PL-900 Demonstrate the capabilities of Power Apps Practice Question
Your organisation has a Power Apps canvas app that uses a custom connector to call an external API. The API key is stored in a global variable. What is the security concern with this approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The API key can be exposed to end users in the app code.
Storing an API key in a global variable within a Power Apps canvas app is insecure because the app's code is accessible to end users. Anyone with access to the app can view the global variable's value through the App object or by inspecting the app's formulas, potentially exposing the API key. The correct answer is D. Option A is incorrect because custom connectors can be used with Power Apps. Option B is incorrect because global variables in Power Apps are writable, not read-only. Option C is incorrect because API keys typically do not expire quickly; the security concern is exposure, not expiration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The custom connector cannot be used with Power Apps.
Why it's wrong here
Custom connectors are explicitly designed to be consumed by canvas apps, so this restriction does not exist. The statement would only be relevant if the connector were built for Power Automate flows alone, but here the genuine concern is that the key sits in client-side memory rather than a secure connection or environment variable.
- ✗
Global variables cannot store API keys because they are read-only.
Why it's wrong here
Global variables in Power Apps are mutable and routinely hold text values, including API keys, so the read-only claim is factually wrong. Read-only behaviour describes collections or named formulas in some contexts, but the real security issue is that any user can retrieve the key from the client session or network traffic.
- ✗
The API key will expire quickly.
Why it's wrong here
Global variables are readable by anyone with app access or through monitoring, exposing the key in plain text; expiry is unrelated to where it is stored. It is tempting because keys genuinely do expire, and rotation would be the concern if the key were held in a secure vault or connector.
- ✓
The API key can be exposed to end users in the app code.
Why this is correct
Global variables are stored client-side in the app, so any user can inspect them at runtime via the browser or Power Apps Studio. Storing the API key there exposes the credential to end users, satisfying the stem's requirement to identify the security concern.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.