Microsoft Certified Power Bi Data Analyst Associate · Free Practice Question Easy
Question 27
Your Power BI report displays sensitive information like customers’ Social Security Numbers to report users. You export the report from the service as PDF/PowerPoint and share it with your vendors for collaboration. You have to ensure that only the authorized users (in the vendor team) can access the exported reports.
Which of the following features would you use?
-
A
Row-level security
-
B
Sensitivity labels
-
C
Object-level security
-
D
Data loss prevention policies
Reveal correct answer
Correct answer: B
Explanation
Since we need to restrict/encrypt only the content that travels outside Power BI (export as PDF/PowerPoint), both row-level security and object-level security are incorrect.
Row-level security applies security by filtering/restricting data access at row-level for report users. Example: displaying only the US-related sales data.
Object-level security locks down specific tables/columns for report users. Example: don’t display the sales column.
Options A and C are incorrect.
Reference Link: https://docs.microsoft.com/en-us/power-bi/enterprise/service-admin-rls
https://www.youtube.com/watch?v=PAX5GP9SkTA
In Microsoft Purview Information Protection, you can create sensitivity labels (with encryption settings) to use in Power BI.

And control who has access to the Power BI content with this label applied. For example, only the approved vendor team members.

After you apply a sensitivity label to a Power BI report, the label has no effect on data for users who can access the reports. They will only see that a sensitivity label is applied to the report.

Quick Preview:

But, if you export this report as a PDF, the sensitivity label and its settings travel with the content. If you try to access the exported PDF in Adobe Reader, you will see a prompt to sign in.

Unauthorized users (not assigned permissions in the sensitivity label definition) cannot open the file.

Only if the user has permissions defined in the label definition, can he access the content.

Option B is the correct answer.
Reference Link: https://docs.microsoft.com/en-us/power-bi/enterprise/service-security-sensitivity-label-overview
A DLP policy for Power BI can use sensitivity labels to detect sensitive datasets and can perform either of the below two actions on dataset refresh/publish:
1. Provide user notification (to educate users about the organization’s policies).
2. Send alerts to administrators.

A DLP policy cannot block/prevent/encrypt the sharing of exported reports.
Reference Link: https://docs.microsoft.com/en-us/power-bi/enterprise/service-security-dlp-policies-for-power-bi#how-do-dlp-policies-for-power-bi-work
Option D is incorrect.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
