so users see only their own department's data.

Why this answer

Business units and security roles with team-based access are the correct implementation because Dataverse uses a hierarchical security model where business units define the organizational structure and security roles control record-level permissions. By configuring business units per department and assigning users to teams within those units, you can enforce that users only see records belonging to their own department through record ownership and sharing rules.

Exam trap

The trap here is that candidates confuse column-level security (which controls field visibility) with record-level security (which controls row visibility), leading them to choose option C when the requirement is about seeing entire records from their own department.

How to eliminate wrong answers

Option A is wrong because Power Automate is an automation tool, not a data access control mechanism; filtering records via a flow would be inefficient, bypass security model enforcement, and could be circumvented by direct API queries. Option B is wrong because audit logging tracks who accessed or modified records but does not restrict visibility; it is a monitoring feature, not a permission control. Option C is wrong because column-level security profiles restrict access to specific columns (fields) within a record, not to entire records; they cannot limit which rows a user sees based on department.

510
Multi-Selecteasy

Which TWO of the following are benefits of using Microsoft Power Platform for business users?

Select 2 answers
A.Reduced dependency on IT for simple solutions.
B.Citizen developers can build apps without writing code.
C.Ability to use custom code in production environments.
D.Automatic generation of revenue from builds.
AnswersA, B

Power Platform's low-code makers build apps, flows and dashboards themselves, so routine business solutions no longer queue behind IT development backlogs. This reduces dependency on IT for simple solutions while IT retains governance through environments and DLP policies.

Why this answer

Option A is correct because Power Platform's low-code/no-code tools (Power Apps, Power Automate, Power BI, Power Virtual Agents) let business users create simple apps, flows, and reports themselves, reducing the backlog and dependency on IT for routine solutions. Option B is correct because citizen developers can use drag-and-drop designers, prebuilt connectors, and templates to build apps and automations without writing traditional code. Option C is not a benefit specific to Power Platform for business users; custom code (e.g., plug-ins, Azure Functions, PCF controls) is typically a pro-dev capability and is not the primary advantage for citizen developers.

Option D is incorrect because Power Platform is a development and automation tool, not a mechanism that automatically generates revenue from builds.

Exam trap

PL-900 often tests the misconception that Power Platform is a revenue-generating tool or that custom code is its main benefit, when the real value is no-code empowerment and reduced IT dependency.

511
MCQmedium

A company wants its Copilot Studio copilot to perform a series of steps in an external system when a user requests a new laptop. The steps include creating a ticket, assigning it, and sending a confirmation. The company already has a Power Automate cloud flow that performs these steps. What should the maker do to let the copilot trigger this flow?

A.Create a custom connector that wraps the flow and add it as a skill.
B.Add the flow as a knowledge source to the copilot.
C.Embed the flow in a Power Apps canvas app and link the app to the copilot.
D.Call the flow from a topic using the Call an action node.
AnswerD

Copilot Studio allows makers to call Power Automate flows from within a topic using the Call an action node. This node can pass variables to the flow and receive outputs. By invoking the existing flow this way, the copilot can execute the ticket creation and confirmation steps when the user requests a laptop, which directly meets the requirement.

Why this answer

Copilot Studio integrates with Power Automate through the Call an action node, which lets a topic invoke a cloud flow and exchange data. This is the standard method to have a copilot perform automated steps such as creating tickets. The other options misplace the flow as a knowledge source, add unnecessary custom connector work, or introduce an intermediary app that does not directly trigger the flow.

Exam trap

The trap here is thinking that a Power Automate flow must be wrapped in a custom connector or knowledge source to be used by a copilot, when Copilot Studio has a built-in Call an action node for flows.

512
MCQeasy

An organization wants to enable Microsoft Copilot Studio (formerly Power Virtual Agents) to answer questions from employees about company policies. The chatbot must only use internal company documents stored in SharePoint as its knowledge source. Which configuration should the administrator use?

A.Enable the 'Use generative AI' feature in the Power Platform admin center
B.Deploy a custom connector to SharePoint
C.Create a Power Automate flow to fetch data from SharePoint and pass it to the chatbot
D.Add a SharePoint knowledge source in Copilot Studio and configure authentication to use the company's Microsoft Entra ID
AnswerD

Copilot Studio's SharePoint knowledge source indexes only the specified internal document libraries, and Microsoft Entra ID authentication ensures the bot queries content the signed-in employee is permitted to see. This confines answers to company policy documents rather than public web results.

Why this answer

Microsoft Copilot Studio allows administrators to add SharePoint as a knowledge source directly, enabling the chatbot to retrieve answers from internal documents without custom development. Configuring authentication with Microsoft Entra ID ensures that only authorized users can access the company policies, maintaining security and compliance.

Exam trap

The trap here is that candidates may overcomplicate the solution by thinking a custom connector or Power Automate flow is required, when in fact Copilot Studio's native SharePoint integration handles the connection directly.

How to eliminate wrong answers

Option A is wrong because the 'Use generative AI' feature in the Power Platform admin center is a tenant-level setting that enables AI capabilities across environments, but it does not directly connect a chatbot to SharePoint documents as a knowledge source. Option B is wrong because deploying a custom connector to SharePoint is unnecessary and overly complex; Copilot Studio natively supports SharePoint as a knowledge source without requiring custom connectors. Option C is wrong because creating a Power Automate flow to fetch data from SharePoint and pass it to the chatbot introduces unnecessary latency and complexity, whereas Copilot Studio can directly query SharePoint using its built-in integration.

513
MCQhard

A Power Platform administrator is configuring data loss prevention (DLP) policies. The company uses Power Automate flows that connect to Microsoft SharePoint and Microsoft Teams. The security team wants to block any flow from sending data from SharePoint to unsanctioned third-party services. Which DLP policy configuration should the administrator apply?

A.Create a policy that only applies to non-production environments
B.Classify SharePoint as Business and all third-party services as Blocked
C.Classify SharePoint as Business and all third-party services as Non-Business
D.Classify all connectors as Blocked
AnswerB

Classifying SharePoint as Business and third-party services as Blocked satisfies the stem's constraint: DLP connector classification prevents cross-group data movement. Power Automate blocks any flow combining a Business connector with a Blocked connector, so SharePoint data cannot reach unsanctioned services. Blocked connectors are excluded entirely, enforcing the security team's requirement.

Why this answer

DLP policies in Power Platform allow administrators to classify connectors into Business, Non-Business, and Blocked categories. By classifying SharePoint as Business and all third-party services as Blocked, the administrator ensures that no flow can send data from SharePoint to unsanctioned third-party connectors, as blocked connectors cannot be used in any flow that also uses a Business connector. This directly enforces the security team's requirement to prevent data exfiltration to unsanctioned services.

Exam trap

The trap here is that candidates often confuse 'Non-Business' with 'Blocked', not realizing that Non-Business connectors can still be used in flows alongside Business connectors, whereas only the Blocked category prevents data from being sent to those services entirely.

How to eliminate wrong answers

Option A is wrong because applying a policy only to non-production environments would not protect production flows that connect SharePoint to unsanctioned third-party services, leaving the security requirement unmet. Option C is wrong because classifying third-party services as Non-Business would still allow flows to use both Business (SharePoint) and Non-Business connectors in the same flow, which does not block data from being sent to those services—only the 'Blocked' category prevents connector usage entirely. Option D is wrong because classifying all connectors as Blocked would prevent all flows from using any connector, including SharePoint and Teams, which would break legitimate business flows and is not the targeted restriction the security team requires.

514
Multi-Selecthard

Which THREE components are part of Power Apps Studio for building Canvas apps? (Choose three.)

Select 3 answers
A.Formula bar
B.Solution Explorer
C.Tree view
D.Property pane
E.Report Designer
AnswersA, C, D

The formula bar sits directly beneath the ribbon in Power Apps Studio, letting makers write and edit Power Fx expressions that drive control behaviour and properties. It satisfies the stem's requirement for a genuine Canvas app authoring component, unlike data connectors or environment settings, which belong elsewhere in the platform.

Why this answer

The Formula bar (A) is a core Power Apps Studio component where makers write Power Fx expressions for controls and properties, making it essential for building Canvas apps. The Tree view (C) is also part of Power Apps Studio, providing a hierarchical list of screens, controls, and components so makers can select, reorder, and manage app elements. The Property pane (D) is the third correct component, allowing configuration of selected controls' properties such as text, color, size, and behavior directly in the authoring interface.

Solution Explorer (B) is not a Power Apps Studio Canvas app builder component; it belongs to solution management experiences in Power Platform. Report Designer (E) is not part of Power Apps Studio either; reporting and paginated report design are handled by Power BI Report Builder or related reporting tools.

Exam trap

The trap is confusing Power Apps Studio's authoring panes with broader Power Platform tooling — candidates who have used Power BI may incorrectly select 'Report Designer,' and those familiar with the maker portal may pick 'Solution Explorer.'

515
MCQmedium

A user created a canvas app to collect feedback. The app writes data to an Excel file stored in OneDrive. When multiple users submit feedback simultaneously, some entries are lost. What is the most likely cause?

A.The app has a performance issue
B.The Excel file is locked by OneDrive sync
C.A Power Automate flow is delaying the write
D.Excel is not designed for concurrent multi-user writes
AnswerD

Excel locks the workbook during each write, so simultaneous submissions collide and later writes overwrite earlier ones, losing entries. This satisfies the stem's concurrency constraint: Excel is a single-user file format, not a transactional datastore. Migrating to Microsoft Dataverse or SharePoint lists would preserve every submission.

Why this answer

Excel files stored in OneDrive are not designed for concurrent multi-user writes; when multiple users submit simultaneously, the file locking and sync behavior can cause writes to overwrite each other or fail silently, leading to lost entries. This is a fundamental limitation of using Excel as a database for multi-user apps.

Exam trap

PL-900 often tests the misconception that Excel is a suitable multi-user database, when the exam expects you to recognize its concurrency limitations and recommend Dataverse or SharePoint instead.

How to eliminate wrong answers

Option A is wrong because a performance issue would cause slowness or timeouts, not silent data loss from concurrent writes. Option B is wrong because OneDrive sync locking may cause temporary failures, but the root cause of lost entries under simultaneous submissions is Excel's lack of concurrency control, not sync locking alone. Option C is wrong because a Power Automate flow delay would not cause data loss; it would only delay processing, and the scenario does not mention a flow.

516
Multi-Selecteasy

Which TWO of the following data sources can be used directly in a canvas app without using a gateway? (Choose TWO.)

Select 2 answers
A.On-premises SQL Server
B.On-premises Oracle Database
C.On-premises SAP HANA
D.Dataverse
E.SharePoint Online
AnswersD, E

Dataverse connects natively through the built-in connector, so canvas apps query tables directly without an on-premises data gateway. The gateway requirement applies only to sources behind a network boundary, which Dataverse is not, satisfying the stem's "without using a gateway" constraint.

Why this answer

Option D, Dataverse, is correct because it is a cloud-hosted Microsoft Power Platform service that canvas apps connect to natively through the built-in Dataverse connector, so no on-premises data gateway is required. Option E, SharePoint Online, is correct because it is a Microsoft 365 cloud service accessed directly via the standard SharePoint connector in Power Apps, again without any gateway. Options A (on-premises SQL Server), B (on-premises Oracle Database), and C (on-premises SAP HANA) are all on-premises systems, so reaching them from a canvas app requires installing and configuring an on-premises data gateway to bridge the cloud service to the local network.

Exam trap

PL-900 often tests the cloud-versus-on-premises distinction by listing familiar data sources (SQL, Oracle, SAP) that sound modern but are on-prem, tricking candidates who assume any database connector works without a gateway.

517
MCQhard

An organization is building a model-driven app on Dataverse. They need to ensure that only managers can delete records, and all other users can only edit them. What should be configured?

A.Add a business rule that checks user role before delete
B.Implement a Power Automate flow that cancels delete
C.Use a business process flow to restrict delete
D.Create custom security roles with different privileges for managers and others
AnswerD

Security roles define privilege levels per entity, including Delete versus Write, and can be assigned to teams or users. Managers receive a role granting Delete; others receive a role with Write but no Delete, precisely satisfying the stated constraint.

Why this answer

Custom security roles in Dataverse define privileges at the entity level, including Create, Read, Write, Delete, Append, and Append To, with access levels (User, Business Unit, Parent: Child Business Unit, Organization). By creating separate roles for managers and other users, you can grant Delete only to managers while giving others Write access. This is the native, supported way to enforce record-level permissions.

Exam trap

PL-900 often tests the misconception that business rules or flows can enforce security — candidates pick them because they sound like guardrails, but only security roles control record-level privileges.

How to eliminate wrong answers

Option A is wrong because business rules cannot check the current user's security role at runtime — they operate on field values and entity logic, not role membership. Option B is wrong because Power Automate flows run asynchronously and cannot reliably prevent a delete; they can react to it but not block it in real time. Option C is wrong because business process flows guide users through stages of a process; they have no mechanism to restrict delete operations.

518
MCQeasy

A hospital uses Power Apps to manage patient intake forms. The app stores data in Microsoft Dataverse. The security policy requires that patient health information (PHI) be encrypted at rest and in transit. The environment is already configured with default Dataverse settings. The IT admin needs to ensure compliance. What should the admin do?

A.Enable customer-managed encryption keys for Dataverse.
B.No further action is needed; Dataverse encrypts data at rest and in transit by default.
C.Configure a VPN for all access to the environment.
D.Use Power Automate to encrypt data before storing it in Dataverse.
AnswerB

Microsoft Dataverse encrypts data at rest using transparent data encryption and secures data in transit with TLS by default, so the existing environment already satisfies the PHI encryption policy. No additional configuration is required to meet the stated compliance requirement.

Why this answer

Microsoft Dataverse encrypts all data at rest using SQL Server Transparent Data Encryption (TDE) and AES-256, and encrypts data in transit using TLS 1.2 or higher by default. Because the environment already uses default Dataverse settings, the encryption-at-rest and in-transit requirements for PHI are already satisfied without any additional configuration. Customer-managed keys are an optional compliance enhancement, not a baseline requirement.

Exam trap

PL-900 often tests the misconception that encryption must be manually enabled in Power Platform services, when in fact Dataverse encrypts data at rest and in transit by default.

How to eliminate wrong answers

Option A is wrong because customer-managed encryption keys (CMK) are an optional feature for organizations that require control over the key lifecycle for regulatory reasons — they are not needed to achieve encryption at rest, which is already on by default. Option C is wrong because a VPN secures network access paths but does not provide encryption at rest, and Dataverse traffic is already TLS-encrypted. Option D is wrong because Power Automate cannot encrypt data before it is stored in Dataverse in a way that satisfies at-rest encryption — Dataverse already handles encryption transparently at the storage layer.

519
Multi-Selecthard

Which THREE of the following are valid ways to customize the appearance and behavior of a Power Pages site?

Select 3 answers
A.Include JavaScript for interactive features
B.Add custom CSS via the Design Studio
C.Embed Power BI reports to change site navigation
D.Create Power Automate flows to change the site theme
E.Use Liquid template language to add dynamic content
AnswersA, B, E

JavaScript runs client-side in the browser, so it adds interactive behaviour such as validation, dynamic show/hide logic and custom event handling. This is a supported customisation method in Power Pages, distinct from server-side Liquid rendering or CSS styling.

Why this answer

Option A is correct because Power Pages allows you to add custom JavaScript to web pages and web templates, enabling interactive client-side features such as dynamic form behavior, animations, and custom validation. Option B is correct because the Design Studio (now part of the Power Pages design experience) lets you apply custom CSS to control colors, fonts, spacing, and other visual styling of the site. Option E is correct because Power Pages uses the Liquid template language in web templates and content snippets to render dynamic content, such as pulling data from Dataverse tables or conditionally displaying markup.

Option C is not correct because embedding Power BI reports is a content/analytics feature and does not change site navigation. Option D is not correct because Power Automate flows automate business processes and cannot modify a site's theme.

520
MCQeasy

A Power Platform administrator needs to provide a team of makers with a shared environment that includes a pre-installed Microsoft Dataverse database and sample apps. The environment should be available to all team members without requiring them to create their own. What should the administrator do?

A.Instruct each team member to create their own personal environment and then share their apps with the team.
B.Use the default environment and enable the 'Sample apps' feature in the Power Platform admin center.
C.Create a Microsoft 365 group and enable Power Apps for the group, which automatically provisions a Dataverse database.
D.Create a new environment in the Power Platform admin center, select 'Yes' for 'Create a database for this environment?', and then assign the 'Environment Maker' security role to the team members.
AnswerD

Creating a new environment with a Dataverse database provides the shared data storage and sample apps. Assigning the Environment Maker security role grants the team members the ability to create apps, flows, and other resources within that environment. This approach directly satisfies the requirement for a shared environment with a database and maker access.

Why this answer

A shared environment with a Dataverse database is created explicitly in the Power Platform admin center by selecting the option to create a database. Assigning the Environment Maker role to team members grants them the necessary permissions to build resources in that environment. Personal environments and the default environment are not suitable for controlled team collaboration with a dedicated database.

Exam trap

The trap here is thinking that personal environments or the default environment can serve as a shared team environment with a Dataverse database, when a dedicated environment must be provisioned explicitly.

521
MCQmedium

Refer to the exhibit. A Power Apps app uses Dataverse with the defined table and roles. An employee reports that they can see all assets in the app, but they should only see assets assigned to them. What is the most likely reason?

A.The Employee security role has 'Read' permission set to 'Organization' scope instead of 'User'
B.The Asset table does not have a relationship to the User table
C.The employee is not the owner of the asset records
D.The app is not configured to filter records based on the current user
AnswerA

The Employee role grants Read at Organization scope, which lets the user view every asset record regardless of ownership. Changing that privilege to User scope restricts visibility to records they own or are shared, matching the requirement to see only assigned assets.

Why this answer

The Employee security role's 'Read' permission is set to 'Organization' scope, which allows the employee to see all asset records in the Dataverse table. To restrict visibility to only assets assigned to the employee, the 'Read' permission should be set to 'User' scope, which limits record access to those the user owns or is assigned to. This is a common misconfiguration in Dataverse role-based security that directly causes the reported issue.

Exam trap

The trap here is that candidates often assume the app must explicitly filter records (Option D) or that a table relationship is needed (Option B), when in fact Dataverse's built-in security role scopes handle record-level visibility automatically without custom app logic.

How to eliminate wrong answers

Option B is wrong because a relationship between the Asset table and the User table is not required for row-level security; Dataverse uses security roles and ownership to control record visibility, not table relationships. Option C is wrong because the employee not being the owner of the asset records is the symptom, not the root cause; the underlying issue is that the security role's 'Read' scope is too permissive (Organization), which overrides ownership-based filtering. Option D is wrong because the app itself does not need to filter records based on the current user if the Dataverse security role is correctly configured with 'User' scope; the platform enforces the scope automatically at the data layer.

522
MCQeasy

A healthcare organization needs a Power Apps app to track patient visit data. The data must be stored in Microsoft Dataverse, and the app should automatically generate a timeline of visits for each patient. Which app type is most suitable?

A.Portal
B.Model-driven app
C.Power Automate
D.Canvas app
AnswerB

Model-driven apps render Dataverse tables as forms, views and dashboards, and the timeline control automatically surfaces related visit records for each patient. This satisfies the Dataverse storage and auto-generated timeline constraints without custom canvas coding.

Why this answer

A model-driven app is the most suitable choice because it is designed for complex, data-centric business applications that require rich relational data modeling, automated business logic, and built-in timeline controls. Dataverse provides the underlying relational storage, and model-driven apps natively support timeline components that automatically aggregate and display patient visit records in chronological order without custom development.

Exam trap

The trap here is that candidates often choose Canvas app because they think custom UI is needed for a timeline, but model-driven apps already include a native timeline component that automatically binds to Dataverse relationships, making it the correct choice for structured data tracking.

How to eliminate wrong answers

Option A is wrong because a Portal app is intended for external-facing, anonymous or authenticated user access (e.g., patient self-service), not for internal staff to track and manage patient visit data with a timeline. Option C is wrong because Power Automate is a workflow automation tool, not an app type; it can trigger actions but cannot serve as the primary user interface for data entry and timeline visualization. Option D is wrong because a Canvas app provides pixel-perfect custom UI but lacks the built-in timeline control and automatic Dataverse relationship handling that model-driven apps offer, requiring manual implementation of timeline functionality.

523
Multi-Selecthard

Which THREE components are part of Microsoft Power Platform? (Choose three.)

Select 3 answers
A.Power BI
B.Power Automate
C.Dynamics 365
D.Microsoft Copilot Studio
E.Power Apps
AnswersA, B, E

Power BI belongs to Microsoft Power Platform, satisfying the stem's requirement for a genuine platform component. It delivers business analytics and interactive reporting, sharing the platform's common connector and Dataverse foundations with Power Apps, Power Automate and Power Pages. This confirms it as one of the three correct selections.

Why this answer

Power BI (A) is a core Power Platform component, providing business analytics and interactive dashboards that connect to data sources and publish reports. Power Automate (B) is also part of the platform, delivering workflow and robotic process automation across services via triggers, actions, and connectors. Power Apps (E) is the third core component, enabling low-code/no-code canvas, model-driven, and portal app development on top of Dataverse and other connectors.

Dynamics 365 (C) is a separate family of business applications that integrates with Power Platform but is not itself one of its components. Microsoft Copilot Studio (D) is a conversational AI/agent-building tool that extends the platform ecosystem but is not counted among the three core Power Platform components.

Exam trap

Candidates often mistakenly include Dynamics 365 or Microsoft Copilot Studio as core components. However, the PL-900 exam defines the core components as Power BI, Power Apps, and Power Automate. Dynamics 365 is a separate application built on Power Platform, and Copilot Studio is an AI tool that can integrate but is not a core component.

524
MCQeasy

A marketing department wants to create a dashboard that shows real-time social media sentiment analysis. Which Power Platform tool should they use?

A.Power Automate
B.Power BI
C.Power Apps
D.Copilot Studio
AnswerB

Power BI connects to streaming datasets and renders sentiment data visually in real time, satisfying the live dashboard requirement. Power Apps builds transactional interfaces and Power Automate orchestrates workflows; neither provides the analytical visualisation layer the marketing department needs.

Why this answer

Power BI is the correct tool because it is designed for data visualization and real-time analytics, including the ability to connect to social media APIs (e.g., Twitter, Facebook) via built-in connectors or custom streaming datasets to display sentiment analysis dashboards. It supports real-time data refresh through DirectQuery or streaming datasets, making it ideal for monitoring live social media sentiment.

Exam trap

The trap here is that candidates may confuse Power Automate's ability to trigger actions based on sentiment (e.g., send an alert) with the dashboarding and visualization capabilities required for the question, leading them to choose Power Automate instead of Power BI.

How to eliminate wrong answers

Option A is wrong because Power Automate is a workflow automation tool for triggering actions (e.g., sending emails, posting messages) based on events, not for building interactive dashboards or performing real-time sentiment analysis. Option C is wrong because Power Apps is a low-code application development platform for building custom apps with forms and logic, not for creating data visualizations or dashboards with live streaming data. Option D is wrong because Copilot Studio is used to create custom copilots (AI-powered conversational agents) and does not provide dashboarding or real-time analytics capabilities for social media sentiment.

525
MCQhard

Your organization uses Power Automate to automate onboarding processes. The flow creates a user in Microsoft Entra ID, assigns licenses, and sends a welcome email. Recently, the flow failed because the 'Create user' action returned 'PrivilegedOperationNotAllowed'. What is the most likely cause?

A.The user already exists in the directory
B.The flow is using an expired connection
C.The service principal lacks required permissions in Microsoft Entra ID
D.The flow has exceeded API rate limits
AnswerC

PrivilegedOperationNotAllowed indicates the connection's service principal lacks the Microsoft Entra ID permission required by the Create user action, such as User.ReadWrite.All with admin consent granted. Insufficient Graph API authorisation causes the directory write to be rejected.

Why this answer

The error 'PrivilegedOperationNotAllowed' from the 'Create user' action in Power Automate indicates that the connection or service principal used by the flow lacks the required Microsoft Graph permissions (such as User.ReadWrite.All or Directory.ReadWrite.All) in Microsoft Entra ID. This is a permissions issue, not a data or rate-limit issue. The service principal must be granted admin consent for the necessary Graph scopes.

Exam trap

The trap is confusing authorization errors with other failure modes — candidates often pick 'user already exists' or 'rate limits' because those are common flow failures, but 'PrivilegedOperationNotAllowed' is a specific Microsoft Graph permissions error that points to missing Entra ID roles or Graph scopes.

How to eliminate wrong answers

Option A is wrong because if the user already exists, the error would typically be a conflict or 'user already exists' message, not 'PrivilegedOperationNotAllowed'. Option B is wrong because an expired connection would produce an authentication or connection error, not a privileged operation error — the flow would fail at the connection level before reaching the action. Option D is wrong because API rate limits produce HTTP 429 'Too Many Requests' errors, not 'PrivilegedOperationNotAllowed', which is specifically a permissions/authorization error from Microsoft Graph.

Page 6

Page 7 of 10

Page 8

All pages