DP-600 - Maintain a Data Analytics Solution - Section 1.3

Apply sensitivity labels and endorse items to govern a Microsoft Fabric analytics solution.

Apply sensitivity labels from Microsoft Purview Information Protection to Fabric items and understand how label inheritance propagates a label from a dataset to downstream reports. Distinguish between promoting an item and certifying it, and recognise which roles can perform each endorsement action.

sensitivity labelsMicrosoft Purview Information Protectionpromoted itemscertified itemslabel inheritance

Practice question for this objective

Free sampleMaintain a Data Analytics Solutionmedium

A governance lead must classify a "Microsoft Fabric" "semantic model" as confidential so that the classification drives encryption and access enforcement, and must travel with the data wherever it goes. A separate concern is signalling to other teams that the model is a recommended, trusted asset to reuse. Which capability should the lead apply to satisfy the classification-and-protection requirement?

  • AA certified endorsement, because certification marks the model as an authoritative asset and encrypts its underlying data at the document level for downstream consumers.
  • BA sensitivity label backed by Microsoft Purview Information Protection, because the label classifies the model and carries encryption and access policy that persist with exported data. Correct
  • CA promoted endorsement, because promotion lets the owner flag the model as recommended and then attaches an information-protection policy that restricts who can open the data.
  • DA workspace role assignment, because granting Viewer at the workspace level controls who can read the model and thereby protects the confidential figures inside it.
Sensitivity labels from Microsoft Purview Information Protection, not endorsement, provide the classification and persistent encryption that travels with Fabric data. Sensitivity labels integrate Microsoft Purview Information Protection with Fabric, so the label both classifies the item and attaches encryption and access policy that remain bound to the data when it leaves the service. Endorsement and workspace roles address trust and access scope, neither of which enforces protection that persists with exported content.

Why A is wrong: Certification signals trust and authority for reuse, but it applies no encryption and enforces no access control, so it cannot satisfy the classification-and-protection requirement.

Why B is correct: Sensitivity labels defined in Microsoft Purview classify the item and apply persistent encryption and access enforcement that travel with the data, which is exactly what the requirement asks for.

Why C is wrong: Promotion only flags an item as recommended for reuse; it carries no encryption or access policy, so it cannot enforce classification-driven protection on the data.

Why D is wrong: Workspace roles govern access inside the workspace only and do not classify the item or protect data after export, so the protection does not travel with the file.

See more DP-600 practice questions, answers explained.

More in this domain

Back to all Maintain a Data Analytics Solution objectives, or the DP-600 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.