Security and Compliance Flashcards
7 cards from real PL 400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Compliance flashcards as text
A developer creates a custom API in Dataverse that should only be callable by other Dataverse processes, not external users. Which privilege controls this?
Answer: Mark the API as 'Is Private' in its definition
Setting a custom API as private prevents it from being discovered or called by external clients, limiting its use to internal Dataverse plugins and workflows.
When configuring a Dataverse plugin to run in the context of a specific user rather than the calling user, which approach should the developer use?
Answer: Use IOrganizationService impersonation with the target user's ID
The Dataverse plugin SDK supports impersonation by passing the initiating user's ID to IOrganizationServiceFactory.CreateOrganizationService(), allowing operations to run in that user's security context.
A company wants to prevent Power Platform users from exporting data from Dataverse to Excel. Which setting achieves this?
Answer: Disable the Export to Excel privilege in all security roles
Removing the 'Export to Excel' miscellaneous privilege from security roles prevents users from exporting Dataverse data to Excel directly from model-driven apps.
In Power Platform, what is the purpose of 'Environment Security Groups' in the Power Platform admin center?
Answer: To restrict who can access the environment by limiting it to group members
Setting a security group on an environment restricts environment access so only members of that Azure AD group can log in and use apps within it.
A developer needs to ensure that a Power Automate flow's service principal has the minimum required Dataverse permissions. Which role should be assigned to an application user for read-only reporting flows?
Answer: A custom security role with only Read privileges on required tables
Creating a custom security role with only the necessary read privileges follows least privilege principles and limits the blast radius of a compromised service principal.
Which Microsoft compliance feature can be used to apply sensitivity labels to data exported from Dataverse through Power BI?
Answer: Azure Information Protection labels via Microsoft Purview
Microsoft Purview Information Protection sensitivity labels can be applied to Power BI reports and datasets, including those sourced from Dataverse.
A developer is implementing a canvas app that connects to Dataverse. They want the app to always use the signed-in user's permissions rather than a shared service account. Which connection type ensures this?
Answer: Connect using 'Connect with the logged in user' (non-embedded) connection
Non-embedded connections in canvas apps pass through the signed-in user's identity to Dataverse, ensuring Dataverse security roles apply per individual user.