Microsoft PL-300 Workspace Roles Item Permissions Semantic Model Access RLS Practice Test

 

Skills 4.2 • 35 original questions

This Microsoft PL-300 Power BI Data Analyst practice test focuses on workspace roles item permissions semantic model access rls and sensitivity labels through original scenario-based questions aligned to the skills measured as of April 20, 2026. Use the full ExamSnap PL-300 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft PL-300 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a finance dashboard refresh at Fourth Coffee, the data analyst must grant the minimum workspace permissions required for a user or team. Which action most directly satisfies the requirement for the finance semantic model, analysis cycle 1?

  1. Assign users or groups to row-level security roles in the Power BI service
  2. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  3. Create row-level security roles with DAX filters that restrict which rows a user can see
  4. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: E

Why: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Option review:

A: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

B: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

C: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

D: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Learning point: Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Question 2

Fabrikam Manufacturing is revising its analytics solution during a operations scorecard redesign. The team needs to grant access to a specific Power BI item without unnecessarily expanding workspace permissions. Which Power BI action should the report author choose for the operations dashboard, analysis cycle 1?

  1. Create row-level security roles with DAX filters that restrict which rows a user can see
  2. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Assign users or groups to row-level security roles in the Power BI service
  5. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy

Correct answer: B

Why: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Option review:

A: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

B: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

D: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

E: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Learning point: Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace

Question 3

A design review for the customer report, analysis cycle 1 at Adventure Works identifies one required capability: allow the appropriate level of access to a shared semantic model for downstream reporting. Which implementation is the strongest fit?

  1. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  2. Create row-level security roles with DAX filters that restrict which rows a user can see
  3. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  4. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: A

Why: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Option review:

A: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

B: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

C: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

D: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Learning point: Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Question 4

For the regional workspace, analysis cycle 1, Proseware Services wants the least indirect way to restrict data rows returned to report users based on a security role. Which Power BI feature or action should the BI developer select?

  1. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  2. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  3. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  4. Create row-level security roles with DAX filters that restrict which rows a user can see
  5. Assign users or groups to row-level security roles in the Power BI service

Correct answer: D

Why: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

Option review:

A: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

B: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

C: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

D: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

E: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

Learning point: Create row-level security roles with DAX filters that restrict which rows a user can see

Question 5

The Power BI data analyst at Fourth Coffee is comparing several approaches for a self-service analytics rollout. The chosen approach must apply an existing RLS definition to the correct users or groups. Which option best meets that condition?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  3. Assign users or groups to row-level security roles in the Power BI service
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: C

Why: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: apply an existing RLS definition to the correct users or groups.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

B: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

C: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: apply an existing RLS definition to the correct users or groups.

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

Learning point: Assign users or groups to row-level security roles in the Power BI service

Question 6

A support escalation at Fabrikam Manufacturing has been narrowed to one requirement: classify Power BI content according to organizational sensitivity and information-protection requirements. Which configuration should be investigated first for the service-level dashboard, analysis cycle 1?

  1. Create row-level security roles with DAX filters that restrict which rows a user can see
  2. Assign users or groups to row-level security roles in the Power BI service
  3. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace

Correct answer: C

Why: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

Option review:

A: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

B: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

C: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

E: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

Learning point: Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy

Question 7

An analytics governance review at Adventure Works asks the data analyst to grant the minimum workspace permissions required for a user or team. Which action aligns most directly with that requirement?

  1. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  2. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  3. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  4. Create row-level security roles with DAX filters that restrict which rows a user can see
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: E

Why: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Option review:

A: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

B: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

C: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

D: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Learning point: Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Question 8

Before the mobile report, analysis cycle 2 is released, the analytics team must grant access to a specific Power BI item without unnecessarily expanding workspace permissions. Which Power BI implementation should be added?

  1. Assign users or groups to row-level security roles in the Power BI service
  2. Create row-level security roles with DAX filters that restrict which rows a user can see
  3. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: C

Why: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Option review:

A: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

B: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

C: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Learning point: Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace

Question 9

Fourth Coffee is replacing a manual analytics process. The replacement must reliably allow the appropriate level of access to a shared semantic model for downstream reporting. Which choice should be implemented for the executive report, analysis cycle 2?

  1. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  2. Assign users or groups to row-level security roles in the Power BI service
  3. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: D

Why: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Option review:

A: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

B: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

C: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Learning point: Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Question 10

Which Power BI action best matches this technical purpose for the sales model, analysis cycle 2: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy.

  1. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  2. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  3. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  4. Create row-level security roles with DAX filters that restrict which rows a user can see
  5. Assign users or groups to row-level security roles in the Power BI service

Correct answer: D

Why: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy..

Option review:

A: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy..

B: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy..

C: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy..

D: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy..

E: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy..

Learning point: Create row-level security roles with DAX filters that restrict which rows a user can see

Question 11

A runbook for the finance semantic model, analysis cycle 2 contains this description: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. Which Power BI feature or action belongs in the runbook?

  1. Assign users or groups to row-level security roles in the Power BI service
  2. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  3. Create row-level security roles with DAX filters that restrict which rows a user can see
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: A

Why: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

Option review:

A: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

B: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

C: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

Learning point: Assign users or groups to row-level security roles in the Power BI service

Question 12

During validation of the operations dashboard, analysis cycle 2, the self-service BI administrator needs a capability that behaves as follows: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. Which choice is correct?

  1. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  2. Assign users or groups to row-level security roles in the Power BI service
  3. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: D

Why: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

Option review:

A: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

B: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

C: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

Learning point: Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy

Question 13

A stakeholder asks why a particular Power BI feature should be used for the customer report, analysis cycle 3. The required behavior is: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. Which action provides that behavior?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  3. Create row-level security roles with DAX filters that restrict which rows a user can see
  4. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  5. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Correct answer: D

Why: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace..

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace..

B: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace..

C: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace..

D: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace..

E: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace..

Learning point: Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Question 14

The regional workspace, analysis cycle 3 is moving to production at Fabrikam Manufacturing. Which action should be approved when the goal is to grant access to a specific Power BI item without unnecessarily expanding workspace permissions?

  1. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  2. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  3. Assign users or groups to row-level security roles in the Power BI service
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace

Correct answer: E

Why: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Option review:

A: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

B: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

C: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

E: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Learning point: Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace

Question 15

A data analyst at Adventure Works must satisfy this acceptance criterion for the inventory model, analysis cycle 3: allow the appropriate level of access to a shared semantic model for downstream reporting. Which implementation is most appropriate?

  1. Assign users or groups to row-level security roles in the Power BI service
  2. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  3. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: D

Why: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Option review:

A: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

B: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

C: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Learning point: Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Question 16

A sales analytics project at Proseware Services can proceed only after the team can restrict data rows returned to report users based on a security role. What should the BI developer configure?

  1. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  2. Assign users or groups to row-level security roles in the Power BI service
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: E

Why: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

Option review:

A: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

B: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

Learning point: Create row-level security roles with DAX filters that restrict which rows a user can see

Question 17

The analytics team at Fourth Coffee has ruled out unrelated redesign work. Which action directly enables the team to apply an existing RLS definition to the correct users or groups for the forecast report, analysis cycle 3?

  1. Create row-level security roles with DAX filters that restrict which rows a user can see
  2. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  3. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  4. Assign users or groups to row-level security roles in the Power BI service
  5. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy

Correct answer: D

Why: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: apply an existing RLS definition to the correct users or groups.

Option review:

A: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

B: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

C: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

D: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: apply an existing RLS definition to the correct users or groups.

E: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

Learning point: Assign users or groups to row-level security roles in the Power BI service

Question 18

An audit finding for the mobile report, analysis cycle 3 says the current design cannot classify Power BI content according to organizational sensitivity and information-protection requirements. Which Power BI action most directly closes the gap?

  1. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  2. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  3. Create row-level security roles with DAX filters that restrict which rows a user can see
  4. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  5. Assign users or groups to row-level security roles in the Power BI service

Correct answer: B

Why: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

Option review:

A: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

B: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

C: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

D: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

E: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

Learning point: Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy

Question 19

For the executive report, analysis cycle 4, the data analyst needs a repeatable solution that will grant the minimum workspace permissions required for a user or team. Which option should replace the current ad hoc process?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  3. Assign users or groups to row-level security roles in the Power BI service
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: B

Why: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

B: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

C: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

Learning point: Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Question 20

During a monthly KPI review, Proseware Services defines the desired outcome as follows: grant access to a specific Power BI item without unnecessarily expanding workspace permissions. Which Power BI capability should the team use?

  1. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  2. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Assign users or groups to row-level security roles in the Power BI service
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: B

Why: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Option review:

A: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

B: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

D: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Learning point: Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace

Question 21

A new requirement is added to the finance semantic model, analysis cycle 4: allow the appropriate level of access to a shared semantic model for downstream reporting. Which action should the analytics lead take?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Assign users or groups to row-level security roles in the Power BI service
  5. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Correct answer: E

Why: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

B: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

D: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

E: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Learning point: Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Question 22

Fabrikam Manufacturing is troubleshooting an unexpected reporting result. The decisive requirement is to restrict data rows returned to report users based on a security role. Which feature or configuration is most relevant?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Assign users or groups to row-level security roles in the Power BI service
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: E

Why: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

B: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

Learning point: Create row-level security roles with DAX filters that restrict which rows a user can see

Question 23

A technical workshop for the customer report, analysis cycle 4 documents this behavior: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. Which Power BI choice is being described?

  1. Assign users or groups to row-level security roles in the Power BI service
  2. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  3. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  4. Create row-level security roles with DAX filters that restrict which rows a user can see
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: A

Why: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

Option review:

A: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

B: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

C: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

D: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

Learning point: Assign users or groups to row-level security roles in the Power BI service

Question 24

The self-service BI administrator must identify the Power BI capability that provides this function: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. Which answer is correct for the regional workspace, analysis cycle 4?

  1. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  2. Create row-level security roles with DAX filters that restrict which rows a user can see
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Assign users or groups to row-level security roles in the Power BI service

Correct answer: A

Why: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

Option review:

A: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

B: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

E: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports..

Learning point: Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy

Question 25

A modernization plan for the inventory model, analysis cycle 5 requires the team to grant the minimum workspace permissions required for a user or team. Which Power BI action is the clearest fit?

  1. Create row-level security roles with DAX filters that restrict which rows a user can see
  2. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  3. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: E

Why: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Option review:

A: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

B: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

C: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Learning point: Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Question 26

The analytics lead at Fabrikam Manufacturing is creating a standard for the service-level dashboard, analysis cycle 5. The standard must grant access to a specific Power BI item without unnecessarily expanding workspace permissions. Which feature should be documented?

  1. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  2. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  3. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  4. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  5. Assign users or groups to row-level security roles in the Power BI service

Correct answer: B

Why: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Option review:

A: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

B: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

C: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

D: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

E: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Learning point: Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace

Question 27

Which implementation should Adventure Works use for the forecast report, analysis cycle 5 when the business requirement is to allow the appropriate level of access to a shared semantic model for downstream reporting?

  1. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  2. Assign users or groups to row-level security roles in the Power BI service
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: A

Why: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Option review:

A: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

B: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Learning point: Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Question 28

A pilot review at Proseware Services finds that users still cannot restrict data rows returned to report users based on a security role. Which action should be completed before the mobile report, analysis cycle 5 is expanded?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Create row-level security roles with DAX filters that restrict which rows a user can see
  3. Assign users or groups to row-level security roles in the Power BI service
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy

Correct answer: B

Why: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

B: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

C: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

E: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

Learning point: Create row-level security roles with DAX filters that restrict which rows a user can see

Question 29

The Power BI data analyst needs to justify a Power BI design decision for the executive report, analysis cycle 5. The feature must provide this behavior: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. Which selection is most defensible?

  1. Assign users or groups to row-level security roles in the Power BI service
  2. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Create row-level security roles with DAX filters that restrict which rows a user can see
  5. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Correct answer: A

Why: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

Option review:

A: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

B: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

D: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

E: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them..

Learning point: Assign users or groups to row-level security roles in the Power BI service

Question 30

For a data-quality remediation, the sales model, analysis cycle 5 must support the ability to classify Power BI content according to organizational sensitivity and information-protection requirements. Which option is technically aligned with that goal?

  1. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  2. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  3. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  4. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: A

Why: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

Option review:

A: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. This directly addresses the stated requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

B: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

C: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

D: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: classify Power BI content according to organizational sensitivity and information-protection requirements.

Learning point: Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy

Question 31

An enterprise BI standards group at Adventure Works asks which feature directly addresses this need: grant the minimum workspace permissions required for a user or team. What should the data analyst recommend?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Create row-level security roles with DAX filters that restrict which rows a user can see
  3. Assign users or groups to row-level security roles in the Power BI service
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: E

Why: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

B: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

C: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant the minimum workspace permissions required for a user or team.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. This directly addresses the stated requirement: grant the minimum workspace permissions required for a user or team.

Learning point: Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Question 32

A change request for the operations dashboard, analysis cycle 6 specifies this outcome: grant access to a specific Power BI item without unnecessarily expanding workspace permissions. Which Power BI action should be implemented?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege
  3. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  4. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  5. Create row-level security roles with DAX filters that restrict which rows a user can see

Correct answer: A

Why: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. This directly addresses the stated requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

B: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

C: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

D: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

E: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: grant access to a specific Power BI item without unnecessarily expanding workspace permissions.

Learning point: Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace

Question 33

During a customer analytics initiative at Fourth Coffee, the analytics lead must allow the appropriate level of access to a shared semantic model for downstream reporting. Which action most directly satisfies the requirement for the customer report, analysis cycle 6?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Create row-level security roles with DAX filters that restrict which rows a user can see
  3. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers
  4. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  5. Assign workspace roles such as Admin, Member, Contributor, or Viewer according to least privilege

Correct answer: C

Why: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

B: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

C: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. This directly addresses the stated requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

D: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

E: Workspace roles determine what users can create, modify, publish, manage, or only view inside the workspace. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: allow the appropriate level of access to a shared semantic model for downstream reporting.

Learning point: Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Question 34

Fabrikam Manufacturing is revising its analytics solution during a semantic model modernization. The team needs to restrict data rows returned to report users based on a security role. Which Power BI action should the BI developer choose for the regional workspace, analysis cycle 6?

  1. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  2. Create row-level security roles with DAX filters that restrict which rows a user can see
  3. Assign users or groups to row-level security roles in the Power BI service
  4. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  5. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Correct answer: B

Why: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

Option review:

A: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

B: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. This directly addresses the stated requirement: restrict data rows returned to report users based on a security role.

C: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

D: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

E: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: restrict data rows returned to report users based on a security role.

Learning point: Create row-level security roles with DAX filters that restrict which rows a user can see

Question 35

A design review for the inventory model, analysis cycle 6 at Adventure Works identifies one required capability: apply an existing RLS definition to the correct users or groups. Which implementation is the strongest fit?

  1. Configure item-level permissions when access must be granted to a specific report, semantic model, or other item rather than broadly through the workspace
  2. Apply a Microsoft Purview sensitivity label to Power BI content according to information-protection policy
  3. Create row-level security roles with DAX filters that restrict which rows a user can see
  4. Assign users or groups to row-level security roles in the Power BI service
  5. Configure semantic-model permissions such as Build, Read, or related access required by downstream authors and consumers

Correct answer: D

Why: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: apply an existing RLS definition to the correct users or groups.

Option review:

A: Item permissions support more granular access than giving a user a broader workspace role. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

B: Sensitivity labels classify and protect content and can carry information-protection context through supported Power BI workflows and exports. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

C: RLS applies role filters to semantic-model data so different users can query only the rows permitted by policy. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

D: Defining an RLS role is not enough; users or groups must be mapped to the role so the intended filter is enforced for them. This directly addresses the stated requirement: apply an existing RLS definition to the correct users or groups.

E: Semantic-model permissions govern whether users can consume, build new content from, or otherwise interact with a published model. It is useful in another Power BI scenario, but it does not most directly satisfy this requirement: apply an existing RLS definition to the correct users or groups.

Learning point: Assign users or groups to row-level security roles in the Power BI service

Popular posts

img