Be able to write GRANT and REVOKE statements at the right Unity Catalog object level, and explain how dynamic views enforce row filters and column masks for users who lack direct table access. The key is granting least privilege on the exact object, not a broader container.
Start practicing
Securing Data — choose a session length
Free · No account required
Domain overview
This domain covers how Databricks data analysts work with Unity Catalog security: privileges, dynamic views, row-level and column-level controls, and identity management across workspaces. Questions present concrete scenarios—querying a protected view, granting table access, restricting sensitive columns—and ask you to choose the correct SQL, privilege, or governance approach.
Exam objectives
Unity Catalog privilege model: GRANT SELECT on tables, views, schemas, and catalogs
Dynamic views enforcing row-level security and column masking for analysts
Account-level identity management required for cross-workspace Unity Catalog governance
Column-level restrictions using GRANT/REVOKE and dynamic view masking functions
Assuming SELECT on a dynamic view also requires SELECT on the underlying table; view owner privileges handle that
Granting access at schema or catalog level when the question asks for one specific table only
Confusing workspace-local metastore identity with account-level identity needed for centralized Unity Catalog governance
Click any question to see the full explanation and answer options, or start a focused practice session above.
A data analyst needs to share a sensitive sales table with the marketing team in Databricks. The marketing team should only see rows where the region column matches 'North America' and should not have access to the credit_card column. Which Unity Catalog feature should the data analyst implement?
2A data analyst needs to grant a colleague read access to a specific table named 'quarterly_sales' within Unity Catalog without exposing other tables in the same schema. Which SQL command should the analyst execute?
3Which identity management approach is required to utilize Unity Catalog for centralized governance across multiple Databricks workspaces?
4An administrator needs to secure a table containing sensitive customer data. Which TWO options represent valid ways to restrict access using Unity Catalog?
5What is the primary function of a Storage Credential in Unity Catalog?
6When sharing data with external organizations using Delta Sharing, which component manages the secure exchange of data?
7Which THREE actions are required to successfully secure an external location in Unity Catalog?
8Refer to the exhibit. This IAM policy is attached to a Storage Credential. A user tries to run 'DROP TABLE' on a table stored in this bucket and fails. Why?
9Which audit log category is most useful for identifying unauthorized attempts to access sensitive tables?
10What is the purpose of the 'Account Admin' role in Databricks?
11Refer to the exhibit. A data scientist can query both tables, but the join fails with a permission error. What is the most likely reason?
12A data platform administrator needs to configure secure data access policies in Unity Catalog. Which TWO actions can the administrator perform to restrict access to sensitive columns within a Delta table? (Choose TWO)
13An organization stores sensitive financial records in a Unity Catalog managed Delta table stored in cloud object storage. To comply with corporate security mandates, all data at rest must be encrypted using a customer-managed encryption key rather than the default cloud provider-managed keys. Where must the administrator configure this encryption setting?
14A data analyst has been asked to grant a new team member read access to a specific table named 'customer_orders' in Unity Catalog. The analyst wants to ensure the team member can query the table but cannot see any other tables in the schema. Which SQL command should the analyst use?
15A data analyst is using a Databricks SQL warehouse to query a table that is protected by row-level security using dynamic views in Unity Catalog. The analyst has SELECT on the view but not on the underlying table. When querying the view, the analyst receives an error about insufficient privileges on the base table. What is the most likely cause?
16A data analyst has a Unity Catalog table `main.finance.payroll` that contains a column `ssn` with sensitive data. The analyst wants to allow the HR team to query the table but mask the `ssn` column so that only users in the `hr_admins` group see the actual values; all other users should see `***` instead. Which Unity Catalog feature should the analyst use to achieve this?
17A data analyst needs to grant a service principal read access to a specific external location in Unity Catalog so that a scheduled job can read data from an S3 bucket. The analyst has already created a storage credential that references an IAM role with the necessary S3 permissions. Which Unity Catalog object must the analyst grant the service principal access to, in addition to the storage credential?
18A data analyst in the 'marketing' group needs to query the table `main.sales.leads` but should not be able to read the underlying data files directly. The analyst currently has `SELECT` on the table and `READ FILES` on the external location where the table's data resides. Which Unity Catalog privilege should the analyst's `READ FILES` on the external location be removed to enforce least privilege?
19A data analyst is reviewing audit logs in Databricks to investigate who accessed a sensitive table 'main.finance.payroll'. The analyst needs to identify the user, the timestamp, and the action performed. Which audit log service should the analyst query to find this information?
20A data analyst at a multinational bank needs to ensure that queries against a Unity Catalog table 'main.risk.transactions' automatically hide the 'customer_ssn' column for users in the 'contractors' group, while all other users see the full data. The analyst wants to implement this without creating separate views for each user group. Which Unity Catalog feature should the analyst use?
21A data analyst wants to share a Unity Catalog table with an external partner using Delta Sharing. The partner uses a non-Databricks client that supports the Delta Sharing protocol. Which Unity Catalog object must the analyst create to enable the partner to access the shared data?
22A data analyst needs to grant a team member the ability to view the metadata of a table `main.finance.transactions` in Unity Catalog, but not query the data. Which privilege should the analyst grant?
23A data analyst is using Databricks SQL to query a table `main.sales.orders` that has a column `credit_card` containing sensitive data. The analyst needs to run a query that aggregates orders by region but must not see the actual credit card numbers. Which Unity Catalog feature should be used to mask the `credit_card` column for this analyst?
24A data analyst is reviewing audit logs in Databricks to investigate unauthorized access attempts to a sensitive table. Which audit log event type should the analyst filter on to find failed attempts to query the table?
Be able to write GRANT and REVOKE statements at the right Unity Catalog object level, and explain how dynamic views enforce row filters and column masks for users who lack direct table access. The key is granting least privilege on the exact object, not a broader container.
The Courseiva Databricks-DA-Assoc question bank contains 24 questions in the Securing Data domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Securing Data domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included