Prepstellar

DP-700 · Practice set 9 of 9

Workspace and Item Access Controls: 10 practice questions

10 questions · Untimed · Free

10 free DP-700 practice questions on Workspace and Item Access Controls, with an explanation for every answer. Untimed. The full mock exam and the timed version are in the app.

Set 9 · Workspace and Item Access Controls · 10 questions Read the lesson
  1. Question 1 of 10

    Which workspace role can view all content but cannot modify it?

    1. AViewer
    2. BContributor
    3. CAdmin
    4. DMember
    Show the answer

    Viewer is the workspace-wide read role; the other three roles include content modification capabilities.

    Next → 1 / 10
  2. Question 2 of 10

    What is the scope of an item permission in Fabric?

    1. AEvery item in one workspace
    2. BEvery item in the tenant
    3. CEvery workspace in one capacity
    4. DOne specific Fabric item
    Show the answer

    Item permissions use the narrow item boundary, unlike workspace roles that apply to all content in one workspace.

    Next → 2 / 10
  3. Question 3 of 10

    Which item permission is granted by default when a Fabric item is shared?

    1. ARead on the shared item
    2. BWrite on the shared item
    3. CReadAll on the workspace
    4. DAdmin on the workspace
    Show the answer

    Sharing starts with item-level Read, which permits the recipient to see the item rather than administer its workspace.

    Next → 3 / 10
  4. Question 4 of 10

    A user must view and modify every item in one workspace but must not receive workspace sharing or permission-management capabilities. Which role fits?

    1. AContributor in that workspace
    2. BMember in that workspace
    3. CViewer in that workspace
    4. DAdmin in that workspace
    Show the answer

    Contributor is the least privileged workspace role that can modify all content; Member adds sharing and Admin adds permission management.

    Next → 4 / 10
  5. Question 5 of 10

    A recipient can open a shared DirectLake report but cannot query its underlying Delta tables directly. What additional access addresses the missing capability?

    1. AReshare permission on the report
    2. BOneLake data permission on the tables
    3. CAnother Read grant on the report
    4. DViewer access to an unrelated workspace
    Show the answer

    Report Read and OneLake data access are separate; direct queries against the Delta tables require the OneLake side of the path.

    Next → 5 / 10
  6. Keep the ones you got wrong

    In the app, every question you miss comes back exactly when you’re about to forget it.

  7. Question 6 of 10

    A direct item permission is removed from a user who remains a Viewer in the item's workspace. What happens?

    1. AThe user can still view the item through the workspace role
    2. BThe user loses all visibility of the item immediately
    3. CThe user can now modify the item but cannot share it
    4. DThe Viewer role is automatically removed from the workspace
    Show the answer

    Direct item access and workspace-role access coexist, so removing the direct grant leaves the Viewer path intact.

    Next → 6 / 10
  8. Question 7 of 10

    How can a user with no workspace role receive access to one report without being able to browse the workspace?

    1. AAssign Contributor to the entire workspace
    2. BGrant Admin on the hosting capacity
    3. CAssign Viewer to the entire workspace
    4. DShare the report directly with the user
    Show the answer

    A direct item grant provides access through the shared link while preserving the boundary around the surrounding workspace.

    Next → 7 / 10
  9. Question 8 of 10

    An external recipient must view a shared DirectLake report and directly query its underlying Delta tables, while access to other workspace items remains unavailable. Which grants meet both requirements?

    1. AViewer on the workspace plus item Read on the report
    2. BItem Read on the report plus Reshare on that same report
    3. COneLake permission on the tables plus Viewer on every source workspace
    4. DItem Read on the report plus OneLake permission on the required tables
    Show the answer

    The item grant opens the report and the OneLake grant enables direct table queries without exposing every item in the workspace.

    Next → 8 / 10
  10. Question 9 of 10

    A regional lead must modify and share every item in the region's workspace, but must not manage workspace permissions or gain access to other regions. Which assignment is appropriate?

    1. AAdmin in the regional workspace
    2. BMember in the regional workspace
    3. CContributor in every regional workspace
    4. DViewer in the regional workspace
    Show the answer

    Member supplies modification and sharing within one workspace, while its scope remains confined to that region's workspace.

    Next → 9 / 10
  11. Question 10 of 10

    A former collaborator has both a direct report grant and Viewer in its workspace. The collaborator must lose the report link and all workspace visibility. Which change satisfies both constraints?

    1. AReplace the Viewer assignment with Contributor and remove Reshare
    2. BRemove the direct report grant but keep the Viewer assignment
    3. CKeep the direct report grant but remove the Viewer assignment
    4. DRemove the direct report grant and the Viewer assignment
    Show the answer

    Both independent access paths must be closed: the item grant supports the link and Viewer supports workspace-wide viewing.

    Next → 10 / 10
  12. You’ve finished this set

    That’s 10 questions on Workspace and Item Access Controls. In the app the ones you miss come back exactly when you’re about to forget them.

The whole course, on your phone

Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.