Security and Compliance Flashcards
7 cards from real PL 400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Compliance flashcards as text
A Power Platform developer needs to comply with GDPR requirements by enabling users to request deletion of their personal data from Dataverse. Which built-in capability supports this?
Answer: Microsoft Purview Data Subject Request (DSR) in the compliance center
Microsoft Purview's Data Subject Request feature allows administrators to find and delete personal data across Microsoft 365 services including Dataverse in response to GDPR requests.
When a Power Apps canvas app is shared using 'Can Edit' permissions, what additional risk does this create compared to 'Can Use'?
Answer: Edit users can see and modify the app's data connections including credentials
Users with 'Can Edit' permissions can open the app in Power Apps Studio and view or modify embedded connection credentials and data source configurations.
A Dataverse plugin needs to securely retrieve a password to call an external service. Which approach is most secure?
Answer: Use a Secure Configuration string in the plugin step registration
Plugin step Secure Configuration stores encrypted values that are only accessible to the plugin code at runtime and are not visible in the plugin registration UI after saving.
A developer configures a Power Automate flow that sends emails with sensitive data. To comply with company policy, all emails must be encrypted in transit. What ensures this for Office 365 Outlook connector emails?
Answer: Configure S/MIME certificates in Microsoft 365 and use the Encrypt option in the Send Email action
S/MIME or Microsoft 365 Message Encryption (OME) can be applied to emails sent via Power Automate using the Outlook connector's sensitivity and encryption options.
In the Power Platform, what is the effect of enabling 'Cross-tenant inbound restrictions' in the tenant isolation settings?
Answer: Blocks connectors from establishing connections originating from other tenants into your tenant
Cross-tenant isolation inbound restrictions block connections where the connector authenticates using credentials from an external tenant to access resources in your tenant.
A developer needs to ensure Power Pages (portals) forms do not expose Dataverse table names or column schema to anonymous web users. Which setting prevents schema exposure?
Answer: Configure table permissions to deny global read and restrict the OData endpoint
Properly configured table permissions prevent the portal's OData endpoint from exposing table schemas or returning unauthorized records to anonymous users.
Which Power Platform governance feature allows administrators to detect when users are creating flows that connect to unapproved data sources before the flows are published?
Answer: Power Platform CoE Starter Kit with DLP Editor and compliance components
The CoE Starter Kit includes compliance and DLP audit components that alert administrators to policy violations and unapproved connector usage in flows across environments.