The answer is C. It's a trick question. It asks how the access for the sales department USERS needs to be set up. This requires RLS to work, and RLS won't work when they are member or admin. The requirements listed that require admin rights refer to the sales DEPARTMENT, not to the sales USERS.
ItsMeScripting is right. There is a difference between these two sections in the requirements:
"The sales department must be able to..."
and
"Users in the sales department must be able to..."
Only the latter is relevant to the question, and only C works for their limited functionality.
but who is the user in sales department? you are right. workspace roles always override RLS roles. It is really tricky. first I went with option C. but after reading the answer I am really confused!
I think it should be D - Add the sales department as a member of the reports workspace.
For the actions they need to perform (edit reports, publish app, etc) the Member role would be the least privilege
Sorry, but that isn't true.
A member can do the following: "Add members or others with lower permissions."
See: https://learn.microsoft.com/en-us/power-bi/collaborate-share/service-roles-new-workspaces
The only thing I know for sure is that it's not A, otherwise it's impossible. I threw the question at three different AI tools, and each one gave a different answer. I'd keep B (my first option)
The correct answer is C. By looking clearly at the question , it is asking about" users" in the Sales department. While the role description listed which for me it is a Admin role refer to the SALES DEPARTMENT. Beside it is said :"Users in the sales department must be able to access only the data of the sales region to which they are assigned in the Sales Employees table." C is the right answer. B and D are talking about SALES DEPARTMENT .
It says: "The sales department relies on the IT department to generate reports in Microsoft SQL Server Reporting Services (SSRS). The IT department takes too long to generate the reports and often misunderstands the report requirements."..
Sales department want to have the control of sales reports
For the Sales Department USERS to access the reports, they must access them through the app. That is the prescribed method for persons who should only have read access with RLS and negates other access to the workspace.
Sorry - I think that the correct answer is D - Tested-
The application will just allow you to consume the reports via the APP. But being a Member will allow you to modify reports, add users to the workspace and so on...
With this requirement: Assign Azure AD groups role-based access to the reports workspace.
As only Admins can ; Add or remove any user in a workspace role.
(https://learn.microsoft.com/en-us/power-bi/collaborate-share/service-roles-new-workspaces)
Considering an AD group is a User whose nature is a group of users (at least any user sharing the same privileges)
Seems We need to :
B. Add the Azure Active Directory group of the sales department as an Admin of the reports workspace.
the answer is B
B. Add the Azure Active Directory group of the sales department as an Admin of the reports workspace.
Here’s why:
Admin Privileges: The requirement for the sales department to create, edit, delete content, manage permissions, and control app distribution necessitates admin-level access to the workspace. This level of access allows users to perform all the listed tasks.
Azure AD Group for Access Control: Adding the Azure AD security group of the sales department to the workspace and assigning them admin roles aligns with the requirement to use Azure AD groups for access control.
RLS for Data Access: The use of RLS will ensure that even within the sales department, users will only be able to see data relevant to their sales region. The RLS expression [EmailAddress] = USERNAME() will filter data based on the user’s email address, which should correspond with the email addresses in the Sales Employees table.
D should be correct.
Members can be granted permissions to create, edit, and delete content, but unlike Admins, their access can be restricted by RLS. This setup would allow the sales department to manage content and permissions without granting them full Admin rights, which would override RLS.
i initially thought the answer was d but after reading the discussion, I realized that the security mentioned is only for the users of the sales department, not the whole sales department. So, my answer is C.
It is certainly not B or D, because RLS only applies to viewers. Both Amdin and Member can modify the dataset (write permission) and therefor the RLS is not applied.
I think the question is just wrong, you can´t manage app if you don't have at least member role, in the other hand rls is only applied for the viewer role.
I think the answer is D. When talking about security. We can have differents settings for the same user group at the level of Workspace and at the level of app. If we choose answer C we will not able to give the right to manage workspace to the sales departement. The answer is D. It can't be B, because of RLS. RLS can't be apply to Admin
C: In this case the only one that will correctly apply what was asked specifically for the Sales Department Users themselves is C. Anything else gives too much, wont work or not enough
This section is not available anymore. Please use the main Exam Page.PL-300 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ItsMeScripting
Highly Voted 2 years, 4 months ago539d541
7 months agomdeg87
2 years agoShalaleh
1 year, 12 months agoClodia
Highly Voted 2 years, 6 months agoFer079
2 years, 6 months agoshimmy_
2 years, 6 months agoMayaYao
2 years, 5 months agoHoeishetmogelijk
2 years, 4 months agoiccent2
2 years, 4 months ago33148b2
Most Recent 2 months agoSylUK
2 months ago_jay95_
3 months agoiloum
4 months, 4 weeks ago539d541
7 months agoJudT
1 year agoJudT
1 year agoDani_eL
1 year, 1 month ago10d9950
1 year, 3 months agoDsbuff
1 year, 3 months agodeyoz
1 year, 4 months ago_Dirk_
1 year, 4 months agoAldeus
1 year, 4 months agoLavoisier
1 year, 8 months agoMEG_Florida
1 year, 8 months agoKushal_P
1 year, 8 months ago