DP-500 · Question #57
You need to recommend an automated solution to monitor Power BI user activity. The solution must meet the following requirements: Security admins must identify when users export reports from Power…
This question tests knowledge of which Microsoft logging systems capture specific Power BI events, mapped to the correct administrative role under least-privilege principles. Two distinct log sources cover the two requirements.
Question
- Security admins must identify when users export reports from Power BI within five days of a new sensitivity label being applied to the artifacts in Power BI.
- Power BI admins must identify updates or changes to the Power BI capacity.
- The principle of least privilege must be used. Which log should you include in the recommendation for each group? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Explanation
This question tests knowledge of which Microsoft logging systems capture specific Power BI events, mapped to the correct administrative role under least-privilege principles. Two distinct log sources cover the two requirements.
Approach. For Security admins (sensitivity label + export correlation): The Microsoft Purview audit log (unified audit log) is correct because it captures both MicrosoftInformationProtection events (label applied) and Power BI export events (ExportReport, ExportArtifact) in a single queryable source, enabling a 5-day window correlation query - and security admins already have Purview Compliance Center access, satisfying least privilege. For Power BI admins (capacity changes): The Power BI activity log is correct because it records administrative operations including capacity updates and configuration changes; Power BI admins have native access to this log via the admin portal or REST API without needing broader Purview or Azure permissions, again satisfying least privilege.
Concept tested. Mapping Power BI monitoring requirements to the correct Microsoft log source (Microsoft Purview audit log vs. Power BI activity log) based on event type and role-appropriate access under the principle of least privilege.
Reference. https://learn.microsoft.com/en-us/power-bi/enterprise/service-admin-auditing - Power BI activity log and audit log overview, including sensitivity label tracking via Microsoft Purview.
Topics
Community Discussion
No community discussion yet for this question.