Prepstellar

DP-600 · Practice set 1 of 8

Workspace and Item Access Controls: 10 practice questions

10 questions · Untimed · Free

10 free DP-600 practice questions on Workspace and Item Access Controls, with an explanation for every answer. Untimed. The full mock exam and the timed version are in the app.

Set 1 · Workspace and Item Access Controls · 10 questions Read the lesson
  1. Question 1 of 10

    Which access mechanism applies to every item in a Fabric workspace?

    1. AA workspace role
    2. BA lakehouse Read permission
    3. CAn item permission
    4. DA SQL endpoint data permission
    Show the answer

    Workspace roles establish broad workspace scope; the other choices grant capabilities on an individual shared item.

    Next → 1 / 10
  2. Question 2 of 10

    What can a user with the Viewer workspace role do by default?

    1. AShare listed workspace content with underlying OneLake data access
    2. BView listed workspace content without underlying OneLake data access
    3. CCreate new workspace content with underlying SQL data access
    4. DModify listed workspace content without underlying SQL data access
    Show the answer

    Viewer is the read-oriented workspace role, but seeing listed Fabric items does not itself grant access to their underlying OneLake data.

    Next → 2 / 10
  3. Question 3 of 10

    What does the Read permission granted when sharing a lakehouse provide?

    1. AAccess to all data through the SQL endpoint
    2. BAccess to item metadata and associated reports
    3. CAccess to all data through Apache Spark
    4. DAccess to create items across the workspace
    Show the answer

    Lakehouse Read exposes the item and its report-facing surface, while underlying data access requires an additional permission.

    Next → 3 / 10
  4. Question 4 of 10

    Which workspace role can create and modify all content without adding sharing or permission-management capabilities?

    1. AMember
    2. BViewer workspace role
    3. CAdmin
    4. DContributor
    Show the answer

    Contributor supplies creation and modification while stopping below Member's sharing capability and Admin's permission management.

    Next → 4 / 10
  5. Question 5 of 10

    Where do you assign a user to a workspace role?

    1. ABuild reports on the default model
    2. BRead all SQL endpoint data for one item
    3. CManage access in the workspace
    4. DManage permissions on one item
    Show the answer

    Manage access is the workspace-level entry point for adding a user and choosing a workspace role.

    Next → 5 / 10
  6. Keep the ones you got wrong

    In the app, every question you miss comes back exactly when you’re about to forget it.

  7. Question 6 of 10

    Which additional lakehouse permission enables T-SQL reads from its SQL analytics endpoint?

    1. ARead all SQL endpoint data
    2. BRead item metadata and reports
    3. CBuild reports on the default semantic model
    4. DRead all Apache Spark and subscribe to events
    Show the answer

    SQL endpoint access is separated from basic item visibility, Spark and OneLake access, and report-building capability.

    Next → 6 / 10
  8. Question 7 of 10

    Which additional lakehouse permission supports creating Power BI reports on its default semantic model?

    1. ABuild reports on the default semantic model
    2. BManage access for the entire workspace
    3. CRead all Apache Spark and subscribe to events
    4. DRead all data from the SQL endpoint
    Show the answer

    Report construction on the default model is a distinct sharing capability from querying underlying lakehouse data.

    Next → 7 / 10
  9. Question 8 of 10

    An analyst needs to see one lakehouse's metadata and associated reports, but must not query its underlying data or access other workspace items. What should you grant?

    1. AAssign Contributor without additional item permissions
    2. BShare the lakehouse with Apache Spark access
    3. CAssign Viewer and grant SQL endpoint access
    4. DShare the lakehouse with Read permission
    Show the answer

    Item-level Read matches both boundaries: one lakehouse only, with metadata and reports but no underlying SQL or OneLake data.

    Next → 8 / 10
  10. Question 9 of 10

    A data engineer must create and modify items throughout a workspace. The engineer must not share content or manage permissions. Which role is the least-privileged fit?

    1. AAdmin
    2. BContributor
    3. CMember
    4. DViewer
    Show the answer

    Contributor covers workspace-wide creation and modification while excluding the higher-level capabilities named as restrictions.

    Next → 9 / 10
  11. Question 10 of 10

    A contractor needs T-SQL access to all data in one lakehouse but should receive neither Spark access nor workspace-wide membership. Which configuration matches the requirement?

    1. AShare the lakehouse with Apache Spark and event access
    2. BShare the lakehouse with Read all SQL endpoint data
    3. CShare the lakehouse with basic Read permission alone
    4. DAssign the contractor the Viewer workspace role
    Show the answer

    The SQL endpoint permission supplies the required query path at item scope without adding the separate Spark path or broad workspace membership.

    Next → 10 / 10
  12. You’ve finished this set

    That’s 10 questions on Workspace and Item Access Controls. In the app the ones you miss come back exactly when you’re about to forget them.

The whole course, on your phone

Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.