Courseiva

PL-900 Demonstrate the capabilities of Power Apps Practice Question

An organization is building a model-driven app on Dataverse. They need to ensure that only managers can delete records, and all other users can only edit them. What should be configured?

⚠ Common exam trap

PL-900 often tests the misconception that business rules or flows can enforce security — candidates pick them because they sound like guardrails, but only security roles control record-level privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create custom security roles with different privileges for managers and others

Custom security roles in Dataverse define privileges at the entity level, including Create, Read, Write, Delete, Append, and Append To, with access levels (User, Business Unit, Parent: Child Business Unit, Organization). By creating separate roles for managers and other users, you can grant Delete only to managers while giving others Write access. This is the native, supported way to enforce record-level permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a business rule that checks user role before delete

    Why it's wrong here

    Business rules run client-side on form events and cannot evaluate security roles for delete operations; they also do not fire on deletes performed outside the form. Tempting because business rules commonly enforce field-level logic, and would suit validation or field visibility, but record deletion is controlled by Dataverse security roles with Delete privilege.

  • ✗

    Implement a Power Automate flow that cancels delete

    Why it's wrong here

    A Power Automate flow triggers after the delete request is processed, so it cannot prevent the deletion; cancellation requires a pre-operation plug-in. Tempting because flows automate Dataverse events, and would be correct for notifications or downstream updates, but privilege enforcement belongs to Dataverse security roles.

  • ✗

    Use a business process flow to restrict delete

    Why it's wrong here

    Business process flows guide users through stages of a defined process and cannot grant or deny delete privileges. Tempting because they shape record progression in model-driven apps, and would be correct for enforcing a structured sequence of stages, but delete permission is set by Dataverse security roles, not process design.

  • ✓

    Create custom security roles with different privileges for managers and others

    Why this is correct

    Security roles define privilege levels per entity, including Delete versus Write, and can be assigned to teams or users. Managers receive a role granting Delete; others receive a role with Write but no Delete, precisely satisfying the stated constraint.

About these practice questions

This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.