Be able to choose and configure Unity Catalog features that enforce least-privilege access: dynamic views or row filter functions for row-level security, column masks for column-level security, and audit log delivery to a SIEM. The most important thing is matching the requirement to the correct Unity Catalog mechanism.
Start practicing
Governance and Security — choose a session length
Free · No account required
Domain overview
This domain covers Unity Catalog governance on Databricks: access control, row and column-level security, audit logging, and lineage. Questions present organizational requirements and ask you to select the correct Unity Catalog feature, privilege model, or configuration to satisfy least-privilege access and compliance needs.
Exam objectives
Unity Catalog privileges: GRANT/REVOKE, catalog/schema/table hierarchy, and securable objects
Row-level security via dynamic views and row filter functions on Unity Catalog tables
Column masking using column mask functions and attribute-based access control
Audit logs and system tables for centralized SIEM ingestion and lineage tracking
Assuming table-level GRANTs alone enforce row filtering; row-level security requires dynamic views or row filter functions.
Confusing Unity Catalog lineage with audit logs; lineage tracks data movement, audit logs capture access events.
Granting privileges at catalog or schema level when least privilege requires table or column scope.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A data engineer needs to share a Delta table managed by Unity Catalog with external partners who do not have access to the Databricks workspace. Which feature should be used to securely grant read-only access to this table without replicating the data?
2A data engineer is configuring Unity Catalog governance for a multi-department organization. Which TWO actions require the metastore admin or catalog owner to have a workspace-independent metastore assigned? (Choose TWO)
3An organization requires that all data access logs across multiple Databricks workspaces be captured and sent to a centralized security information and event management (SIEM) system. Which Databricks feature should be configured to capture these audit events?
4A data engineer is migrating legacy tables to Unity Catalog. Which TWO of the following statements regarding the transition to three-level namespace (catalog.schema.table) are true?
5Refer to the exhibit. A data engineer attempts to run the GRANT statement above in a Databricks SQL query editor. What is the most likely reason for failure?
6Which feature in Unity Catalog is primarily used to track data movement and transformation history for compliance and auditing?
7Which THREE of the following represent core security principles enforced by Unity Catalog?
8A data engineer needs to share a subset of a table with an external partner who does not have access to the internal Databricks workspace. What is the most appropriate method to achieve this?
9Which of the following describes the correct order of operations to configure a new external location in Unity Catalog?
10What is the primary role of a 'Metastore Admin' in a Databricks Unity Catalog environment?
11Refer to the exhibit. A user who is a member of 'data_analysts_group' reports they cannot see the 'orders' table in the Catalog Explorer. What is the most likely cause?
12What must be configured to allow Databricks to access cloud storage on behalf of a user without the user needing to provide their own cloud credentials?
13Which TWO of the following are benefits of using Unity Catalog over the legacy Hive Metastore?
14A data engineer needs to share a table in Unity Catalog with a partner organization using a different Databricks account. Which feature should be used to provide secure access without moving the data?
15Which of the following best describes the purpose of 'Credential Passthrough' in Databricks?
16Which THREE of the following are benefits of using Unity Catalog over the legacy Hive Metastore?
17Refer to the exhibit. A data engineer is configuring an IAM policy for a Databricks storage credential. Which of the following is the most significant security risk in this configuration?
18What is the primary function of an 'Access Connector' for Azure Databricks when using Unity Catalog?
19Which security feature should a data engineer configure to ensure that audit logs from all Databricks workspaces are captured and stored in a single, centralized location?
20Which of the following is the best practice for managing service principals in a Databricks workspace?
21A data engineer needs to share a table in Unity Catalog with external partners who do not have access to the Databricks workspace. Which feature should the data engineer configure?
22A data engineering team must implement dynamic row-level filtering on a customer analytics table in Unity Catalog so that regional analysts only view records corresponding to their assigned territory. Which TWO steps are required to achieve this using Unity Catalog features? (Choose 2)
23Refer to the exhibit. An organization needs to ensure that members of the 'analyst_group' can only view data where the region column equals 'US'. Based on the provided configuration, what is the best approach to implement this in Unity Catalog?
24Which security feature in Databricks allows administrators to mask sensitive data, such as email addresses or social security numbers, in query results based on user-defined functions?
25A data engineer is tasked with securing sensitive PII data in Unity Catalog. Which THREE actions are recommended to ensure robust security and compliance?
26Which identity management approach is mandatory for the implementation of Unity Catalog within a Databricks environment?
27A data engineering team needs to restrict access to a sensitive customer table in Unity Catalog so that junior data engineers can only view non-PII columns, while senior engineers can view all columns. Which approach should be used to implement this requirement securely and efficiently?
28A data engineer has a Unity Catalog table `prod.sales.orders` that contains a column `customer_email`. They need to allow analysts in the `marketing` group to query the table but only see a masked version of `customer_email` (e.g., `a***@example.com`). The masking logic is implemented as a SQL user-defined function `prod.security.mask_email`. Which statement should the engineer execute to apply the mask?
29A data engineer is configuring Unity Catalog row-level security on a table `prod.finance.transactions`. They want to ensure that users in the `us_team` group can only see rows where `region = 'US'`, while users in the `eu_team` group can only see rows where `region = 'EU'`. They create a row filter function `prod.security.region_filter`. Which TWO statements accurately describe how to implement and manage this row-level security? (Choose two.)
30A data engineer needs to grant the `analyst` group the ability to read data from a Unity Catalog table `sales.fact_orders`. They also want to ensure that members of `analyst` can see the table in the catalog explorer but cannot modify it. Which privilege should be granted to the `analyst` group on the table?
31A data engineer stores a Delta table in Unity Catalog at the managed location of the schema 'sales'. The table is later dropped using DROP TABLE. What happens to the underlying data files?
32A data engineer has configured a storage credential in Unity Catalog to access an AWS S3 bucket. The credential uses an IAM role with a trust policy that allows Databricks to assume it. The engineer now needs to ensure that only a specific set of users can create external tables pointing to that S3 bucket. Which Unity Catalog object should be used to control this access?
33A data engineer has a Unity Catalog table named `sales.raw.orders` that contains a column `credit_card` with sensitive data. The security team requires that users in the `analyst` group see only the last four digits of the credit card number when querying this table, while all other users with appropriate privileges see the full value. The data engineer wants to implement this with minimal disruption to existing queries. Which approach should the data engineer take?
34A data engineer has a Unity Catalog table `prod.sales.orders` containing a column `customer_email`. Company policy requires that users in the `analyst_group` see only the domain part of the email (e.g., `***@example.com`), while members of `pii_admin_group` must see the full email. The engineer wants to enforce this at query time without creating separate views. Which approach should the engineer use?
35A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The S3 bucket policy grants access to an IAM role. The data engineer creates a storage credential with that IAM role's ARN. However, when attempting to create an external location using this storage credential, the operation fails with an error indicating insufficient permissions. The data engineer verifies that the IAM role has the correct S3 permissions. What is the most likely cause of the failure?
36A data engineer needs to ensure that only members of the 'finance' group can view a specific column containing credit card numbers in a Unity Catalog table. Which feature should be used?
37A data engineer is configuring a storage credential in Unity Catalog to access an AWS S3 bucket. The engineer creates an IAM role with the necessary permissions and sets up the storage credential using the role ARN. What additional step is required to allow Databricks to assume the role?
38A data engineer needs to ensure that all queries against a Unity Catalog table are logged for audit purposes. The logs must include the user identity, the query text, and the timestamp. Which Databricks feature should be enabled to capture this information?
39A data engineer is designing an access control model in Unity Catalog for a new catalog `finance`. The team wants to follow the principle of least privilege while still enabling collaboration. Which TWO of the following practices best align with Unity Catalog's privilege model? (Choose two.)
40A data engineer needs to allow a service principal to read data from a Unity Catalog table `sales.orders` and also write to a volume `sales.raw_data`. Which set of privileges should be granted to the service principal?
41A data engineer is configuring audit logging for a Databricks workspace that uses Unity Catalog. The security team requires that all access to data in Unity Catalog be logged and available for analysis in a centralized location. The data engineer wants to enable the delivery of audit logs to an AWS S3 bucket. Which configuration should the data engineer use?
42A data engineer is asked to ensure that all queries against a Unity Catalog table are recorded for auditing, including the identity of the user and the query text. Which Databricks feature should the engineer enable to capture this information?
43A data engineer needs to grant a group `data_consumers` the ability to query a view `prod.reporting.sales_summary` that is defined on top of tables in the same catalog. The group currently has no privileges on the underlying tables. What is the minimum set of privileges the engineer must grant to `data_consumers` so they can query the view successfully?
44A data engineer is managing a Unity Catalog table that contains sensitive financial data. The table is owned by the 'finance' group, and the data engineer needs to allow the 'auditors' group to read the table but not modify it. Additionally, the data engineer wants to ensure that the 'auditors' group can see the table's metadata (e.g., column names and types) but cannot access the underlying data files directly. Which TWO actions should the data engineer take to meet these requirements? (Choose two.)
45A data engineer is configuring Unity Catalog to allow a service principal to run a Databricks job that writes to a Delta table in an external location. The service principal has been granted USAGE on the catalog and schema, and MODIFY on the table. However, the job fails with an error indicating that the service principal cannot access the external location. What is the most likely missing privilege?
46A data engineer manages a Unity Catalog table `sales.raw.transactions` that contains a column `credit_card_number`. The security team requires that users in the `auditors` group can see the full credit card number, while all other users who have SELECT privileges on the table should see only the last four digits. The engineer decides to use a column mask. Which SQL statement should the engineer execute to meet this requirement?
Be able to choose and configure Unity Catalog features that enforce least-privilege access: dynamic views or row filter functions for row-level security, column masks for column-level security, and audit log delivery to a SIEM. The most important thing is matching the requirement to the correct Unity Catalog mechanism.
The Courseiva Databricks-DE-Assoc question bank contains 46 questions in the Governance and Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Governance and Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included