20+ practice questions focused on Data Security and Compliance — one of the most tested topics on the Databricks Certified Data Engineer Professional exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Data Security and Compliance PracticeWhich THREE of the following are valid ways to audit data access within Databricks Unity Catalog?
Explanation: System tables (system.access.audit) provide a queryable interface for audit logs. Workspace-level audit logs (delivered to cloud storage) capture platform events. Account-level diagnostic logs are the primary mechanism for capturing Unity Catalog-specific events across the account. 'SHOW PERMISSIONS' is a command to view current privileges, not an audit log mechanism for historical data access.
An organization is auditing its Unity Catalog environment. Which THREE of the following actions require the 'Metastore Admin' role?
Explanation: The Metastore Admin role is responsible for managing objects within a Unity Catalog metastore, including creating catalogs, storage credentials, and external locations. However, configuring the metastore root location is an Account Admin task performed in the Account Console during metastore creation. Metastore Admins cannot change the root location of the metastore itself.
An organization is using Databricks with Unity Catalog and needs to ensure that sensitive data remains encrypted even if the underlying cloud storage is compromised. What is the most effective solution?
Explanation: Unity Catalog masking policies are a dynamic access control mechanism, not an encryption mechanism. Masking policies hide data from users within the Databricks workspace, but they do not encrypt the data at rest in the underlying cloud storage. If the cloud storage is compromised, the raw data remains unencrypted. The correct solution for data remaining encrypted even if storage is compromised is Customer-Managed Keys (CMK) for managed storage or envelope encryption.
A data engineer at a healthcare company needs to configure a Unity Catalog external location so that the storage credential can be used only from a specific set of IP addresses. The company uses AWS and has a Databricks workspace with Unity Catalog enabled. Which of the following should the engineer do to meet this requirement?
Explanation: The correct approach is to create a storage credential with an IAM role that includes a condition limiting access to the specified IP addresses. This leverages AWS IAM policy conditions to enforce network restrictions at the identity level, which is the most secure and centralized method. Other options either do not exist as described or do not properly restrict the credential's usage.
A data engineer is configuring Unity Catalog to control access to a table containing financial records. The security team requires that members of the 'finance_auditors' group can see individual transactions but cannot view the 'account_number' column, while all other columns remain accessible. The engineer creates a dynamic view that excludes the 'account_number' column and grants SELECT on the view to 'finance_auditors'. However, users in that group report they can still see the 'account_number' data when querying the underlying table directly. What is the most likely cause of this issue?
Explanation: To enforce column-level security with Unity Catalog, you must ensure users do not have direct access to the base table. Granting SELECT on a dynamic view alone is insufficient if users also have SELECT on the underlying table. Revoking direct table privileges forces all access through the view, where column filtering applies. This separation of privileges is critical for effective data masking.
+15 more Data Security and Compliance questions available
Practice all Data Security and Compliance questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Data Security and Compliance. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Data Security and Compliance questions on the Databricks-DE-Pro frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Data Security and Compliance is tested as part of the Databricks Certified Data Engineer Professional blueprint. Practicing with targeted Data Security and Compliance questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free Databricks-DE-Pro practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Data Security and Compliance is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Data Security and Compliance practice session with instant scoring and detailed explanations.
Start Data Security and Compliance Practice →