Applying DLP Policies to Power BI Fabric Items

Answer Correct answer: C — Apply sensitivity labels to the semantic model and reports to enforce the DLP policy.

You have a Fabric tenant that contains a workspace named Workspace1. Workspace1 contains a single semantic model that has two Microsoft Power BI reports. You have a Microsoft 365 subscription that contains a data loss prevention (DLP) policy named DLP1. You need to apply DLP1 to the items in Workspace1. What should you do?

  1. Create a workspace identity.
  2. Apply a certified endorsement to the semantic model.
  3. Apply sensitivity labels to the semantic model and reports. Correct Answer
  4. Apply a master data endorsement to the semantic model.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your understanding of how Microsoft 365 governance tools integrate with Microsoft Fabric; the trap is confusing Fabric-specific endorsements or identities with standard M365 security labels.

To enforce a Microsoft 365 Data Loss Prevention (DLP) policy on Power BI items within a Fabric tenant, you must apply sensitivity labels. This question establishes that sensitivity labels are the bridge between M365 policies and Fabric content.

Candidates often select 'Create a workspace identity' because it sounds like a governance control, but workspace identities manage access, not data classification for DLP enforcement.

Community Discussion (3 comments)

wgaignard2 👍 2
Apply sensitivity labels to the semantic model and reports. https://learn.microsoft.com/en-us/fabric/governance/data-loss-prevention-configure
aks2304 👍 1 Selected: C
To apply the DLP policy (DLP1) to the items in Workspace1, you should apply sensitivity labels to the semantic model and reports. Sensitivity labels are used to classify and protect data across Microsoft 365 services, including Power BI So, the correct answer is C. Apply sensitivity labels to the semantic model and reports.
testtaker45 👍 2 Selected: C
Sensitivity Labels are usually integrated with DLP. C is the right answer.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Sensitivity labels are the primary mechanism in Microsoft 365 for classifying and protecting data. When a sensitivity label containing DLP rules is applied to a semantic model or report in Power BI/Fabric, the associated DLP policy is enforced on that content. This ensures that sensitive information is protected according to the organization's compliance standards.

Why the Other Options Are Wrong

Creating a workspace identity (Option A) manages permissions and access control lists, not data loss prevention. Certified endorsement (Option B) and master data endorsement (Option D) are related to data quality and governance workflows, not security policies or DLP enforcement. These options do not trigger Microsoft 365 DLP actions.

Community Comment Notes

Community consensus strongly supports Option C. As user wgaignard2 noted, applying sensitivity labels is the correct method for configuring DLP in Fabric. Another commenter, aks2304, emphasized that sensitivity labels classify data across Microsoft 365 services, including Power BI, making them essential for DLP integration.

Official Reference

Exam Strategy

Always look for 'Sensitivity Labels' when a question involves applying Microsoft 365 security policies (like DLP or encryption) to specific assets like files, emails, or reports. In Fabric, these labels extend M365 capabilities to analytical workloads.

Frequently Asked Questions

Why doesn't creating a workspace identity apply DLP?

Workspace identities manage access permissions and role assignments, not data classification or security policies like DLP.

Can I apply DLP directly without sensitivity labels?

No, in Microsoft 365 and Fabric, DLP policies are typically triggered and enforced through the application of sensitivity labels to the content.

Related Analysis

Practice All DP-600 Questions

Access 115 questions with complete answers and detailed explanations.

View Full DP-600 Practice Test →

← Back to DP-600 Study Guide