Microsoft Certified: Power Platform App Maker Associate Security and Governance in Power Platform 1 — Questions and Answers
Question 1: What is the primary tool used to manage Power Platform environments, data policies, and security settings across a tenant?
- Power Apps Studio
- Power Platform Admin Center (Correct answer)
- Azure Active Directory Portal
- Microsoft 365 Admin Center
Correct answer: Power Platform Admin Center
The Power Platform Admin Center is the central hub for administrators to manage environments, DLP policies, capacity, and tenant-wide security settings.
Question 2: What is the primary purpose of a Data Loss Prevention (DLP) policy in Power Platform?
- Encrypting data stored in Dataverse tables
- Preventing unauthorized users from launching apps
- Classifying connectors into groups to restrict which connectors can share data together (Correct answer)
- Backing up and recovering data from deleted environments
Correct answer: Classifying connectors into groups to restrict which connectors can share data together
DLP policies classify connectors into Business, Non-Business, or Blocked tiers to control which connectors can exchange data within the same app or flow.
Question 3: Which of the following is a valid set of Power Platform environment types?
- Production, Development, Test, and Archive
- Production, Sandbox, Trial, and Developer (Correct answer)
- Live, Staging, QA, and Backup
- Enterprise, Standard, Personal, and Free
Correct answer: Production, Sandbox, Trial, and Developer
Power Platform officially supports Production, Sandbox, Trial, and Developer environment types, each designed for different stages of the app lifecycle.
Question 4: Which minimum role is required at the tenant level to create a new Power Platform environment?
- Global Administrator or Power Platform Administrator (Correct answer)
- Any Microsoft 365 licensed user
- Dataverse Database Administrator
- Power Apps per-user plan holder
Correct answer: Global Administrator or Power Platform Administrator
Creating environments requires either the Global Administrator or Power Platform Administrator role, as it is a tenant-level administrative action.
Question 5: When a Canvas App is shared with a user in Power Apps, what is the minimum permission level that allows them to run the app without editing it?
- Owner
- Co-owner
- Can use (User) (Correct answer)
- Can edit
Correct answer: Can use (User)
The 'Can use' (User) permission allows users to run the app without the ability to modify or share it.
Question 6: Which Azure Active Directory feature is most commonly used to share Power Apps with multiple users simultaneously?
- Azure AD Privileged Identity Management
- Azure AD Security Groups and Microsoft 365 Groups (Correct answer)
- Azure AD Conditional Access Policies
- Azure AD Application Proxy
Correct answer: Azure AD Security Groups and Microsoft 365 Groups
Security Groups and Microsoft 365 Groups in Azure AD allow administrators to share apps and manage access for large groups of users efficiently.
Question 7: What happens to all apps, flows, and data when a Power Platform environment is deleted?
- They are automatically migrated to the default environment
- They are permanently deleted along with all environment data (Correct answer)
- They are exported to OneDrive for 30 days for recovery
- They become read-only for 30 days before permanent deletion
Correct answer: They are permanently deleted along with all environment data
Deleting a Power Platform environment permanently and irreversibly removes all apps, flows, connections, and data contained within it.
What is the primary tool used to manage Power Platform environments, data policies, and security settings across a tenant?