TL;DR
This reference is organized by what you're trying to build, not by exam domain — because PL-400 scenario questions describe a task and expect you to name the right tool, not recite a domain label. Jump to the task ledger below, then use the pattern-recognition table to translate exam wording into the concept it's testing.
MSCertQuiz sells a 500-question PL-400 practice bank; this cheat sheet is maintained by the same team and reflects patterns we see candidates get wrong most often in that bank, not just a copy of the Microsoft study guide's domain list.
Exam Snapshot
| Certification | Microsoft Certified: Power Platform Developer Associate |
| Passing score | 700 / 1000 (scaled score) |
| Typical price | US$165 (Associate-level baseline; varies by region) |
| Renewal | Free online assessment every 12 months |
| Largest domain | Extend the platform — 30–35% |
Full domain breakdown and study-hour allocation: see the PL-400 study guide.
If You Need To... Use This
| You need to... | Reach for | Key detail |
|---|---|---|
| Cancel an invalid operation before it touches the database | Plug-in, PreValidation stage | Runs before security checks and before the transaction opens — cheapest place to cancel |
| Change a field value just before the record saves | Plug-in, PreOperation stage | Runs inside the transaction; avoid canceling here — it forces a rollback |
| React after a save completes without slowing the user down | Plug-in, PostOperation stage + Asynchronous mode | Async plug-ins can only be registered on PostOperation |
| Read the value a field had before an Update changed it | Pre-image on the step registration | Pre-images capture attribute state before the core operation |
| Read attribute values only available after the operation ran | Post-image on the step registration | Post-images capture attribute state after the core operation |
| Add an operation that isn’t a Create, Update, or Delete | Custom API (bound or unbound) | Registered like a plug-in via the Plug-in Registration Tool |
| Build a reusable custom input/output control for a form or canvas app | PCF (Power Apps component framework) code component | Implements init, updateView, getOutputs, destroy |
| Store a value that must differ between dev, test, and prod | Environment variable | Definition travels in the solution; value is supplied per target environment |
| Let a flow or canvas app call your own REST API | Custom connector from an OpenAPI definition | Wraps a public or private REST/SOAP API for the platform |
| Authenticate a custom connector against an Entra ID–protected API | OAuth 2.0, identity provider = Microsoft Entra ID | Client credentials grant type is not supported — use authorization code flow |
| Run a long-running or scheduled backend job against Dataverse | Azure Function, managed identity authentication | Removes the need to rotate client secrets for the connection |
| Notify an external system the moment a Dataverse record changes | Service endpoint (webhook, Azure Service Bus, or Azure Event Hub) | Registered through the Plug-in Registration Tool |
| Sync only what changed in Dataverse, not the full table every time | Change tracking | Returns a token to fetch just the delta since the last sync |
| Upsert records from a source system with no Dataverse GUID | Alternate key + UpsertRequest message | Avoids creating duplicate rows when only a business key is known |
| Run business logic from a canvas app without writing a plug-in | Power Automate cloud flow called from the app | Keeps logic declarative and outside compiled code |
| Fix a canvas app that’s slow against a large data source | Delegable formulas + pre-loading data | Non-delegable formulas silently cap results at the record limit |
| Show a command only to users with a specific security role | Ribbon/command bar rule with Power Fx or JavaScript | Evaluated via the Client API at form load |
| Send a user to a custom page from a form command | Client API navigation method | Part of the model-driven client scripting surface |
| Promote a solution through dev/test/prod without manual reconfig | Power Platform Pipelines or Build Tools + deployment settings file | Pre-populates connection references and environment variables per environment |
| Limit what a plug-in’s calling user context can touch | Dataverse security role scoped to least privilege | Applies to the “Run in User’s Context” setting on the step |
Pattern Recognition: If the Question Says X, Think Y
PL-400 scenario questions rarely say "PreValidation stage" outright — they describe the timing and consequence, and expect you to name the mechanism. Recognizing these phrasings is often worth more than memorizing the concept in isolation.
| If the question says... | Think... |
|---|---|
| “Before the record is saved, and the operation should be canceled if invalid” | PreValidation stage |
| “Modify a value just before it’s written, still part of the same transaction” | PreOperation stage |
| “After the save finishes, without adding latency for the user” | PostOperation + Asynchronous execution |
| “Needs to know what the field used to contain” | Pre-image |
| “The operation doesn’t map to Create, Update, or Delete” | Custom API |
| “Same custom control reused across multiple forms or apps” | PCF code component |
| “Value must be different once it reaches production” | Environment variable |
| “Wrap an existing REST API so Power Automate can call it” | Custom connector |
| “Authenticate using the org’s Azure AD / Entra ID sign-in” | OAuth 2.0, Microsoft Entra ID provider |
| “Sync changes only, not the whole table on every run” | Change tracking |
| “Source system doesn’t know the Dataverse record ID” | Alternate key + Upsert |
Plug-in Stage Quick Map
| Stage | Runs | In transaction? | Typical use |
|---|---|---|---|
| PreValidation | Before security checks, before main operation | No | Cancel an invalid operation cheaply |
| PreOperation | Before main operation | Yes | Modify entity attribute values before save |
| MainOperation | The core platform operation itself | Yes | Reserved — custom APIs and custom virtual table data providers only |
| PostOperation | After main operation | Yes (sync) or outside it (async) | React to a completed change; only stage that supports async mode |
Source: Microsoft Learn, event execution pipeline.
PCF Lifecycle Quick Map
| Method | Called when | Required? |
|---|---|---|
| init | Component first loads on the page | Yes |
| updateView | Any bound property, dataset, or context value changes | Yes |
| getOutputs | Framework needs current output values, after notifyOutputChanged | No — optional |
| destroy | Component removed from the DOM | Yes |
Source: Microsoft Learn, code components overview.
Custom Connector Auth Quick Map
| Auth type | Use when |
|---|---|
| No authentication | The API is public and anonymous |
| Basic authentication | A simple username/password is all the API needs |
| API Key | The API expects a key in a header or query string |
| OAuth 2.0 | Delegated user identity is required, e.g. an Entra ID–protected API |
Source: Microsoft Learn, connection parameters.
Common Gotchas
- →MainOperation is reserved for custom APIs and custom virtual table data providers — it is not an option for ordinary business logic.
- →Canceling in PreOperation forces a full transaction rollback; cancel in PreValidation instead whenever possible.
- →Asynchronous execution mode can only be registered on the PostOperation stage.
- →Never include the primary key in filtering attributes — it is always present on Update and negates every other filter.
- →context.webAPI is not available when a PCF component runs inside a canvas app — always check host API availability before using it.
- →Custom connector OAuth 2.0 does not support the client credentials grant type — only the authorization code flow issues the refresh tokens it needs.
- →Only the environment variable definition should travel inside a managed solution; values are supplied per target environment, not exported with the solution.
Drill this against real scenario questions
The task ledger above tells you the mechanism. Practice tells you how PL-400 disguises which mechanism it wants.
Start Free Practice →Frequently Asked Questions
Is this cheat sheet enough to pass PL-400 on its own?
No. It assumes you already understand the underlying concepts and just need a fast lookup for exam day or a final review pass. Pair it with hands-on practice and the PL-400 study guide if you're still learning the material for the first time.
How is this different from the PL-400 study guide?
The study guide explains what each domain tests and why, with a study-time plan. This cheat sheet skips the explanation and organizes the same underlying knowledge by task — "what do I reach for when I need to do X" — for quick lookup rather than learning from zero.
Can I print this cheat sheet?
Yes — it's plain tables and text with no interactive elements, so your browser's print function renders it cleanly on paper or as a PDF for offline review.
Why isn't there a percentage/weighting column here?
Domain weightings tell you how to allocate study time, not which tool to pick during the exam — that's exactly what the study guide is for. This page is organized by task because that's how PL-400 scenario questions are actually phrased.
What if a scenario doesn't match any row exactly?
Work backward from timing and consequence: does it need to happen before or after the save, inside or outside the transaction, synchronously or not? Those four questions narrow almost every "which plug-in stage" scenario to one correct answer even if the wording is unfamiliar.
Does MainOperation ever apply to me on the exam?
Only in the context of custom APIs and custom virtual table data providers — Microsoft explicitly reserves it for internal use otherwise. If an answer choice suggests registering ordinary business logic on MainOperation, it's a distractor.
More PL-400 Resources
What each domain tests, common myths, and a study-hour plan by weighting.
Free PL-400 Practice QuestionsEasy, medium, and hard scenario questions with full rationale.
PL-400 Exam Readiness QuizA quick timed check of whether you're ready to schedule the real exam.
All Microsoft CertificationsBrowse every certification MSCertQuiz covers.