DP-700 - Implement and Manage an Analytics Solution - Section 1.5

Configure and implement OneLake security, sensitivity labels, item endorsement, and Microsoft Fabric audit logs.

Configure OneLake data access roles, apply sensitivity labels with label inheritance, and endorse items as promoted or certified in Microsoft Fabric. Use Microsoft Fabric audit logs and Microsoft Purview integration to govern data access and track activity.

OneLake security and data access rolessensitivity labels and label inheritanceendorsement (promote and certify)Microsoft Fabric audit logsMicrosoft Purview integration

Practice question for this objective

Free sampleImplement and Manage an Analytics Solutionmedium

An organisation has integrated Microsoft Purview with Microsoft Fabric and published sensitivity labels for use across the tenant. A data engineer applies the Confidential label to a Lakehouse, and another engineer later builds a semantic model and a report from that Lakehouse. The governance team wants to understand the prerequisites and behaviour of sensitivity labels for Fabric content. Which TWO statements about sensitivity labels in Microsoft Fabric are correct? Select TWO.

  • ASensitivity labels can be applied to Fabric items only after a workspace administrator converts the workspace into a dedicated Purview compliance workspace first.
  • BSensitivity labels must be created and published in Microsoft Purview and enabled for Fabric in the tenant before users can apply them to Fabric items. Correct
  • CApplying a label to a Fabric item encrypts the underlying OneLake Parquet files so that even tenant administrators cannot read them without the label's key.
  • DWhen a child item such as a semantic model is created from a labelled source, the label can be inherited downstream so classification follows the lineage. Correct
Sensitivity labels are published in Microsoft Purview, enabled for the Fabric tenant, then applied to items where they can inherit downstream. Sensitivity labels are authored and published in Microsoft Purview and require the Fabric tenant setting that permits applying them; once applied, label inheritance lets a label flow to child items created from a labelled source so the classification follows lineage, rather than encrypting the raw OneLake files.

Why A is wrong: It is tempting because Purview governs the labels, but no special compliance workspace exists; labels are published in Purview and enabled tenant-wide for Fabric, then applied to ordinary items.

Why B is correct: Labels originate in the Purview compliance portal and require the Fabric tenant setting that allows applying labels, so this prerequisite chain is correct.

Why C is wrong: This overstates protection; labels classify items and can drive encryption on exports, but they do not encrypt the OneLake storage files themselves in this manner.

Why D is correct: Downstream inheritance propagates a source item's label to items built from it, so the classification follows the data lineage as described.

See more DP-700 practice questions, answers explained.

More in this domain

Back to all Implement and Manage an Analytics Solution objectives, or the DP-700 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.