20+ practice questions focused on Governance and Security — one of the most tested topics on the Databricks Certified Data Engineer Associate exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Governance and Security PracticeAn enterprise data governance team needs to ensure that junior data analysts can view customer transaction records, but their view must automatically mask the primary credit card number column. Which Unity Catalog feature accomplishes this requirement?
Explanation: In Unity Catalog, column masking is implemented using the 'MASK' clause within a 'CREATE VIEW' statement or an 'ALTER TABLE' statement, typically referencing a SQL UDF. The explanation correctly identifies the use of SQL UDFs and ALTER TABLE, but the phrasing 'Row filters and column masks using SQL user-defined functions applied via ALTER TABLE statements' is the standard way to describe this feature in Unity Catalog.
Which TWO of the following statements accurately describe the behavior and characteristics of managed tables versus external tables in Unity Catalog? (Choose TWO)
Explanation: Managed tables and external tables in Unity Catalog both provide ACID transactions and Delta Lake optimizations, but they differ significantly in storage lifecycle management. Managed tables store data in the metastore's root storage container and have their underlying files automatically deleted when dropped, whereas external tables point to custom cloud storage locations where files remain intact upon dropping.
A data engineer needs to ensure that PII data in a 'users' table is masked for all users except those in the 'HR' group. Which Unity Catalog feature should be used to implement this requirement?
Explanation: While Dynamic Views can achieve this, Unity Catalog introduced native Column Masking (using the MASK clause) and Row Filters (using the ROW FILTER clause) as the standard, more performant, and easier-to-manage feature for this specific requirement. Dynamic Views are considered a legacy approach for this use case.
Which TWO of the following are true regarding the use of Personal Access Tokens (PATs) versus Service Principals for automated jobs in Unity Catalog?
Explanation: Service Principals are independent of individual user accounts, which prevents service disruption when employees leave. Additionally, they do not require a standard interactive Databricks user license for API/automated job access. PATs are tied to users, making them a security risk upon offboarding and harder to audit globally compared to centralized service principals.
If an organization wants to ensure that no data can be accessed unless it is explicitly granted, which Unity Catalog setting should be enforced?
Explanation: Unity Catalog enforces a 'deny-by-default' security model by design once a workspace is enabled for Unity Catalog. There is no specific setting called 'Enable Unity Catalog for all workspaces' that acts as a toggle for this behavior; rather, it is the default state of the Unity Catalog metastore. The question is poorly phrased as it implies a configuration setting that doesn't exist in the Databricks documentation.
+15 more Governance and Security questions available
Practice all Governance and Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Governance and Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Governance and Security questions on the Databricks-DE-Assoc frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Governance and Security is tested as part of the Databricks Certified Data Engineer Associate blueprint. Practicing with targeted Governance and Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free Databricks-DE-Assoc practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Governance and Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Governance and Security practice session with instant scoring and detailed explanations.
Start Governance and Security Practice →