Microsoft Fabric Analytics Engineer DP-600 Security Governance And Access Controls Practice Test

 

Skill 1.1 – 75 original questions

This Microsoft DP-600 practice test focuses on security governance and access controls through original scenario-based questions aligned to the active DP-600 skills measured as of July 21, 2026. Use the complete ExamSnap DP-600 collection for broader practice across Microsoft Fabric analytics lifecycle, data preparation, querying, and semantic modeling. For broader exam preparation, review the Microsoft DP-600 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each option includes a reason it is or is not the strongest choice for the scenario.

Question 1

An internal audit of Wingtip Toys’s marketing semantic model identifies this requirement: give auditors read-only access to every item in one workspace without allowing edits. The operations data team also notes that the rollout must support controlled validation. What should they do? Existing users should keep their current access.

  1. Configure deployment rules for the target stage
  2. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  3. Assign the auditors the Viewer workspace role
  4. Certify the semantic model
  5. Define and assign row-level security roles for the semantic model

Correct answer: C

Why: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This directly matches the stated requirement.

Option review:

A: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This directly matches the stated requirement.

D: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the auditors the Viewer workspace role

Question 2

The supply-chain lakehouse at Proseware is moving from proof of concept to production. Before rollout, the data governance group must let developers create and edit Fabric items but prevent them from managing workspace membership, while ensuring that the team wants predictable performance and behavior. Which action best meets both needs? Existing users should keep their current access.

  1. Assign the developers the Contributor workspace role
  2. Grant Build permission on the semantic model rather than a workspace role
  3. Connect the workspace to a supported Git repository by using Fabric Git integration
  4. Use Fabric lineage and impact analysis before making the change
  5. Create and distribute a Power BI data source (.pbids) file

Correct answer: A

Why: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This directly matches the stated requirement.

Option review:

A: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This directly matches the stated requirement.

B: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the developers the Contributor workspace role

Question 3

Blue Yonder Airlines has a change request for the IoT telemetry solution: let a release lead create, modify, and share workspace content without granting full workspace administration. The enterprise reporting group wants a solution where the choice should use a native Fabric capability. Which implementation is most suitable? Existing users should keep their current access.

  1. Assign the release lead the Member workspace role
  2. Create a deployment pipeline with separate lifecycle stages
  3. Apply the appropriate Microsoft Purview sensitivity label to the item
  4. Create and distribute a Power BI data source (.pbids) file
  5. Share only that report and grant the required item permission

Correct answer: A

Why: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This directly matches the stated requirement.

Option review:

A: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This directly matches the stated requirement.

B: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the release lead the Member workspace role

Question 4

A solution architect reviewing Fabrikam’s finance reporting platform asks the finance analytics squad to allow a platform owner to manage workspace settings, membership, and all content. Since the design should minimize duplicated data, which recommendation is strongest? Existing users should keep their current access.

  1. Assign the platform owner the Admin workspace role
  2. Connect to the workspace XMLA endpoint with read/write operations enabled
  3. Configure deployment rules for the target stage
  4. Connect the workspace to a supported Git repository by using Fabric Git integration
  5. Create a deployment pipeline with separate lifecycle stages

Correct answer: A

Why: Admin is the workspace role intended for full workspace administration, including permissions and settings. This directly matches the stated requirement.

Option review:

A: Admin is the workspace role intended for full workspace administration, including permissions and settings. This directly matches the stated requirement.

B: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the platform owner the Admin workspace role

Question 5

The next sprint for Litware’s retail performance dashboard includes a task to give auditors read-only access to every item in one workspace without allowing edits. The acceptance criteria add that least privilege must be preserved. Which Fabric or Power BI action is appropriate? No unrelated workspace or model permissions should be changed.

  1. Share only that report and grant the required item permission
  2. Assign the auditors the Viewer workspace role
  3. Create a Power BI template (.pbit) file
  4. Connect the workspace to a supported Git repository by using Fabric Git integration
  5. Apply the required sensitivity label to the report

Correct answer: B

Why: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This directly matches the stated requirement.

Option review:

A: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This directly matches the stated requirement.

C: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the auditors the Viewer workspace role

Question 6

Woodgrove Bank is troubleshooting a design decision in the marketing semantic model. The desired end state is to let developers create and edit Fabric items but prevent them from managing workspace membership; the rollout must support controlled validation. Which change should the operations data team make? No unrelated workspace or model permissions should be changed.

  1. Create and distribute a Power BI data source (.pbids) file
  2. Connect to the workspace XMLA endpoint with read/write operations enabled
  3. Assign the developers the Contributor workspace role
  4. Share only that report and grant the required item permission
  5. Use the XMLA endpoint to manage the semantic model programmatically

Correct answer: C

Why: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This directly matches the stated requirement.

Option review:

A: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This directly matches the stated requirement.

D: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the developers the Contributor workspace role

Question 7

For the supply-chain lakehouse, Coho Winery has documented a business requirement to let a release lead create, modify, and share workspace content without granting full workspace administration. The data governance group must meet it in a way where the team wants predictable performance and behavior. What is the best choice? No unrelated workspace or model permissions should be changed.

  1. Create a OneLake security role scoped to the required folders or tables
  2. Apply the appropriate Microsoft Purview sensitivity label to the item
  3. Use the PBIP project format and commit the project folder
  4. Certify the semantic model
  5. Assign the release lead the Member workspace role

Correct answer: E

Why: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This directly matches the stated requirement.

Option review:

A: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This directly matches the stated requirement.

Learning point: Assign the release lead the Member workspace role

Question 8

A governance review of Adventure Works’s IoT telemetry solution asks for evidence that the solution can allow a platform owner to manage workspace settings, membership, and all content. Because the choice should use a native Fabric capability, which action should be approved? No unrelated workspace or model permissions should be changed.

  1. Use Fabric lineage and impact analysis before making the change
  2. Create a OneLake security role scoped to the required folders or tables
  3. Create a Power BI template (.pbit) file
  4. Assign the platform owner the Admin workspace role
  5. Certify the semantic model

Correct answer: D

Why: Admin is the workspace role intended for full workspace administration, including permissions and settings. This directly matches the stated requirement.

Option review:

A: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: Admin is the workspace role intended for full workspace administration, including permissions and settings. This directly matches the stated requirement.

E: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the platform owner the Admin workspace role

Question 9

Before expanding the finance reporting platform, the finance analytics squad at Tailspin Toys must give auditors read-only access to every item in one workspace without allowing edits. The rollout plan says that the design should minimize duplicated data. Which option most directly addresses the requirement? The team will validate the change first in a nonproduction environment.

  1. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  2. Assign the auditors the Viewer workspace role
  3. Apply column-level security to the sensitive columns
  4. Use the PBIP project format and commit the project folder
  5. Apply the appropriate Microsoft Purview sensitivity label to the item

Correct answer: B

Why: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This directly matches the stated requirement.

Option review:

A: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This directly matches the stated requirement.

C: Column-level security restricts access at the column boundary while preserving access to permitted data. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the auditors the Viewer workspace role

Question 10

Fourth Coffee is redesigning its retail performance dashboard. The analytics engineering team must let developers create and edit Fabric items but prevent them from managing workspace membership. In addition, least privilege must be preserved. Which action is the best fit? The team will validate the change first in a nonproduction environment.

  1. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  2. Assign the developers the Contributor workspace role
  3. Use Fabric lineage and impact analysis before making the change
  4. Use the XMLA endpoint to manage the semantic model programmatically
  5. Create a Power BI template (.pbit) file

Correct answer: B

Why: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This directly matches the stated requirement.

Option review:

A: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This directly matches the stated requirement.

C: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the developers the Contributor workspace role

Question 11

During a design review for Wide World Importers’s marketing semantic model, one requirement is non-negotiable: let a release lead create, modify, and share workspace content without granting full workspace administration. Because the rollout must support controlled validation, what should the operations data team implement? The team will validate the change first in a nonproduction environment.

  1. Use the PBIP project format and commit the project folder
  2. Use Fabric lineage and impact analysis before making the change
  3. Assign the release lead the Member workspace role
  4. Publish and reuse a shared semantic model
  5. Use the XMLA endpoint to manage the semantic model programmatically

Correct answer: C

Why: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This directly matches the stated requirement.

Option review:

A: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This directly matches the stated requirement.

D: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the release lead the Member workspace role

Question 12

The data governance group at Northwind Traders is preparing the next release of its supply-chain lakehouse. They need to allow a platform owner to manage workspace settings, membership, and all content; the team wants predictable performance and behavior. Which choice most directly satisfies the requirement? The team will validate the change first in a nonproduction environment.

  1. Review downstream dependencies in the lineage or impact-analysis view
  2. Apply the appropriate Microsoft Purview sensitivity label to the item
  3. Share only that report and grant the required item permission
  4. Assign the platform owner the Admin workspace role
  5. Grant Build permission on the semantic model rather than a workspace role

Correct answer: D

Why: Admin is the workspace role intended for full workspace administration, including permissions and settings. This directly matches the stated requirement.

Option review:

A: Dependency analysis exposes which artifacts consume the changed object and therefore require validation. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: Admin is the workspace role intended for full workspace administration, including permissions and settings. This directly matches the stated requirement.

E: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the platform owner the Admin workspace role

Question 13

A production readiness review at Trey Research found a gap in the IoT telemetry solution. The remediation must give auditors read-only access to every item in one workspace without allowing edits, and the choice should use a native Fabric capability. What is the most appropriate action? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Assign the auditors the Viewer workspace role
  2. Use the item Manage permissions or sharing experience for that item
  3. Certify the semantic model
  4. Use Fabric lineage and impact analysis before making the change
  5. Promote the item

Correct answer: A

Why: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This directly matches the stated requirement.

Option review:

A: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This directly matches the stated requirement.

B: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: Promotion is appropriate for recommended content that has not gone through the formal certification process. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the auditors the Viewer workspace role

Question 14

For a new phase of the finance reporting platform, Alpine Ski House asks the finance analytics squad to let developers create and edit Fabric items but prevent them from managing workspace membership. The architecture decision record also states that the design should minimize duplicated data. Which approach should be selected? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  2. Apply column-level security to the sensitive columns
  3. Assign the developers the Contributor workspace role
  4. Create a deployment pipeline with separate lifecycle stages
  5. Use the PBIP project format and commit the project folder

Correct answer: C

Why: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This directly matches the stated requirement.

Option review:

A: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: Column-level security restricts access at the column boundary while preserving access to permitted data. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

C: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This directly matches the stated requirement.

D: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the developers the Contributor workspace role

Question 15

Contoso is standardizing how the retail performance dashboard is managed. The immediate goal is to let a release lead create, modify, and share workspace content without granting full workspace administration. Given that least privilege must be preserved, which option should the analytics engineering team choose? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Define and assign row-level security roles for the semantic model
  2. Assign the release lead the Member workspace role
  3. Certify the semantic model
  4. Configure deployment rules for the target stage
  5. Create and distribute a Power BI data source (.pbids) file

Correct answer: B

Why: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This directly matches the stated requirement.

Option review:

A: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

B: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This directly matches the stated requirement.

C: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

D: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

E: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement workspace-level access controls’.

Learning point: Assign the release lead the Member workspace role

Question 16

An internal audit of Wingtip Toys’s customer 360 model identifies this requirement: let a contractor view one report without becoming a member of the containing workspace. The BI platform team also notes that the rollout must support controlled validation. What should they do? Existing users should keep their current access.

  1. Assign the developers the Contributor workspace role
  2. Share only that report and grant the required item permission
  3. Certify the semantic model
  4. Create a deployment pipeline with separate lifecycle stages
  5. Use the PBIP project format and commit the project folder

Correct answer: B

Why: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

Option review:

A: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

C: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Share only that report and grant the required item permission

Question 17

The sales analytics solution at Proseware is moving from proof of concept to production. Before rollout, the security analytics team must let an analyst build new reports from one governed semantic model while avoiding access to unrelated workspace content, while ensuring that the team wants predictable performance and behavior. Which action best meets both needs? Existing users should keep their current access.

  1. Publish and reuse a shared semantic model
  2. Grant Build permission on the semantic model rather than a workspace role
  3. Configure deployment rules for the target stage
  4. Use Fabric lineage and impact analysis before making the change
  5. Save the solution as a Power BI Desktop project (.pbip)

Correct answer: B

Why: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

Option review:

A: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

C: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Grant Build permission on the semantic model rather than a workspace role

Question 18

Blue Yonder Airlines has a change request for the risk analytics environment: grant access to a single Fabric item and keep all other items in the workspace hidden. The Fabric center of excellence wants a solution where the choice should use a native Fabric capability. Which implementation is most suitable? Existing users should keep their current access.

  1. Create a Power BI template (.pbit) file
  2. Apply the appropriate Microsoft Purview sensitivity label to the item
  3. Apply the required sensitivity label to the report
  4. Use the item Manage permissions or sharing experience for that item
  5. Define and assign row-level security roles for the semantic model

Correct answer: D

Why: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

Option review:

A: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

E: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Use the item Manage permissions or sharing experience for that item

Question 19

A solution architect reviewing Fabrikam’s service-operations warehouse asks the customer insights team to let a contractor view one report without becoming a member of the containing workspace. Since the design should minimize duplicated data, which recommendation is strongest? No unrelated workspace or model permissions should be changed.

  1. Apply the appropriate Microsoft Purview sensitivity label to the item
  2. Configure deployment rules for the target stage
  3. Share only that report and grant the required item permission
  4. Apply the required sensitivity label to the report
  5. Use the PBIP project format and commit the project folder

Correct answer: C

Why: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

Option review:

A: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

D: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Share only that report and grant the required item permission

Question 20

The next sprint for Litware’s executive reporting workspace includes a task to let an analyst build new reports from one governed semantic model while avoiding access to unrelated workspace content. The acceptance criteria add that least privilege must be preserved. Which Fabric or Power BI action is appropriate? No unrelated workspace or model permissions should be changed.

  1. Grant Build permission on the semantic model rather than a workspace role
  2. Create a OneLake security role scoped to the required folders or tables
  3. Assign the developers the Contributor workspace role
  4. Create a Power BI template (.pbit) file
  5. Publish and reuse a shared semantic model

Correct answer: A

Why: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

Option review:

A: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

B: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Grant Build permission on the semantic model rather than a workspace role

Question 21

Woodgrove Bank is troubleshooting a design decision in the customer 360 model. The desired end state is to grant access to a single Fabric item and keep all other items in the workspace hidden; the rollout must support controlled validation. Which change should the BI platform team make? No unrelated workspace or model permissions should be changed.

  1. Configure object-level security for the protected table or column
  2. Use the item Manage permissions or sharing experience for that item
  3. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  4. Assign the auditors the Viewer workspace role
  5. Connect the workspace to a supported Git repository by using Fabric Git integration

Correct answer: B

Why: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

Option review:

A: OLS prevents users from discovering or querying protected model objects. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

C: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Use the item Manage permissions or sharing experience for that item

Question 22

For the sales analytics solution, Coho Winery has documented a business requirement to let a contractor view one report without becoming a member of the containing workspace. The security analytics team must meet it in a way where the team wants predictable performance and behavior. What is the best choice? The team will validate the change first in a nonproduction environment.

  1. Publish and reuse a shared semantic model
  2. Share only that report and grant the required item permission
  3. Apply the required sensitivity label to the report
  4. Configure deployment rules for the target stage
  5. Save the solution as a Power BI Desktop project (.pbip)

Correct answer: B

Why: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

Option review:

A: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

C: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Share only that report and grant the required item permission

Question 23

A governance review of Adventure Works’s risk analytics environment asks for evidence that the solution can let an analyst build new reports from one governed semantic model while avoiding access to unrelated workspace content. Because the choice should use a native Fabric capability, which action should be approved? The team will validate the change first in a nonproduction environment.

  1. Promote the item
  2. Configure object-level security for the protected table or column
  3. Grant Build permission on the semantic model rather than a workspace role
  4. Create and distribute a Power BI data source (.pbids) file
  5. Create a Power BI template (.pbit) file

Correct answer: C

Why: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

Option review:

A: Promotion is appropriate for recommended content that has not gone through the formal certification process. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: OLS prevents users from discovering or querying protected model objects. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

D: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Grant Build permission on the semantic model rather than a workspace role

Question 24

Before expanding the service-operations warehouse, the customer insights team at Tailspin Toys must grant access to a single Fabric item and keep all other items in the workspace hidden. The rollout plan says that the design should minimize duplicated data. Which option most directly addresses the requirement? The team will validate the change first in a nonproduction environment.

  1. Save the solution as a Power BI Desktop project (.pbip)
  2. Use the item Manage permissions or sharing experience for that item
  3. Assign the platform owner the Admin workspace role
  4. Apply the appropriate Microsoft Purview sensitivity label to the item
  5. Define and assign row-level security roles for the semantic model

Correct answer: B

Why: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

Option review:

A: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

C: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Use the item Manage permissions or sharing experience for that item

Question 25

Fourth Coffee is redesigning its executive reporting workspace. The retail insights team must let a contractor view one report without becoming a member of the containing workspace. In addition, least privilege must be preserved. Which action is the best fit? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Share only that report and grant the required item permission
  2. Apply the required sensitivity label to the report
  3. Assign the release lead the Member workspace role
  4. Publish and reuse a shared semantic model
  5. Configure object-level security for the protected table or column

Correct answer: A

Why: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

Option review:

A: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

B: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: OLS prevents users from discovering or querying protected model objects. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Share only that report and grant the required item permission

Question 26

During a design review for Wide World Importers’s customer 360 model, one requirement is non-negotiable: let an analyst build new reports from one governed semantic model while avoiding access to unrelated workspace content. Because the rollout must support controlled validation, what should the BI platform team implement? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Grant Build permission on the semantic model rather than a workspace role
  2. Create a Power BI template (.pbit) file
  3. Assign the platform owner the Admin workspace role
  4. Connect to the workspace XMLA endpoint with read/write operations enabled
  5. Certify the semantic model

Correct answer: A

Why: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

Option review:

A: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

B: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Grant Build permission on the semantic model rather than a workspace role

Question 27

The security analytics team at Northwind Traders is preparing the next release of its sales analytics solution. They need to grant access to a single Fabric item and keep all other items in the workspace hidden; the team wants predictable performance and behavior. Which choice most directly satisfies the requirement? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Create a Power BI template (.pbit) file
  2. Use the XMLA endpoint to manage the semantic model programmatically
  3. Use the item Manage permissions or sharing experience for that item
  4. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  5. Use the PBIP project format and commit the project folder

Correct answer: C

Why: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

Option review:

A: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

D: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Use the item Manage permissions or sharing experience for that item

Question 28

A production readiness review at Trey Research found a gap in the risk analytics environment. The remediation must let a contractor view one report without becoming a member of the containing workspace, and the choice should use a native Fabric capability. What is the most appropriate action? The design decision will be reviewed by both data engineering and BI owners.

  1. Create a deployment pipeline with separate lifecycle stages
  2. Share only that report and grant the required item permission
  3. Connect to the workspace XMLA endpoint with read/write operations enabled
  4. Assign the auditors the Viewer workspace role
  5. Assign the platform owner the Admin workspace role

Correct answer: B

Why: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

Option review:

A: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This directly matches the stated requirement.

C: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Share only that report and grant the required item permission

Question 29

For a new phase of the service-operations warehouse, Alpine Ski House asks the customer insights team to let an analyst build new reports from one governed semantic model while avoiding access to unrelated workspace content. The architecture decision record also states that the design should minimize duplicated data. Which approach should be selected? The design decision will be reviewed by both data engineering and BI owners.

  1. Create a OneLake security role scoped to the required folders or tables
  2. Create a deployment pipeline with separate lifecycle stages
  3. Grant Build permission on the semantic model rather than a workspace role
  4. Connect the workspace to a supported Git repository by using Fabric Git integration
  5. Assign the release lead the Member workspace role

Correct answer: C

Why: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

Option review:

A: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This directly matches the stated requirement.

D: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

Learning point: Grant Build permission on the semantic model rather than a workspace role

Question 30

Contoso is standardizing how the executive reporting workspace is managed. The immediate goal is to grant access to a single Fabric item and keep all other items in the workspace hidden. Given that least privilege must be preserved, which option should the retail insights team choose? The design decision will be reviewed by both data engineering and BI owners.

  1. Apply column-level security to the sensitive columns
  2. Assign the developers the Contributor workspace role
  3. Save the solution as a Power BI Desktop project (.pbip)
  4. Use Fabric lineage and impact analysis before making the change
  5. Use the item Manage permissions or sharing experience for that item

Correct answer: E

Why: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

Option review:

A: Column-level security restricts access at the column boundary while preserving access to permitted data. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

B: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

C: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

D: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement item-level access controls’.

E: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This directly matches the stated requirement.

Learning point: Use the item Manage permissions or sharing experience for that item

Question 31

An internal audit of Wingtip Toys’s marketing semantic model identifies this requirement: show each regional manager only rows for that manager region in the semantic model. The operations data team also notes that the rollout must support controlled validation. What should they do? Existing users should keep their current access.

  1. Create and distribute a Power BI data source (.pbids) file
  2. Assign the release lead the Member workspace role
  3. Apply the appropriate Microsoft Purview sensitivity label to the item
  4. Grant Build permission on the semantic model rather than a workspace role
  5. Define and assign row-level security roles for the semantic model

Correct answer: E

Why: RLS filters rows by user or role so consumers see only the permitted records. This directly matches the stated requirement.

Option review:

A: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: RLS filters rows by user or role so consumers see only the permitted records. This directly matches the stated requirement.

Learning point: Define and assign row-level security roles for the semantic model

Question 32

The supply-chain lakehouse at Proseware is moving from proof of concept to production. Before rollout, the data governance group must hide a sensitive table or column metadata from a class of semantic-model users, while ensuring that the team wants predictable performance and behavior. Which action best meets both needs? Existing users should keep their current access.

  1. Assign the developers the Contributor workspace role
  2. Use the PBIP project format and commit the project folder
  3. Use the XMLA endpoint to manage the semantic model programmatically
  4. Connect the workspace to a supported Git repository by using Fabric Git integration
  5. Configure object-level security for the protected table or column

Correct answer: E

Why: OLS prevents users from discovering or querying protected model objects. This directly matches the stated requirement.

Option review:

A: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: OLS prevents users from discovering or querying protected model objects. This directly matches the stated requirement.

Learning point: Configure object-level security for the protected table or column

Question 33

Blue Yonder Airlines has a change request for the IoT telemetry solution: allow a read-only user to access only selected OneLake folders or tables. The enterprise reporting group wants a solution where the choice should use a native Fabric capability. Which implementation is most suitable? Existing users should keep their current access.

  1. Apply the appropriate Microsoft Purview sensitivity label to the item
  2. Create a OneLake security role scoped to the required folders or tables
  3. Assign the developers the Contributor workspace role
  4. Apply the required sensitivity label to the report
  5. Save the solution as a Power BI Desktop project (.pbip)

Correct answer: B

Why: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This directly matches the stated requirement.

Option review:

A: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This directly matches the stated requirement.

C: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Create a OneLake security role scoped to the required folders or tables

Question 34

A solution architect reviewing Fabrikam’s finance reporting platform asks the finance analytics squad to restrict access to sensitive columns while leaving other data in the same analytics store available. Since the design should minimize duplicated data, which recommendation is strongest? Existing users should keep their current access.

  1. Create a Power BI template (.pbit) file
  2. Certify the semantic model
  3. Apply column-level security to the sensitive columns
  4. Use the item Manage permissions or sharing experience for that item
  5. Connect to the workspace XMLA endpoint with read/write operations enabled

Correct answer: C

Why: Column-level security restricts access at the column boundary while preserving access to permitted data. This directly matches the stated requirement.

Option review:

A: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: Column-level security restricts access at the column boundary while preserving access to permitted data. This directly matches the stated requirement.

D: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Apply column-level security to the sensitive columns

Question 35

The next sprint for Litware’s retail performance dashboard includes a task to show each regional manager only rows for that manager region in the semantic model. The acceptance criteria add that least privilege must be preserved. Which Fabric or Power BI action is appropriate? No unrelated workspace or model permissions should be changed.

  1. Use the item Manage permissions or sharing experience for that item
  2. Create a Power BI template (.pbit) file
  3. Define and assign row-level security roles for the semantic model
  4. Connect the workspace to a supported Git repository by using Fabric Git integration
  5. Assign the release lead the Member workspace role

Correct answer: C

Why: RLS filters rows by user or role so consumers see only the permitted records. This directly matches the stated requirement.

Option review:

A: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: RLS filters rows by user or role so consumers see only the permitted records. This directly matches the stated requirement.

D: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Define and assign row-level security roles for the semantic model

Question 36

Woodgrove Bank is troubleshooting a design decision in the marketing semantic model. The desired end state is to hide a sensitive table or column metadata from a class of semantic-model users; the rollout must support controlled validation. Which change should the operations data team make? No unrelated workspace or model permissions should be changed.

  1. Configure object-level security for the protected table or column
  2. Grant Build permission on the semantic model rather than a workspace role
  3. Assign the auditors the Viewer workspace role
  4. Configure deployment rules for the target stage
  5. Use Fabric lineage and impact analysis before making the change

Correct answer: A

Why: OLS prevents users from discovering or querying protected model objects. This directly matches the stated requirement.

Option review:

A: OLS prevents users from discovering or querying protected model objects. This directly matches the stated requirement.

B: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Configure object-level security for the protected table or column

Question 37

For the supply-chain lakehouse, Coho Winery has documented a business requirement to allow a read-only user to access only selected OneLake folders or tables. The data governance group must meet it in a way where the team wants predictable performance and behavior. What is the best choice? No unrelated workspace or model permissions should be changed.

  1. Use the PBIP project format and commit the project folder
  2. Use the XMLA endpoint to manage the semantic model programmatically
  3. Share only that report and grant the required item permission
  4. Connect the workspace to a supported Git repository by using Fabric Git integration
  5. Create a OneLake security role scoped to the required folders or tables

Correct answer: E

Why: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This directly matches the stated requirement.

Option review:

A: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This directly matches the stated requirement.

Learning point: Create a OneLake security role scoped to the required folders or tables

Question 38

A governance review of Adventure Works’s IoT telemetry solution asks for evidence that the solution can restrict access to sensitive columns while leaving other data in the same analytics store available. Because the choice should use a native Fabric capability, which action should be approved? No unrelated workspace or model permissions should be changed.

  1. Share only that report and grant the required item permission
  2. Connect to the workspace XMLA endpoint with read/write operations enabled
  3. Grant Build permission on the semantic model rather than a workspace role
  4. Use the PBIP project format and commit the project folder
  5. Apply column-level security to the sensitive columns

Correct answer: E

Why: Column-level security restricts access at the column boundary while preserving access to permitted data. This directly matches the stated requirement.

Option review:

A: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: Column-level security restricts access at the column boundary while preserving access to permitted data. This directly matches the stated requirement.

Learning point: Apply column-level security to the sensitive columns

Question 39

Before expanding the finance reporting platform, the finance analytics squad at Tailspin Toys must show each regional manager only rows for that manager region in the semantic model. The rollout plan says that the design should minimize duplicated data. Which option most directly addresses the requirement? The team will validate the change first in a nonproduction environment.

  1. Grant Build permission on the semantic model rather than a workspace role
  2. Share only that report and grant the required item permission
  3. Define and assign row-level security roles for the semantic model
  4. Use the XMLA endpoint to manage the semantic model programmatically
  5. Create and distribute a Power BI data source (.pbids) file

Correct answer: C

Why: RLS filters rows by user or role so consumers see only the permitted records. This directly matches the stated requirement.

Option review:

A: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: RLS filters rows by user or role so consumers see only the permitted records. This directly matches the stated requirement.

D: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Define and assign row-level security roles for the semantic model

Question 40

Fourth Coffee is redesigning its retail performance dashboard. The analytics engineering team must hide a sensitive table or column metadata from a class of semantic-model users. In addition, least privilege must be preserved. Which action is the best fit? The team will validate the change first in a nonproduction environment.

  1. Promote the item
  2. Use Fabric lineage and impact analysis before making the change
  3. Assign the release lead the Member workspace role
  4. Use the PBIP project format and commit the project folder
  5. Configure object-level security for the protected table or column

Correct answer: E

Why: OLS prevents users from discovering or querying protected model objects. This directly matches the stated requirement.

Option review:

A: Promotion is appropriate for recommended content that has not gone through the formal certification process. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: OLS prevents users from discovering or querying protected model objects. This directly matches the stated requirement.

Learning point: Configure object-level security for the protected table or column

Question 41

During a design review for Wide World Importers’s marketing semantic model, one requirement is non-negotiable: allow a read-only user to access only selected OneLake folders or tables. Because the rollout must support controlled validation, what should the operations data team implement? The team will validate the change first in a nonproduction environment.

  1. Configure deployment rules for the target stage
  2. Create a OneLake security role scoped to the required folders or tables
  3. Save the solution as a Power BI Desktop project (.pbip)
  4. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  5. Use the XMLA endpoint to manage the semantic model programmatically

Correct answer: B

Why: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This directly matches the stated requirement.

Option review:

A: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This directly matches the stated requirement.

C: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Create a OneLake security role scoped to the required folders or tables

Question 42

The data governance group at Northwind Traders is preparing the next release of its supply-chain lakehouse. They need to restrict access to sensitive columns while leaving other data in the same analytics store available; the team wants predictable performance and behavior. Which choice most directly satisfies the requirement? The team will validate the change first in a nonproduction environment.

  1. Assign the release lead the Member workspace role
  2. Apply the required sensitivity label to the report
  3. Apply column-level security to the sensitive columns
  4. Share only that report and grant the required item permission
  5. Assign the developers the Contributor workspace role

Correct answer: C

Why: Column-level security restricts access at the column boundary while preserving access to permitted data. This directly matches the stated requirement.

Option review:

A: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: Column-level security restricts access at the column boundary while preserving access to permitted data. This directly matches the stated requirement.

D: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Apply column-level security to the sensitive columns

Question 43

A production readiness review at Trey Research found a gap in the IoT telemetry solution. The remediation must show each regional manager only rows for that manager region in the semantic model, and the choice should use a native Fabric capability. What is the most appropriate action? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Define and assign row-level security roles for the semantic model
  2. Connect to the workspace XMLA endpoint with read/write operations enabled
  3. Assign the developers the Contributor workspace role
  4. Create a Power BI template (.pbit) file
  5. Certify the semantic model

Correct answer: A

Why: RLS filters rows by user or role so consumers see only the permitted records. This directly matches the stated requirement.

Option review:

A: RLS filters rows by user or role so consumers see only the permitted records. This directly matches the stated requirement.

B: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Define and assign row-level security roles for the semantic model

Question 44

For a new phase of the finance reporting platform, Alpine Ski House asks the finance analytics squad to hide a sensitive table or column metadata from a class of semantic-model users. The architecture decision record also states that the design should minimize duplicated data. Which approach should be selected? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Save the solution as a Power BI Desktop project (.pbip)
  2. Assign the developers the Contributor workspace role
  3. Assign the auditors the Viewer workspace role
  4. Assign the platform owner the Admin workspace role
  5. Configure object-level security for the protected table or column

Correct answer: E

Why: OLS prevents users from discovering or querying protected model objects. This directly matches the stated requirement.

Option review:

A: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

D: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: OLS prevents users from discovering or querying protected model objects. This directly matches the stated requirement.

Learning point: Configure object-level security for the protected table or column

Question 45

Contoso is standardizing how the retail performance dashboard is managed. The immediate goal is to allow a read-only user to access only selected OneLake folders or tables. Given that least privilege must be preserved, which option should the analytics engineering team choose? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Certify the semantic model
  2. Apply the appropriate Microsoft Purview sensitivity label to the item
  3. Create a OneLake security role scoped to the required folders or tables
  4. Assign the platform owner the Admin workspace role
  5. Create and distribute a Power BI data source (.pbids) file

Correct answer: C

Why: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This directly matches the stated requirement.

Option review:

A: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

B: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

C: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This directly matches the stated requirement.

D: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

E: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Implement row-level, column-level, object-level, and file-level access control’.

Learning point: Create a OneLake security role scoped to the required folders or tables

Question 46

An internal audit of Wingtip Toys’s customer 360 model identifies this requirement: classify a finance semantic model as confidential so the classification travels with supported downstream content. The BI platform team also notes that the rollout must support controlled validation. What should they do? Existing users should keep their current access.

  1. Define and assign row-level security roles for the semantic model
  2. Assign the platform owner the Admin workspace role
  3. Create a Power BI template (.pbit) file
  4. Apply the appropriate Microsoft Purview sensitivity label to the item
  5. Use Fabric Git integration and map the development workspace to the appropriate repository branch

Correct answer: D

Why: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Option review:

A: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

E: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the appropriate Microsoft Purview sensitivity label to the item

Question 47

The sales analytics solution at Proseware is moving from proof of concept to production. Before rollout, the security analytics team must mark a report that contains regulated personal data with the organization standard information-protection classification, while ensuring that the team wants predictable performance and behavior. Which action best meets both needs? Existing users should keep their current access.

  1. Configure deployment rules for the target stage
  2. Save the solution as a Power BI Desktop project (.pbip)
  3. Define and assign row-level security roles for the semantic model
  4. Review downstream dependencies in the lineage or impact-analysis view
  5. Apply the required sensitivity label to the report

Correct answer: E

Why: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Option review:

A: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Dependency analysis exposes which artifacts consume the changed object and therefore require validation. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Learning point: Apply the required sensitivity label to the report

Question 48

Blue Yonder Airlines has a change request for the risk analytics environment: classify a finance semantic model as confidential so the classification travels with supported downstream content. The Fabric center of excellence wants a solution where the choice should use a native Fabric capability. Which implementation is most suitable? No unrelated workspace or model permissions should be changed.

  1. Publish and reuse a shared semantic model
  2. Review downstream dependencies in the lineage or impact-analysis view
  3. Configure object-level security for the protected table or column
  4. Apply the appropriate Microsoft Purview sensitivity label to the item
  5. Create a deployment pipeline with separate lifecycle stages

Correct answer: D

Why: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Option review:

A: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: Dependency analysis exposes which artifacts consume the changed object and therefore require validation. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: OLS prevents users from discovering or querying protected model objects. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

E: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the appropriate Microsoft Purview sensitivity label to the item

Question 49

A solution architect reviewing Fabrikam’s service-operations warehouse asks the customer insights team to mark a report that contains regulated personal data with the organization standard information-protection classification. Since the design should minimize duplicated data, which recommendation is strongest? No unrelated workspace or model permissions should be changed.

  1. Use the PBIP project format and commit the project folder
  2. Configure deployment rules for the target stage
  3. Apply the required sensitivity label to the report
  4. Save the solution as a Power BI Desktop project (.pbip)
  5. Create a Power BI template (.pbit) file

Correct answer: C

Why: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Option review:

A: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

D: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the required sensitivity label to the report

Question 50

The next sprint for Litware’s executive reporting workspace includes a task to classify a finance semantic model as confidential so the classification travels with supported downstream content. The acceptance criteria add that least privilege must be preserved. Which Fabric or Power BI action is appropriate? The team will validate the change first in a nonproduction environment.

  1. Grant Build permission on the semantic model rather than a workspace role
  2. Save the solution as a Power BI Desktop project (.pbip)
  3. Apply the appropriate Microsoft Purview sensitivity label to the item
  4. Apply column-level security to the sensitive columns
  5. Define and assign row-level security roles for the semantic model

Correct answer: C

Why: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Option review:

A: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

D: Column-level security restricts access at the column boundary while preserving access to permitted data. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the appropriate Microsoft Purview sensitivity label to the item

Question 51

Woodgrove Bank is troubleshooting a design decision in the customer 360 model. The desired end state is to mark a report that contains regulated personal data with the organization standard information-protection classification; the rollout must support controlled validation. Which change should the BI platform team make? The team will validate the change first in a nonproduction environment.

  1. Assign the release lead the Member workspace role
  2. Apply the required sensitivity label to the report
  3. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  4. Assign the developers the Contributor workspace role
  5. Create a OneLake security role scoped to the required folders or tables

Correct answer: B

Why: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Option review:

A: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

C: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the required sensitivity label to the report

Question 52

For the sales analytics solution, Coho Winery has documented a business requirement to classify a finance semantic model as confidential so the classification travels with supported downstream content. The security analytics team must meet it in a way where the team wants predictable performance and behavior. What is the best choice? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Grant Build permission on the semantic model rather than a workspace role
  2. Create and distribute a Power BI data source (.pbids) file
  3. Apply the appropriate Microsoft Purview sensitivity label to the item
  4. Use the PBIP project format and commit the project folder
  5. Connect the workspace to a supported Git repository by using Fabric Git integration

Correct answer: C

Why: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Option review:

A: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

D: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the appropriate Microsoft Purview sensitivity label to the item

Question 53

A governance review of Adventure Works’s risk analytics environment asks for evidence that the solution can mark a report that contains regulated personal data with the organization standard information-protection classification. Because the choice should use a native Fabric capability, which action should be approved? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Apply the required sensitivity label to the report
  2. Assign the release lead the Member workspace role
  3. Save the solution as a Power BI Desktop project (.pbip)
  4. Use the PBIP project format and commit the project folder
  5. Use the XMLA endpoint to manage the semantic model programmatically

Correct answer: A

Why: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Option review:

A: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

B: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the required sensitivity label to the report

Question 54

Before expanding the service-operations warehouse, the customer insights team at Tailspin Toys must classify a finance semantic model as confidential so the classification travels with supported downstream content. The rollout plan says that the design should minimize duplicated data. Which option most directly addresses the requirement? The design decision will be reviewed by both data engineering and BI owners.

  1. Certify the semantic model
  2. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  3. Grant Build permission on the semantic model rather than a workspace role
  4. Apply the appropriate Microsoft Purview sensitivity label to the item
  5. Create and distribute a Power BI data source (.pbids) file

Correct answer: D

Why: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Option review:

A: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

E: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the appropriate Microsoft Purview sensitivity label to the item

Question 55

Fourth Coffee is redesigning its executive reporting workspace. The retail insights team must mark a report that contains regulated personal data with the organization standard information-protection classification. In addition, least privilege must be preserved. Which action is the best fit? The design decision will be reviewed by both data engineering and BI owners.

  1. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  2. Apply the required sensitivity label to the report
  3. Connect to the workspace XMLA endpoint with read/write operations enabled
  4. Certify the semantic model
  5. Use the PBIP project format and commit the project folder

Correct answer: B

Why: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Option review:

A: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

C: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the required sensitivity label to the report

Question 56

During a design review for Wide World Importers’s customer 360 model, one requirement is non-negotiable: classify a finance semantic model as confidential so the classification travels with supported downstream content. Because the rollout must support controlled validation, what should the BI platform team implement? Existing users should keep their current access.

  1. Certify the semantic model
  2. Create a OneLake security role scoped to the required folders or tables
  3. Assign the auditors the Viewer workspace role
  4. Connect to the workspace XMLA endpoint with read/write operations enabled
  5. Apply the appropriate Microsoft Purview sensitivity label to the item

Correct answer: E

Why: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Option review:

A: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This can be valid for ‘Endorse items’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Learning point: Apply the appropriate Microsoft Purview sensitivity label to the item

Question 57

The security analytics team at Northwind Traders is preparing the next release of its sales analytics solution. They need to mark a report that contains regulated personal data with the organization standard information-protection classification; the team wants predictable performance and behavior. Which choice most directly satisfies the requirement? Existing users should keep their current access.

  1. Apply the required sensitivity label to the report
  2. Configure deployment rules for the target stage
  3. Share only that report and grant the required item permission
  4. Configure object-level security for the protected table or column
  5. Create a OneLake security role scoped to the required folders or tables

Correct answer: A

Why: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Option review:

A: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

B: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: Item-level sharing can grant access to a specific Fabric item without assigning a workspace role. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: OLS prevents users from discovering or querying protected model objects. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the required sensitivity label to the report

Question 58

A production readiness review at Trey Research found a gap in the risk analytics environment. The remediation must classify a finance semantic model as confidential so the classification travels with supported downstream content, and the choice should use a native Fabric capability. What is the most appropriate action? No unrelated workspace or model permissions should be changed.

  1. Save the solution as a Power BI Desktop project (.pbip)
  2. Create and distribute a Power BI data source (.pbids) file
  3. Configure deployment rules for the target stage
  4. Use the item Manage permissions or sharing experience for that item
  5. Apply the appropriate Microsoft Purview sensitivity label to the item

Correct answer: E

Why: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Option review:

A: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: A PBIDS file provides reusable connection information that helps authors connect to an approved data source. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Learning point: Apply the appropriate Microsoft Purview sensitivity label to the item

Question 59

For a new phase of the service-operations warehouse, Alpine Ski House asks the customer insights team to mark a report that contains regulated personal data with the organization standard information-protection classification. The architecture decision record also states that the design should minimize duplicated data. Which approach should be selected? No unrelated workspace or model permissions should be changed.

  1. Use the PBIP project format and commit the project folder
  2. Configure object-level security for the protected table or column
  3. Create a OneLake security role scoped to the required folders or tables
  4. Review downstream dependencies in the lineage or impact-analysis view
  5. Apply the required sensitivity label to the report

Correct answer: E

Why: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Option review:

A: PBIP externalizes project definitions so changes can be reviewed and versioned using standard source-control practices. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: OLS prevents users from discovering or querying protected model objects. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Dependency analysis exposes which artifacts consume the changed object and therefore require validation. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

E: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This directly matches the stated requirement.

Learning point: Apply the required sensitivity label to the report

Question 60

Contoso is standardizing how the executive reporting workspace is managed. The immediate goal is to classify a finance semantic model as confidential so the classification travels with supported downstream content. Given that least privilege must be preserved, which option should the retail insights team choose? The team will validate the change first in a nonproduction environment.

  1. Use the item Manage permissions or sharing experience for that item
  2. Grant Build permission on the semantic model rather than a workspace role
  3. Configure deployment rules for the target stage
  4. Apply the appropriate Microsoft Purview sensitivity label to the item
  5. Create a deployment pipeline with separate lifecycle stages

Correct answer: D

Why: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

Option review:

A: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

B: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

C: Deployment rules let selected settings, such as data-source or parameter values, vary by stage without changing the source artifact. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

D: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This directly matches the stated requirement.

E: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Apply sensitivity labels to items’.

Learning point: Apply the appropriate Microsoft Purview sensitivity label to the item

Question 61

An internal audit of Wingtip Toys’s marketing semantic model identifies this requirement: identify a centrally governed semantic model as the authoritative enterprise source. The operations data team also notes that the rollout must support controlled validation. What should they do? Existing users should keep their current access.

  1. Assign the release lead the Member workspace role
  2. Save the solution as a Power BI Desktop project (.pbip)
  3. Certify the semantic model
  4. Create a OneLake security role scoped to the required folders or tables
  5. Grant Build permission on the semantic model rather than a workspace role

Correct answer: C

Why: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Option review:

A: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

D: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Certify the semantic model

Question 62

The supply-chain lakehouse at Proseware is moving from proof of concept to production. Before rollout, the data governance group must signal that a useful dataset is recommended by its owners but has not completed central certification, while ensuring that the team wants predictable performance and behavior. Which action best meets both needs? Existing users should keep their current access.

  1. Assign the release lead the Member workspace role
  2. Use Fabric lineage and impact analysis before making the change
  3. Promote the item
  4. Publish and reuse a shared semantic model
  5. Create a deployment pipeline with separate lifecycle stages

Correct answer: C

Why: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

Option review:

A: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

D: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Promote the item

Question 63

Blue Yonder Airlines has a change request for the IoT telemetry solution: identify a centrally governed semantic model as the authoritative enterprise source. The enterprise reporting group wants a solution where the choice should use a native Fabric capability. Which implementation is most suitable? No unrelated workspace or model permissions should be changed.

  1. Define and assign row-level security roles for the semantic model
  2. Use Fabric lineage and impact analysis before making the change
  3. Publish and reuse a shared semantic model
  4. Certify the semantic model
  5. Review downstream dependencies in the lineage or impact-analysis view

Correct answer: D

Why: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Option review:

A: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

E: Dependency analysis exposes which artifacts consume the changed object and therefore require validation. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Certify the semantic model

Question 64

A solution architect reviewing Fabrikam’s finance reporting platform asks the finance analytics squad to signal that a useful dataset is recommended by its owners but has not completed central certification. Since the design should minimize duplicated data, which recommendation is strongest? No unrelated workspace or model permissions should be changed.

  1. Promote the item
  2. Create a deployment pipeline with separate lifecycle stages
  3. Create a OneLake security role scoped to the required folders or tables
  4. Apply the required sensitivity label to the report
  5. Apply the appropriate Microsoft Purview sensitivity label to the item

Correct answer: A

Why: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

Option review:

A: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

B: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Promote the item

Question 65

The next sprint for Litware’s retail performance dashboard includes a task to identify a centrally governed semantic model as the authoritative enterprise source. The acceptance criteria add that least privilege must be preserved. Which Fabric or Power BI action is appropriate? The team will validate the change first in a nonproduction environment.

  1. Create a OneLake security role scoped to the required folders or tables
  2. Assign the release lead the Member workspace role
  3. Certify the semantic model
  4. Create a deployment pipeline with separate lifecycle stages
  5. Create a Power BI template (.pbit) file

Correct answer: C

Why: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Option review:

A: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

D: Deployment pipelines support staged promotion, comparison, and controlled deployment of supported content. This can be valid for ‘Create and configure deployment pipelines’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Certify the semantic model

Question 66

Woodgrove Bank is troubleshooting a design decision in the marketing semantic model. The desired end state is to signal that a useful dataset is recommended by its owners but has not completed central certification; the rollout must support controlled validation. Which change should the operations data team make? The team will validate the change first in a nonproduction environment.

  1. Grant Build permission on the semantic model rather than a workspace role
  2. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  3. Promote the item
  4. Save the solution as a Power BI Desktop project (.pbip)
  5. Apply the appropriate Microsoft Purview sensitivity label to the item

Correct answer: C

Why: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

Option review:

A: Build permission enables creation of content from the semantic model while keeping unrelated workspace items out of scope. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

D: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Promote the item

Question 67

For the supply-chain lakehouse, Coho Winery has documented a business requirement to identify a centrally governed semantic model as the authoritative enterprise source. The data governance group must meet it in a way where the team wants predictable performance and behavior. What is the best choice? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  2. Apply the appropriate Microsoft Purview sensitivity label to the item
  3. Use the item Manage permissions or sharing experience for that item
  4. Review downstream dependencies in the lineage or impact-analysis view
  5. Certify the semantic model

Correct answer: E

Why: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Option review:

A: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: Dependency analysis exposes which artifacts consume the changed object and therefore require validation. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Learning point: Certify the semantic model

Question 68

A governance review of Adventure Works’s IoT telemetry solution asks for evidence that the solution can signal that a useful dataset is recommended by its owners but has not completed central certification. Because the choice should use a native Fabric capability, which action should be approved? The solution must work with the current Fabric architecture rather than a parallel custom platform.

  1. Apply the appropriate Microsoft Purview sensitivity label to the item
  2. Use the item Manage permissions or sharing experience for that item
  3. Save the solution as a Power BI Desktop project (.pbip)
  4. Promote the item
  5. Use the XMLA endpoint to manage the semantic model programmatically

Correct answer: D

Why: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

Option review:

A: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

E: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Promote the item

Question 69

Before expanding the finance reporting platform, the finance analytics squad at Tailspin Toys must identify a centrally governed semantic model as the authoritative enterprise source. The rollout plan says that the design should minimize duplicated data. Which option most directly addresses the requirement? The design decision will be reviewed by both data engineering and BI owners.

  1. Certify the semantic model
  2. Assign the platform owner the Admin workspace role
  3. Use the item Manage permissions or sharing experience for that item
  4. Assign the developers the Contributor workspace role
  5. Connect the workspace to a supported Git repository by using Fabric Git integration

Correct answer: A

Why: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Option review:

A: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

B: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Item permissions are scoped to an individual item and are appropriate when workspace-wide access is unnecessary. This can be valid for ‘Implement item-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: Contributor permits creation and modification of workspace content without the broader membership-management permissions of Member or Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Certify the semantic model

Question 70

Fourth Coffee is redesigning its retail performance dashboard. The analytics engineering team must signal that a useful dataset is recommended by its owners but has not completed central certification. In addition, least privilege must be preserved. Which action is the best fit? The design decision will be reviewed by both data engineering and BI owners.

  1. Create a OneLake security role scoped to the required folders or tables
  2. Assign the platform owner the Admin workspace role
  3. Promote the item
  4. Create a Power BI template (.pbit) file
  5. Assign the auditors the Viewer workspace role

Correct answer: C

Why: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

Option review:

A: OneLake security roles can scope data access to specific tables or folders for users who should not receive broad item write access. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

D: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: The Viewer role provides read access to workspace content without create, edit, or workspace-management rights. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Promote the item

Question 71

During a design review for Wide World Importers’s marketing semantic model, one requirement is non-negotiable: identify a centrally governed semantic model as the authoritative enterprise source. Because the rollout must support controlled validation, what should the operations data team implement? Existing users should keep their current access.

  1. Certify the semantic model
  2. Apply column-level security to the sensitive columns
  3. Assign the release lead the Member workspace role
  4. Connect the workspace to a supported Git repository by using Fabric Git integration
  5. Define and assign row-level security roles for the semantic model

Correct answer: A

Why: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Option review:

A: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

B: Column-level security restricts access at the column boundary while preserving access to permitted data. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: Fabric Git integration synchronizes supported workspace item definitions with source control for branching, review, and history. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: RLS filters rows by user or role so consumers see only the permitted records. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Certify the semantic model

Question 72

The data governance group at Northwind Traders is preparing the next release of its supply-chain lakehouse. They need to signal that a useful dataset is recommended by its owners but has not completed central certification; the team wants predictable performance and behavior. Which choice most directly satisfies the requirement? Existing users should keep their current access.

  1. Use Fabric lineage and impact analysis before making the change
  2. Apply the appropriate Microsoft Purview sensitivity label to the item
  3. Publish and reuse a shared semantic model
  4. Promote the item
  5. Save the solution as a Power BI Desktop project (.pbip)

Correct answer: D

Why: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

Option review:

A: Lineage and impact analysis reveal downstream dependencies so changes can be evaluated before deployment. This can be valid for ‘Perform impact analysis of downstream dependencies from lakehouses, warehouses, dataflows, and semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Sensitivity labels provide governance classification and can propagate through supported Power BI and Fabric workflows. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: A shared semantic model centralizes governed measures, relationships, and business logic for reuse across reports. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

E: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Promote the item

Question 73

A production readiness review at Trey Research found a gap in the IoT telemetry solution. The remediation must identify a centrally governed semantic model as the authoritative enterprise source, and the choice should use a native Fabric capability. What is the most appropriate action? No unrelated workspace or model permissions should be changed.

  1. Use Fabric Git integration and map the development workspace to the appropriate repository branch
  2. Use the XMLA endpoint to manage the semantic model programmatically
  3. Certify the semantic model
  4. Connect to the workspace XMLA endpoint with read/write operations enabled
  5. Assign the platform owner the Admin workspace role

Correct answer: C

Why: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Option review:

A: Workspace-to-branch integration provides source-controlled collaboration for supported Fabric items. This can be valid for ‘Configure version control for a workspace’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

D: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: Admin is the workspace role intended for full workspace administration, including permissions and settings. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Certify the semantic model

Question 74

For a new phase of the finance reporting platform, Alpine Ski House asks the finance analytics squad to signal that a useful dataset is recommended by its owners but has not completed central certification. The architecture decision record also states that the design should minimize duplicated data. Which approach should be selected? No unrelated workspace or model permissions should be changed.

  1. Promote the item
  2. Create a Power BI template (.pbit) file
  3. Save the solution as a Power BI Desktop project (.pbip)
  4. Connect to the workspace XMLA endpoint with read/write operations enabled
  5. Assign the release lead the Member workspace role

Correct answer: A

Why: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

Option review:

A: Promotion is appropriate for recommended content that has not gone through the formal certification process. This directly matches the stated requirement.

B: A PBIT captures reusable report and model definitions while omitting imported data. This can be valid for ‘Create and update reusable assets, including Power BI template (.pbit) files, Power BI data source (.pbids) files, and shared semantic models’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

C: PBIP stores report and semantic-model definitions as project files that work better with source control and developer workflows. This can be valid for ‘Create and manage a Power BI Desktop project (.pbip)’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: The XMLA endpoint exposes semantic-model metadata to supported external tools and automation for management and deployment. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Promote the item

Question 75

Contoso is standardizing how the retail performance dashboard is managed. The immediate goal is to identify a centrally governed semantic model as the authoritative enterprise source. Given that least privilege must be preserved, which option should the analytics engineering team choose? The team will validate the change first in a nonproduction environment.

  1. Apply the required sensitivity label to the report
  2. Certify the semantic model
  3. Use the XMLA endpoint to manage the semantic model programmatically
  4. Assign the release lead the Member workspace role
  5. Configure object-level security for the protected table or column

Correct answer: B

Why: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

Option review:

A: Sensitivity labels are the native mechanism for classifying protected content according to the information-protection policy. This can be valid for ‘Apply sensitivity labels to items’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

B: Certification is the stronger endorsement used for content that has been reviewed and approved as authoritative. This directly matches the stated requirement.

C: XMLA provides programmatic access to tabular semantic-model metadata for advanced lifecycle operations. This can be valid for ‘Deploy and manage semantic models by using the XMLA endpoint’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

D: Member supports creating, modifying, and sharing content while reserving full workspace administration for Admin. This can be valid for ‘Implement workspace-level access controls’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

E: OLS prevents users from discovering or querying protected model objects. This can be valid for ‘Implement row-level, column-level, object-level, and file-level access control’, but it does not directly satisfy the scenario requirement being tested under ‘Endorse items’.

Learning point: Certify the semantic model

Popular posts

img