โ† All PL 400 Flashcard Decks

Security and Compliance Flashcards

7 cards from real PL 400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Compliance flashcards as text
  1. A Power Platform developer needs to restrict a canvas app so only users in a specific Azure AD security group can access it. What is the correct approach?

    Answer: Share the app with the Azure AD security group

    Canvas apps can be shared with Azure AD security groups, granting access to all members of that group at once.

  2. Which Dataverse security concept allows you to grant a user access to records they own plus records shared with their business unit?

    Answer: Business unit-level access

    Business unit-level access in Dataverse allows users to access their own records and those belonging to their business unit.

  3. A developer wants to ensure a Power Automate flow cannot access a specific SharePoint site outside the approved list. Which feature enforces this?

    Answer: Data Loss Prevention (DLP) policies

    DLP policies can classify connectors and block flows from connecting to unapproved data sources like specific SharePoint sites.

  4. When implementing column-level security in Dataverse, what must be true before a user can read a secured column?

    Answer: The user must be assigned to a Column Security Profile that grants read access

    Column security profiles explicitly grant read, create, or update permissions on secured columns independent of table-level security roles.

  5. A Power Platform solution includes a PCF control that calls an external API. Which mechanism should be used to store the API key securely within the solution?

    Answer: Store it in an environment variable of type Secret

    Environment variables of type Secret store sensitive values in Azure Key Vault and are the recommended approach for secrets in Power Platform solutions.

  6. In Dataverse, which access mode allows an application to authenticate and perform operations without requiring a licensed user account for every API call?

    Answer: Application user (S2S) access

    Application users (S2S/server-to-server) authenticate via Azure AD app registrations and can perform Dataverse operations without a per-user license.

  7. A developer is building a model-driven app and wants to hide a specific form field for all users except members of a security group. What is the recommended approach?

    Answer: Use column-level security with a Column Security Profile

    Column-level security profiles are the proper mechanism to restrict visibility and access to specific Dataverse columns based on group membership.