PL-900 Practice Question: Demonstrate the capabilities of Power Automate
Which TWO are best practices for designing Power Automate flows in a production environment? (Select TWO.)
⚠ Common exam trap
PL-900 often tests the misconception that disabling logging improves performance or that hardcoding connections is acceptable; the exam expects you to recognize error handling and data security as the real best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use 'Configure Run After' to implement error handling.
Option B is correct because 'Configure Run After' lets you define the run-after conditions on an action so that subsequent steps execute even when a prior action fails, times out, or is skipped, which is the standard way to build robust try/catch-style error handling in Power Automate. Option E is correct because enabling Secure Inputs and Secure Outputs on actions that process sensitive data (such as credentials, tokens, or personal information) prevents those values from appearing in the run history and flow logs, protecting them from unintended exposure. Option A is not a best practice because disabling logging removes the run history and diagnostic data needed to monitor, troubleshoot, and audit production flows, and logging is not the primary performance bottleneck. Option C is not a best practice because nesting 'Apply to each' loops multiplies iterations and can cause severe performance degradation or throttling; large datasets should instead be handled with pagination, filtering, batching, or the 'Select' and 'Filter array' operations. Option D is not a best practice because hardcoding connection references reduces portability and maintainability across environments; connections should be parameterized or managed through environment variables and solution-aware connection references.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable flow logging to improve performance.
Why it's wrong here
Disabling logging removes the run history needed to diagnose failures and audit production activity, and it does not meaningfully improve throughput. It is tempting because logging is often assumed to add overhead, and reducing telemetry is legitimate when storage cost or data-volume limits are the actual constraint.
- ✓
Use 'Configure Run After' to implement error handling.
Why this is correct
'Configure Run After' defines how downstream actions respond when a preceding action fails, times out or is skipped, enabling graceful error handling and escalation. This prevents silent failures in production flows, satisfying the best-practice requirement for resilient design.
- ✗
Nest Apply to each actions to handle large datasets.
Why it's wrong here
Nesting Apply to each actions multiplies iterations and can breach the 100,000-action limit or trigger throttling, so it degrades rather than handles large datasets. It is tempting because nesting appears to give finer control over grouped items, and it is legitimate when iterating genuinely hierarchical, small collections.
- ✗
Hardcode connection references for simplicity.
Why it's wrong here
Hardcoded connection references break when flows move between environments, since each environment holds different connection IDs, so deployment fails. It is tempting because hardcoding removes setup steps during initial development, and it is acceptable for a single-environment throwaway flow that will never be promoted.
- ✓
Use secure inputs and outputs for actions handling sensitive data.
Why this is correct
Secure inputs and outputs mask action data in run history, so credentials and sensitive fields are not exposed to anyone viewing the flow's execution logs. This satisfies the production requirement to protect confidential data handled by actions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.