Security and Compliance Flashcards
7 cards from real PL 400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Compliance flashcards as text
A company requires that Power Platform environments only allow connections to Microsoft 365 connectors and block all third-party connectors. How should DLP policies be configured?
Answer: Set all Microsoft 365 connectors to Business and all others to Blocked
DLP policies support a Blocked classification that prevents connectors from being used in any flow or app within the policy scope.
Which Dataverse feature allows a developer to automatically share records with specific users or teams when a record meets defined criteria?
Answer: Access Teams
Access Teams allow dynamic sharing of individual records with specific users without changing ownership, ideal for scenario-based record access.
A Power Automate flow uses an HTTP connector to call an internal API that requires OAuth 2.0. The token must be refreshed automatically. Which approach is most appropriate?
Answer: Use a custom connector with OAuth 2.0 authentication configured
Custom connectors support OAuth 2.0 configuration that handles token acquisition and refresh automatically, abstracting credential management from the flow.
In Power Platform, what does the 'Minimum Privilege' principle mean when assigning Dataverse security roles?
Answer: Users should receive only the permissions necessary to perform their job functions
The principle of least privilege requires granting only the minimum permissions needed for a user to accomplish their intended tasks.
A developer needs to audit which users accessed sensitive Dataverse records over the past 30 days. Which feature provides this capability?
Answer: Dataverse auditing with audit log queries
Dataverse auditing tracks read, create, update, and delete operations on tables and can be queried through the audit log in the Power Platform admin center.
Which Azure AD feature can be used to require MFA for users accessing Power Apps in a specific environment based on their location?
Answer: Azure AD Conditional Access policies
Conditional Access policies can enforce MFA requirements for Power Platform applications based on conditions like user location, device compliance, or risk level.
A Power Apps portal (Power Pages) needs to allow anonymous users to submit forms but restrict record viewing to authenticated users. Which feature controls this?
Answer: Web roles with Entity permissions for authenticated users
Power Pages uses web roles and table permissions to control access; authenticated web roles can grant read access to records while anonymous users only submit.