Power Platform Administration, Security & Governance
10 free practice questions with explanations
10 free questions · instant explanations · no sign-up
PassNova has 10 free Microsoft PL-900 (Power Platform Fundamentals) practice questions on Power Platform Administration, Security & Governance, each with a clear explanation. Practise them in the browser with instant feedback — 100% free, no sign-up, on any device. Updated for 2026.
Power Platform Administration, Security & Governance: example questions & answers
10 worked examples with answers and explanations below. Practise them in the browser with instant feedback on every answer.
What is a Power Platform environment, as defined by Microsoft Learn?
- AA container that holds an organization's business data, apps, flows, agents and other resources✓
- BA connector category used to classify apps for Data Loss Prevention policies
- CA security role that grants a user permission to edit a specific app
- DA single Dataverse table used to store configuration settings for an app
Answer: A Power Platform environment is a container that holds an organization's business data, apps, flows, agents and other resources, allowing them to be organized and separated by role, security requirement or development stage. It is a much broader concept than a single Dataverse table, which stores only one kind of record within an environment. It is also distinct from a Data Loss Prevention connector category, which classifies connectors rather than resources, and from a security role, which grants permissions rather than containing resources.
An administrator wants to prevent makers from sharing a canvas app with the entire organization, restricting sharing to specific security groups instead. Which Managed Environments feature provides this control?
- ASolution checker enforcement
- BEnvironment routing
- CLimit sharing✓
- DIP Firewall
Answer: Limit sharing lets administrators restrict how broadly users share canvas apps, preventing sharing with the whole organization or limiting it to specific security groups. IP Firewall instead restricts access to Power Platform resources based on allowed IP address ranges, not app-sharing scope. Environment routing directs makers to personal developer environments, and solution checker enforcement blocks deployments that violate best-practice rules, neither of which controls app sharing.
Which Microsoft Entra ID capability requires a user to verify their identity through a second factor, such as a mobile app notification, in addition to their password?
- AData Loss Prevention (DLP) policy
- BCustomer-managed key (CMK)
- CMultifactor authentication (MFA)✓
- DRole-based access control (RBAC)
Answer: Multifactor authentication requires users to verify their identity through a second factor, such as a mobile app notification, a phone call or a biometric scan, in addition to their password, significantly reducing the risk from a compromised password alone. Role-based access control instead governs what an authenticated user is allowed to do, not how they prove their identity. A Data Loss Prevention policy controls connector data flows, and a customer-managed key is an encryption option, neither of which is a second authentication factor.
When configuring a Data Loss Prevention policy, an administrator categorizes a personal social media connector so that it cannot exchange data with Dataverse or SharePoint. Which connector group does that social media connector belong to?
- AManaged
- BNon-business✓
- CBlocked
- DBusiness
Answer: The Non-business group is for connectors that should not interact with sensitive business data, such as personal email services or social media platforms, which is exactly why they are kept separate from Business-group connectors like Dataverse and SharePoint. The Business group is instead reserved for connectors approved for sensitive data, the opposite of the social media example. Blocked connectors are prohibited from use entirely rather than merely separated from business data, and Managed is not one of the three DLP connector categories described.
Contoso's European operations run in an EU-based Power Platform environment. What does this guarantee about the customer and manufacturing data collected there?
- AIt is exempt from Microsoft's standard encryption at rest requirements
- BIt can only be accessed by administrators, never by licensed end users
- CIt remains within the designated EU region because of the environment's data residency✓
- DIt is automatically replicated to every regional environment in the tenant
Answer: Environments created within a tenant can target specific geographic regions, and data stored in Dataverse within those environments remains within the designated region, so Contoso's EU environment keeps its data in the EU without extra configuration. This is the opposite of automatic replication across every regional environment, which would undermine data residency rather than support it. Data residency also does not exempt data from standard AES 256-bit encryption at rest, and it does not restrict access to administrators only, since licensed end users still work with the data under normal security roles.
Which accessibility conformance target does Microsoft state it aims for across Power Platform, including Power Apps and Power BI?
- AISO 27001
- BWCAG 2.2 AA✓
- CSection 508 only, with no WCAG alignment
- DWCAG 2.0 A
Answer: Across Power Platform, Microsoft targets conformance with Web Content Accessibility Guidelines (WCAG) 2.2 AA standards, the most widely recognized accessibility guidelines for web-based technology, noting that WCAG 2.2 is backward-compatible with WCAG 2.1 while adding mobile and cognitive accessibility criteria. WCAG 2.0 A is an earlier, lower conformance level than the one Microsoft targets. ISO 27001 is an information security management standard rather than an accessibility guideline, and the source material does not describe Power Platform accessibility as limited to Section 508 with no WCAG alignment.
In the Power Platform admin center, which area is dedicated to understanding solution health and detecting performance degradations or failures in near real time?
- ASecurity
- BManage
- CDeployment
- DMonitor✓
Answer: Monitor is the dedicated area of the Power Platform admin center for understanding the health of solutions and detecting performance degradations or failures in near real time. Manage instead provides access to environment settings, resource inventory and capacity usage rather than real-time health detection. Security covers the organization's security score and policy gaps, and Deployment centralizes Power Platform ALM pipeline activity, neither of which is focused on real-time solution health.
Which built-in Power Automate analytics report shows the volume of flow runs over time, broken down by success and failure rates?
- AThe Usage report
- BThe Runs report✓
- CThe Error report
- DThe Connectors report
Answer: The Runs report shows the volume of flow runs over time, broken down by success and failure rates, giving administrators a direct view of overall flow reliability. The Connectors report instead shows which connectors are in active use across flows, useful for validating DLP coverage rather than run volume. The Usage report tracks which flows run most frequently and which connectors they use, and the Error report identifies flows that encountered errors along with the error messages, neither of which is framed around success-versus-failure run volume.
Which component of the Power Platform Center of Excellence (CoE) Starter Kit provides tenant-wide insights into app and flow inventory, maker activity and governance compliance status?
- AThe Power BI dashboard✓
- BThe Nurture components
- CThe Audit components
- DThe Governance components
Answer: The CoE Starter Kit's Power BI dashboard provides tenant-wide insights into app and flow inventory, maker activity, connector usage and governance compliance status. Governance components instead automate workflows such as requesting business justifications from makers, rather than presenting a dashboard. Nurture components support maker onboarding and training programs, and Audit components help track changes and compliance risks, but neither is the dashboard that visualizes tenant-wide inventory and activity.
In Power Platform ALM, an administrator configures a pipeline stage so that a deployment to a sensitive production environment runs under a service principal's identity, without giving the requesting maker direct access to that environment. What is this configuration called?
- AA delegated deployment✓
- BA preflight check
- CAn unmanaged solution
- DAn environment group
Answer: A delegated deployment carries out the deployment using a service principal or pipeline stage owner's identity rather than the requesting maker's, letting makers request deployments to sensitive environments without needing direct access, in line with least privilege. An unmanaged solution instead describes an editable solution used during development, not a deployment identity mechanism. A preflight check is the Solution Checker validation that runs before a deployment proceeds, and an environment group is a way of grouping environments for consistent policy application, neither of which describes running a deployment under a delegated identity.