Be able to choose and apply the right Unity Catalog or workspace control for a stated requirement: masks and row filters for column/row-level access, CMK for encryption at rest, IP access lists for network restrictions, and Delta Sharing for cross-account reads. Get the access-control mechanism matched to the exact requirement.
Start practicing
Data Security and Compliance — choose a session length
Free · No account required
Domain overview
This domain covers securing data in Databricks: Unity Catalog fine-grained access control (row filters, column masks), customer-managed keys for encryption at rest, network restrictions via IP access lists, and secure data sharing across accounts. Questions present realistic engineering scenarios and ask you to select the correct Unity Catalog, cloud, or sharing feature to meet a stated compliance requirement.
Exam objectives
Unity Catalog column masks and row filters for fine-grained access control on Delta tables
Customer-managed keys (CMK) for encrypting workspace-managed data at rest
IP access lists to restrict workspace connections to approved corporate network ranges
Delta Sharing to expose tables to external partners without copying data
Confusing column masks with row filters, or applying them at table level instead of via Unity Catalog functions and GRANT statements
Assuming CMK changes who can query data, when it only controls encryption keys protecting data at rest
Believing Delta Sharing copies data to the recipient, rather than granting governed read access to the shared table
Click any question to see the full explanation and answer options, or start a focused practice session above.
A Data Engineer needs to ensure that PII data in a Delta table is accessible only to members of the 'hr_admin' group, while allowing all other users to view the non-PII columns. Which Unity Catalog feature is the most efficient way to implement this requirement?
2An organization is migrating to Unity Catalog and needs to secure sensitive data. Which TWO of the following statements regarding Unity Catalog security best practices are correct?
3A Data Engineer needs to encrypt data at rest within a Databricks workspace that uses a customer-managed key (CMK). What is the primary purpose of this configuration?
4An organization wants to restrict data access to only allow connections from specific corporate IP ranges. Which Databricks feature should be configured to implement this network security requirement?
5What is the primary function of a 'Personal Access Token' (PAT) in Databricks, and why is it considered a security risk if not managed properly?
6Which of the following describes the correct behavior of Unity Catalog's 'Data Lineage' when used for security compliance?
7Which of the following is the most secure method for a Data Engineer to provide access to a specific Delta table for a temporary project?
8Which TWO of the following are benefits of using Unity Catalog for managing data governance in a multi-workspace environment?
9When migrating an existing Hive metastore to Unity Catalog, what is the most important security consideration regarding object naming?
10A data engineer needs to ensure that PII data in a Delta table is accessible only to users in the 'HR_Manager' group. Which approach provides the most granular and scalable security implementation?
11An organization requires that all data stored in their S3 bucket used by Databricks be encrypted using a Customer Managed Key (CMK). Which configuration must be performed to meet this requirement?
12Refer to the exhibit. A data engineer executes this command in a Unity Catalog-enabled workspace. What is the immediate effect on the 'analyst_group'?
13Which TWO of the following are primary benefits of using Unity Catalog for data governance in Databricks?
14A data engineer is tasked with ensuring that sensitive information in a 'customer' table is masked for all users except the 'Data_Science' group. What is the correct Unity Catalog feature to implement?
15When configuring a Service Principal to access a Unity Catalog-enabled workspace, which THREE steps are required to ensure secure and functional access?
16A data engineer is setting up a new Unity Catalog metastore. What is the primary purpose of the 'Metastore Admin' role?
17Refer to the exhibit. A user encounters this error when running a query. What is the correct action to resolve this issue while maintaining the security model?
18A data engineering team stores customer transaction data in a Unity Catalog managed table named prod.finance.transactions. The security team requires that any query referencing this table, whether through a view or directly, is recorded with the identity of the user who ran it, and that the audit logs are retained for 365 days. The workspace uses Unity Catalog and has audit logs delivered to a cloud storage location. Which configuration should the data engineer verify or set to meet the requirement that all access to the table is captured with the user identity?
19A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The organization's security policy requires that Databricks assumes an IAM role, and that no long-lived AWS access keys are stored in Databricks. The engineer has created an IAM role with a trust policy and an external ID. Which action must the engineer take to complete the storage credential configuration in Unity Catalog?
20A financial services firm stores market data in an external location registered in Unity Catalog as `s3://firm-market-data/`. The security team requires that only a specific IAM role, assumed by a Unity Catalog storage credential, can read the bucket, and that no Databricks user can bypass Unity Catalog to read the data directly with their own cloud credentials. The Data Engineer must configure the storage credential. Which configuration achieves this?
21A data engineer is configuring audit logging for a Unity Catalog-enabled workspace. The security team wants to capture all access to tables and the granting of privileges. Which Databricks feature should the engineer enable to collect these audit events?
22A Data Engineer is implementing column-level security on a Unity Catalog table `sales.customers` that contains `email`, `ssn`, and `region` columns. The requirement is that analysts in the `analyst` group see only the last four digits of `ssn` and a hashed `email`, while members of the `compliance` group see full values. The engineer plans to use column masks. Which TWO actions are required to meet the requirement? (Choose two.)
23A data engineer is implementing fine-grained access control on a Delta table in Unity Catalog that contains sensitive customer data. The requirement is to mask the `credit_card` column for all users except members of the `finance` group, and to filter out rows where the `region` column is not in the user's allowed regions. Which two Unity Catalog features should the engineer use? (Choose two.)
24A data engineer is configuring a Unity Catalog external location to allow access to an S3 bucket. The security team requires that all access to the bucket be authenticated using a specific IAM role, and that the credentials not be stored in Databricks. Which Unity Catalog object should the engineer create to meet this requirement?
25A data engineer needs to grant a service principal permission to read data from a Unity Catalog table named sales.orders. The service principal is used by an automated job and should have only the minimum necessary privileges. Which Unity Catalog privilege should be granted on the table to allow the service principal to read data?
26A data engineer is designing a solution to share a Delta table with an external partner organization. The partner uses a different Databricks account and must be able to read the table, but the data must not be copied outside the provider's cloud storage. The provider uses Unity Catalog and wants to minimize operational overhead while ensuring the partner sees only the shared table. Which Unity Catalog feature should the engineer use?
27A data engineer is configuring a Databricks workspace with Unity Catalog. The security team wants to ensure that all data access is logged for compliance auditing. The engineer enables audit logs and configures delivery to a cloud storage location. Which Unity Catalog object should the engineer use to query audit logs for data access events?
28A data engineer is configuring a Unity Catalog external location to securely access data in an AWS S3 bucket. The engineer has already created an IAM role with the necessary permissions and configured the storage credential. Which additional step is required to allow Databricks to access the S3 bucket?
Be able to choose and apply the right Unity Catalog or workspace control for a stated requirement: masks and row filters for column/row-level access, CMK for encryption at rest, IP access lists for network restrictions, and Delta Sharing for cross-account reads. Get the access-control mechanism matched to the exact requirement.
The Courseiva Databricks-DE-Pro question bank contains 28 questions in the Data Security and Compliance domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Data Security and Compliance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included