โ† All PL 400 Flashcard Decks

Security and Compliance Flashcards

7 cards from real PL 400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Compliance flashcards as text
  1. A company requires that Power Platform environments only allow connections to Microsoft 365 connectors and block all third-party connectors. How should DLP policies be configured?

    Answer: Set all Microsoft 365 connectors to Business and all others to Blocked

    DLP policies support a Blocked classification that prevents connectors from being used in any flow or app within the policy scope.

  2. Which Dataverse feature allows a developer to automatically share records with specific users or teams when a record meets defined criteria?

    Answer: Access Teams

    Access Teams allow dynamic sharing of individual records with specific users without changing ownership, ideal for scenario-based record access.

  3. A Power Automate flow uses an HTTP connector to call an internal API that requires OAuth 2.0. The token must be refreshed automatically. Which approach is most appropriate?

    Answer: Use a custom connector with OAuth 2.0 authentication configured

    Custom connectors support OAuth 2.0 configuration that handles token acquisition and refresh automatically, abstracting credential management from the flow.

  4. In Power Platform, what does the 'Minimum Privilege' principle mean when assigning Dataverse security roles?

    Answer: Users should receive only the permissions necessary to perform their job functions

    The principle of least privilege requires granting only the minimum permissions needed for a user to accomplish their intended tasks.

  5. A developer needs to audit which users accessed sensitive Dataverse records over the past 30 days. Which feature provides this capability?

    Answer: Dataverse auditing with audit log queries

    Dataverse auditing tracks read, create, update, and delete operations on tables and can be queried through the audit log in the Power Platform admin center.

  6. Which Azure AD feature can be used to require MFA for users accessing Power Apps in a specific environment based on their location?

    Answer: Azure AD Conditional Access policies

    Conditional Access policies can enforce MFA requirements for Power Platform applications based on conditions like user location, device compliance, or risk level.

  7. A Power Apps portal (Power Pages) needs to allow anonymous users to submit forms but restrict record viewing to authenticated users. Which feature controls this?

    Answer: Web roles with Entity permissions for authenticated users

    Power Pages uses web roles and table permissions to control access; authenticated web roles can grant read access to records while anonymous users only submit.