certslothcertsloth
DP-700/Topic 02

Microsoft / Associate

Fabric Security, Governance and Shared Data

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Workspace access is broad; data rules need their own design.

Must remember

Separate workspace roles, item permissions and data-level controls. A user able to manage an item may have broader access than a consumer intended to see a subset. Apply supported row, column, object and folder/file controls at the layer and engine that actually serves the request. Test every access path, including shortcuts, SQL endpoints, Spark and reports.

OneLake security centralizes supported data-access policies, but feature scope, engine support and configured modes matter. SQL row-level predicates and column/object permissions solve different problems. Dynamic data masking changes displayed values for eligible queries; it is not encryption and not a substitute for restricting privileged/direct access.

Sensitivity labels communicate classification and apply supported protection/handling. Endorsement marks promoted or certified content under organizational governance. Neither replaces permission enforcement or validates business calculations. Audit logs record eligible actions for investigation; configure appropriate collection, retention and access.

Shortcuts reference data without an ordinary duplicate ingestion copy. Access to the shortcut and its target depends on the supported source/credential model. Validate trust boundaries, data residency and external connectivity. A shortcut can fail because its target, connection or permission changed even when its local definition remains intact.

Choose under exam pressure

Requirement Choice and reason
Consumer sees only their business unit Supported row-level rules with tested consumer access.
Hide a displayed sensitive value Masking where appropriate, plus real authorization controls.
Share existing lake data without copying A supported shortcut with validated target access.

Traps

  • Masked does not mean encrypted.
  • One working query path does not prove every engine enforces identical permissions.

Active recall

1. Why test multiple engines?

They may access the same data through different authorization paths.

2. What does a sensitivity label indicate?

Classification and supported handling/protection requirements.

3. What does endorsement indicate?

An organizational trust/governance signal.

4. Why can a shortcut break?

The target, connection or permissions can change independently.

5. What should audit evidence include?

The relevant actor, operation, item and time, retained under appropriate controls.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.