PL-400 · Microsoft Power Platform Developer

Free PL-400 Practice Questions: Easy to Hard

12 questions · full rationale for every choice

TL;DR

Twelve scenario-based PL-400 questions below, grouped by difficulty instead of by exam domain — four easy (single-concept recall), four medium (applied scenarios with one twist), and four hard (multi-step scenarios built to trip up developers who know the concepts individually but not how they interact). Every choice has a rationale, not just the correct one.

MSCertQuiz maintains a 500-question PL-400 bank; these 12 are a free sample written the same way, grounded in Microsoft's own developer documentation for plug-ins, PCF components, custom connectors, and ALM rather than generic trivia.

What These Questions Cover

These questions sample across all six PL-400 domains — technical design, ALM, canvas app improvements, client scripting/PCF, plug-ins/connectors/platform APIs, and integrations — weighted toward "Extend the platform" scenarios since that domain carries 30–35% of the real exam. Each tier increases the number of moving parts you have to track at once, which is how PL-400's actual difficulty curve works.

Easy: Core Concepts

Single-concept recall, lightly wrapped in a scenario.

E1

1. A developer needs to cancel a Dataverse operation before it reaches the database if the incoming data is invalid. Which plug-in stage should this logic run in?

A.PostOperation
B.PreValidation✓ Correct
C.MainOperation
D.PreOperation

Why B is correct: PreValidation runs before the transaction opens and before Dataverse performs its security checks — the cheapest possible place to cancel an operation.

Why A is wrong: PostOperation runs after the operation has already completed — too late to prevent it.

Why C is wrong: MainOperation is reserved for internal platform use (and custom APIs / virtual table data providers) — it is not an option for ordinary validation logic.

Why D is wrong: PreOperation runs inside the database transaction. Canceling there still works, but it forces a full rollback and has a real performance cost Microsoft explicitly warns against.

E2

2. A developer wants to build a custom input control that can be reused across multiple model-driven app forms and canvas apps. Which feature should they use?

A.A business rule
B.A Power Automate cloud flow
C.A Power Apps component framework (PCF) code component✓ Correct
D.An environment variable

Why C is correct: PCF code components are precisely the platform mechanism for building a custom, reusable UI control that works across model-driven and canvas apps.

Why A is wrong: Business rules apply declarative field-level logic — they don’t render custom UI.

Why B is wrong: Cloud flows automate backend processes; they have no UI-rendering role inside a form or app.

Why D is wrong: Environment variables store configuration values, not interface logic or rendering code.

E3

3. A developer is building a custom connector that wraps a fully public REST API requiring no sign-in of any kind. Which authentication type should they configure?

A.OAuth 2.0
B.API Key
C.Basic authentication
D.No authentication✓ Correct

Why D is correct: When the underlying API genuinely requires no credentials, "No authentication" lets any user connect without being prompted for one.

Why A is wrong: OAuth 2.0 implies a registered app and a delegated identity flow — unnecessary overhead for a fully anonymous API.

Why B is wrong: API Key still requires the caller to supply a key value, which contradicts a "no sign-in of any kind" API.

Why C is wrong: Basic authentication requires a username and password, which an anonymous API doesn’t need or accept.

E4

4. A developer needs to store a connection string that must hold a different value in development, test, and production. Which Power Platform ALM component should hold it?

A.An environment variable✓ Correct
B.A connection reference
C.A custom table column
D.A solution layer

Why A is correct: Environment variables are the solution component designed exactly for this: a key whose value is expected to differ per target environment as a solution is promoted through ALM.

Why B is wrong: A connection reference represents the authentication/credential link to a connector — related, but it isn’t the mechanism for an arbitrary config value like a connection string.

Why C is wrong: A custom table column stores business data rows, not per-environment configuration, and doesn’t automatically get re-supplied per environment during import.

Why D is wrong: A solution layer describes how customizations stack on top of each other; it has nothing to do with storing configuration values.

Medium: Applied Scenarios

One realistic complication layered on top of the core concept.

M1

5. A plug-in registered on the PostOperation stage of the Create message for the SystemUser table must update a related UserSettings record that Dataverse creates automatically right after the SystemUser row is created. Which execution mode should this step use, and why?

A.Synchronous, because it must complete before the form returns
B.Synchronous, because PostOperation only supports synchronous execution
C.Asynchronous, because the UserSettings record isn’t created until after the SystemUser row is created✓ Correct
D.Asynchronous, because PreOperation plug-ins cannot access related records

Why C is correct: Microsoft’s own guidance calls out this exact scenario: the UserSettings record for a new user doesn’t exist yet at the moment SystemUser is created, so the update must be deferred to asynchronous mode to reliably find it.

Why A is wrong: Running synchronously would race the platform’s own creation of UserSettings, causing intermittent failures.

Why B is wrong: False on two counts: PostOperation supports both modes, and in fact async execution can only be registered on PostOperation in the first place — it isn’t the "only" option there, it’s the required stage for using it at all.

Why D is wrong: This scenario is a PostOperation step, not a PreOperation one — the reasoning doesn’t match the setup described.

M2

6. A model-driven app needs a command button visible only when the current user’s security role permits editing a related custom table, evaluated entirely in the browser with no server round trip. What should the developer implement?

A.A server-side plug-in on the Retrieve message
B.A Power Automate flow triggered on form load
C.A Dataverse security role assigned directly to the field
D.A ribbon/command bar rule using the Client API✓ Correct

Why D is correct: Command bar visibility rules evaluated through the Client API run client-side and can check privilege/context information without a server call, which is exactly what "Extend the user experience" tests.

Why A is wrong: A plug-in on Retrieve runs server-side and doesn’t control command bar visibility directly — it would need extra machinery and still isn’t the standard mechanism for this.

Why B is wrong: Triggering a flow on form load adds a server round trip, which the scenario explicitly rules out.

Why C is wrong: Security roles govern record/table-level access; they don’t by themselves drive command bar visibility logic — a client-side rule still needs to reference that access.

M3

7. A canvas app queries a SharePoint list with over 3,000 items using a filter formula built with a function that isn’t supported for delegation. What is the most likely symptom, and the correct fix?

A.The app silently returns an incomplete result set bounded by the delegation limit; rewrite the filter with delegable functions or pre-aggregate the data✓ Correct
B.The app throws a compile error; rewrite the formula using only string functions
C.The app crashes on load; increase the environment’s API request limit
D.The connection is rejected; switch to a premium connector

Why A is correct: Non-delegable formulas are valid Power Fx and compile fine — the real danger is that the app silently returns only a subset of records up to the delegation limit, giving wrong results without any visible error.

Why B is wrong: There is no compile-time error here; that’s exactly why this failure mode is dangerous — it looks like working code.

Why C is wrong: Delegation limits don’t crash an app on load; this is a data-correctness bug, not a load failure.

Why D is wrong: This has nothing to do with connector licensing tier — delegation is about which operations a data source can execute server-side, independent of premium status.

M4

8. An integration needs an external system to be notified near-real-time whenever a Dataverse Opportunity record is updated, without the external system polling Dataverse. Which combination accomplishes this?

A.A scheduled Power Automate flow that queries the Web API every 5 minutes
B.A plug-in on the Update message with a service endpoint (e.g., Azure Service Bus) registered via the Plug-in Registration Tool✓ Correct
C.Change tracking with the Web API, polled periodically by the external system
D.A custom connector called manually by the external system

Why B is correct: Registering a plug-in that publishes to a service endpoint is the push-based Dataverse event pattern — the external system receives the notification instead of asking for it.

Why A is wrong: A 5-minute schedule is still polling, not push-based, and adds unnecessary latency and load for a "near-real-time" requirement.

Why C is wrong: Change tracking is designed for the external system to pull deltas it missed — still a pull/poll pattern, not a push notification.

Why D is wrong: A custom connector lets Power Platform call out to an external API; it doesn’t give Dataverse a way to notify that system when something changes inside Dataverse.

Hard: Multi-Step Trap Scenarios

Two or more concepts interacting — the pattern that separates a pass from a near-miss.

H1

9. A PreOperation plug-in on the Account table’s Update message filters on the "revenue" column. A separate PostOperation plug-in on the same message updates a related field, which a workflow then uses to indirectly change "revenue" again. The PreOperation plug-in unexpectedly fires a second time. What is the most likely cause and fix?

A.Filtering attributes don’t work on PreOperation, only PostOperation — remove the filter entirely
B.Filtering attributes should include the primary key so the plug-in can detect duplicate calls
C.PreOperation plug-ins always run twice per logical update by design; no fix is needed
D.The workflow’s write to "revenue" is a second, legitimate Update operation matching the filter; add a guard clause that checks whether the value actually changed, or consolidate the logic into one transaction✓ Correct

Why D is correct: The second firing is a distinct, legitimate Update operation caused by the workflow’s own write to "revenue" — the plug-in isn’t misbehaving, it’s correctly reacting to two separate triggering events. A guard clause (or consolidating the logic) prevents the unwanted second reaction.

Why A is wrong: Filtering attributes work identically on any stage; the stage isn’t the source of this behavior.

Why B is wrong: Microsoft’s own registration guidance explicitly says never include the primary key in filtering attributes, since it’s always present on Update and would negate every other filter rather than help detect duplicates.

Why C is wrong: PreOperation plug-ins don’t duplicate-fire "by design" for one operation — this is two separate Update operations, not one operation processed twice.

H2

10. A PCF dataset component loads the next page of records on scroll, but developers observe that calling the paging methods repeatedly sometimes reloads the same page instead of advancing. What is the most likely root cause?

A.The paging methods (loadNextPage, loadExactPage, etc.) don’t support parallel or overlapping execution, and the component is calling them again before the prior call’s updateView cycle finishes✓ Correct
B.getOutputs was not implemented correctly
C.The component’s manifest is missing a resource declaration
D.context.webAPI is unavailable in the hosting app

Why A is correct: Microsoft’s own troubleshooting guidance for the component framework states that paging functions don’t support parallel execution — calling them again before the triggered updateView cycle completes causes exactly this same-page-repeats symptom.

Why B is wrong: getOutputs governs bound output values returned to the framework; it has no role in dataset paging.

Why C is wrong: A missing resource declaration would break rendering outright, not cause this specific paging-repeat symptom.

Why D is wrong: context.webAPI availability is a canvas-app hosting limitation unrelated to dataset paging, and nothing in the scenario mentions canvas apps.

H3

11. A custom connector for an internal Entra ID–secured API uses OAuth 2.0 with a client ID and client secret. Six months later, users start losing their connections and must reauthenticate weekly. What is the most likely cause, and what should change going forward?

A.The API itself is unstable and nothing can be done from the connector side
B.The client secret is nearing expiration and wasn’t rotated in time; monitor and renew credentials proactively, or use managed identity authentication to avoid secret rotation entirely✓ Correct
C.OAuth 2.0 is the wrong authentication type for Entra ID; switch to API Key
D.The connector needs to be republished every week regardless of credentials

Why B is correct: Microsoft explicitly warns that OAuth-based connectors need their client ID and client secret monitored and renewed before expiry — and offers managed identity authentication specifically to remove the need for secret rotation altogether.

Why A is wrong: This is a credential-lifecycle issue on the connector’s own registration, not evidence the backend API is unstable.

Why C is wrong: OAuth 2.0 with Entra ID is the recommended pattern for exactly this case; the type isn’t the problem, expired credentials are.

Why D is wrong: Republishing the connector doesn’t address an expiring secret — it doesn’t touch the underlying credential lifecycle at all.

H4

12. After importing a solution into production via Power Platform Build Tools, several environment variables show blank values, and a canvas app fails because a SharePoint-backed environment variable has no connection. What did the team most likely forget?

A.To include the environment variable definitions in the solution before export
B.To assign the System Administrator security role to the deployment service account
C.To pre-populate the deployment settings file with target-environment-specific connection references and environment variable values before the automated import✓ Correct
D.To increase the solution’s maximum size limit before import

Why C is correct: Environment variable definitions travel with the solution by design, but their values do not — for a fully automated CI/CD import, the deployment settings file must be pre-populated with the target environment’s connection references and variable values ahead of time.

Why A is wrong: The definitions clearly imported successfully (the variables exist and show up blank) — it’s the values that are missing, and values are intentionally excluded from solution export.

Why B is wrong: A missing security role would typically block the import with an access-denied error, not leave selectively blank environment variable values.

Why D is wrong: Solution size limits (95 MB) cause an outright import failure, not a partial values-population problem like this.

Want 500 more PL-400 questions like these?

Full timed exam mode, weighted the way the real PL-400 domains are weighted.

Take the Exam Readiness Quiz →

Frequently Asked Questions

Are these questions from the real PL-400 exam?

No. Microsoft doesn't release real exam items. These are original scenario questions written to test the same concepts and traps the real exam is documented to cover, grounded in Microsoft's own developer documentation.

Why are these grouped by difficulty instead of by domain?

Domain grouping is useful for studying one topic in isolation, which is what the study guide is for. Difficulty grouping mirrors how the real exam actually escalates — from single-concept recall to multi-step scenarios that combine several domains in one question.

I got the hard questions wrong. Does that mean I'll fail PL-400?

Not necessarily — but it's a signal to revisit how concepts interact, not just what each one means individually. Re-read the rationale for the distractors, not just the correct answer; the wrong-choice reasoning is usually where the actual gap is.

How many questions does the real PL-400 exam have?

Microsoft doesn't publish a PL-400-specific count. Its general guidance says most certification exams run 40–60 questions, and the exact number can change between refreshes. See the study guide for the full sourced breakdown.

Do I need to memorize C# syntax for questions like these?

No — none of the 12 questions above require writing code from memory. They test whether you understand which mechanism applies to a given scenario (a plug-in stage, a PCF lifecycle method, an auth type), which is how PL-400 scenario questions are actually built.

Related PL-400 Resources