You must be able to choose the right Unity Catalog object or feature to enforce access, protect sensitive columns, and share data securely. The most important thing: map each governance requirement to the correct mechanism, such as grants, masks, row filters, external locations, or Delta Sharing.
Start practicing
Data Governance — choose a session length
Free · No account required
Domain overview
This domain covers Unity Catalog's governance layer on Databricks: metastores, catalogs, schemas, grants, external locations and storage credentials, column- and row-level security, audit logging, and Delta Sharing. Questions are scenario-based, asking you to pick the correct Unity Catalog object or feature to enforce access, protect PII, or share data across accounts and non-Databricks consumers.
Exam objectives
Configuring external locations and storage credentials to govern cloud storage paths in Unity Catalog
Applying GRANT/REVOKE privileges on catalogs, schemas, tables, and views
Using column masks, row filters, and dynamic views to protect PII
Sharing data with external or non-Databricks recipients via Delta Sharing
Assuming table ACLs alone protect PII; column masks or row filters are needed for fine-grained enforcement.
Confusing external locations with storage credentials; the credential authenticates, the location defines the governed path.
Believing Delta Sharing requires the recipient to run Databricks; recipients can consume shares with open Delta Sharing clients.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A data engineer needs to restrict access to personally identifiable information (PII) columns in a Unity Catalog table for a group of analysts. Which Unity Catalog feature should be used to enforce this policy while ensuring data remains queryable?
2Which TWO of the following are primary benefits of using Unity Catalog for managing data lineage in Databricks?
3Which THREE actions are required to properly implement a secure data sharing strategy using Delta Sharing?
4A data engineer wants to ensure that all data in a specific catalog is encrypted at rest. Which feature should they verify is enabled within the Unity Catalog metastore configuration?
5An organization needs to share a dataset with a client who does not use Databricks. What is the most efficient and secure way to share this data using Unity Catalog?
6Which TWO of the following are true regarding Unity Catalog's ability to govern external locations?
7When migrating to Unity Catalog, what is the best practice for managing existing data access permissions?
8A data engineer is implementing column-level masking in Unity Catalog. They need to mask the 'email' column in the table 'prod.customers' such that only members of the 'hr_group' see the full email, while all other users see a masked version. The engineer creates a masking function and applies it using ALTER TABLE. Which statement correctly applies the mask?
9A data engineer needs to audit which users have accessed a Unity Catalog table containing sensitive data. They want to see a record of all queries that read from the table over the past 30 days. Which Unity Catalog feature should they use?
10A data engineer is configuring a Unity Catalog metastore to use a customer-managed key (CMK) for encryption at rest. The engineer has created the necessary Key Vault and key in Azure. Which additional configuration is required to enable CMK for the metastore?
11A data engineer has a Unity Catalog managed table `sales.raw.transactions` that contains a column `customer_email` with PII. Analysts in the `marketing_analysts` group need to query the table for aggregate reporting but must never see individual email addresses. The engineer wants to enforce this dynamically without creating a separate view or copy of the data. Which Unity Catalog feature should the engineer use?
12A data engineer is configuring a Unity Catalog external location to allow a service principal to write to an ADLS Gen2 container. The storage credential uses a managed identity. The engineer grants the service principal `WRITE FILES` on the external location. However, when the service principal attempts to write, it fails with a permissions error. The engineer verifies that the managed identity has the Storage Blob Data Contributor role on the container. What is the most likely cause of the failure?
13A data engineer is designing a Unity Catalog governance model for a new data lakehouse. They need to ensure that data access is auditable and that sensitive data is protected. Which two actions should the engineer take to meet these requirements? (Choose two.)
14A data engineer is using Delta Sharing to share a table with an external partner. The partner needs to access the shared data using their own Databricks workspace. Which protocol does Delta Sharing use to enable this cross-platform sharing?
15A data engineer needs to grant a new data analyst the ability to query tables in the `sales` catalog, which is in Unity Catalog. The analyst should only be able to read data and not modify any tables or metadata. Which sequence of privileges should the engineer grant to the analyst?
16A data engineer is asked to implement column-level masking for a Unity Catalog table `main.hr.employees` that contains a column `ssn` with Social Security numbers. The requirement is that only members of the `hr_group` should see the full SSN, while all other users should see only the last four digits (e.g., XXX-XX-1234). The engineer decides to use a column mask function. Which statement accurately describes how to apply the mask?
You must be able to choose the right Unity Catalog object or feature to enforce access, protect sensitive columns, and share data securely. The most important thing: map each governance requirement to the correct mechanism, such as grants, masks, row filters, external locations, or Delta Sharing.
The Courseiva Databricks-DE-Pro question bank contains 16 questions in the Data Governance domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Data Governance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included