Courseiva
Securing Data →mediumMultiple Choice

Databricks-DA-Assoc Securing Data Practice Question

A data analyst has a Unity Catalog table `main.finance.payroll` that contains a column `ssn` with sensitive data. The analyst wants to allow the HR team to query the table but mask the `ssn` column so that only users in the `hr_admins` group see the actual values; all other users should see `***` instead. Which Unity Catalog feature should the analyst use to achieve this?

⚠ Common exam trap

A common mix-up: candidates confuse column masking with row-level security, which filters rows rather than altering column values.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Column-level masking using a user-defined function (UDF) applied via `ALTER TABLE ... ALTER COLUMN ... SET MASK`.

Column masks in Unity Catalog allow conditional redaction of sensitive column values based on the querying user's identity or group memberships. By applying a mask function to the `ssn` column, the analyst can ensure that only members of `hr_admins` see the real values, while others see a masked placeholder. This satisfies the requirement without changing how users query the table.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Column-level masking using a user-defined function (UDF) applied via `ALTER TABLE ... ALTER COLUMN ... SET MASK`.

    Why this is correct

    Unity Catalog supports column masks that invoke a user-defined function to transform the column value at query time. The mask function can check the user's group membership and return the original value for members of `hr_admins` and a redacted value for others. This directly meets the requirement of conditional masking based on group membership.

  • ✗

    Table ACLs granting SELECT only to `hr_admins` and denying SELECT to others.

    Why it's wrong here

    Table ACLs control whether a user can query the table at all, not how individual column values are presented. Using ACLs would either allow or deny access to the entire table, which does not meet the requirement of allowing all users to query the table while masking the `ssn` column for non-admins. It lacks the granularity needed for column-level masking.

  • ✗

    Dynamic view that selects all columns except `ssn` for non-admin users.

    Why it's wrong here

    A dynamic view can exclude the `ssn` column for non-admins, but it would not show a masked value like `***`; it would simply omit the column. Also, dynamic views require users to query the view instead of the table, which changes the table reference. The requirement is to mask the column value, not to remove the column entirely.

  • ✗

    Row-level security using a filter expression on the table.

    Why it's wrong here

    Row-level security filters which rows are visible, not which column values are shown. It would not mask the `ssn` column; instead it would hide entire rows based on conditions. The requirement is to mask a specific column for certain users while still allowing them to see the rest of the row, so row-level security does not satisfy the need.

About these practice questions

Courseiva writes every Databricks-DA-Assoc question from scratch — 291 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.