Courseiva

PL-900 Practice Question: Describe the business value of Microsoft Power Platform

An organization is using Microsoft Power Platform to build a compliance solution. They need to ensure that sensitive data in Dataverse is encrypted at rest and that access is audited. Which feature should they enable?

⚠ Common exam trap

Candidates often confuse Data Loss Prevention (DLP) policies with data protection at rest, but DLP only governs data movement and does not provide encryption or auditing of stored data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer-managed encryption key (CMK) and Audit logging

Customer-managed encryption key (CMK) provides control over the encryption key used to encrypt data at rest in Dataverse, ensuring sensitive data is encrypted with a key managed by the organization. Audit logging records all access and changes to data, enabling compliance auditing. Together, they directly address the requirements for encryption at rest and access auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data Loss Prevention (DLP) policies

    Why it's wrong here

    DLP policies restrict which connectors can coexist in an environment, preventing data exfiltration across services; they do not encrypt Dataverse columns at rest or log record-level access. They are tempting because they are the primary Power Platform governance control, and would be correct if the requirement were blocking sensitive data flows to unapproved connectors.

  • ✓

    Customer-managed encryption key (CMK) and Audit logging

    Why this is correct

    Customer-managed encryption keys let the organisation control the key protecting Dataverse data at rest, while audit logging records every access to sensitive records. Together they satisfy both stated compliance constraints: encryption at rest under customer control and auditable access.

  • ✗

    Power Apps business rules

    Why it's wrong here

    Business rules enforce field validation and set column values within a model-driven form; they provide no encryption at rest and generate no access auditing. They are tempting because they are a core Dataverse logic feature, and would be correct if the requirement were conditionally hiding or requiring fields based on other column values.

  • ✗

    Microsoft Entra ID Conditional Access policies

    Why it's wrong here

    Conditional Access governs sign-in risk and session controls at authentication; it neither encrypts Dataverse columns at rest nor produces the audit trail the stem requires. It is tempting because it genuinely secures identity-based access to Power Platform environments, and would be correct if the requirement were restricting sign-ins by location or device compliance.

About these practice questions

This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.