Databricks-DA-Assoc Securing Data Practice Question
A data analyst has been asked to grant a new team member read access to a specific table named 'customer_orders' in Unity Catalog. The analyst wants to ensure the team member can query the table but cannot see any other tables in the schema. Which SQL command should the analyst use?
⚠ Common exam trap
Many exam-takers confuse the USAGE privilege with SELECT for tables, or assuming that schema-level grants are necessary for table access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GRANT SELECT ON TABLE main.sales.customer_orders TO `user@example.com`;
To grant read access to a specific table in Unity Catalog, the SELECT privilege must be granted on that table. This allows the user to query the table's data while leaving other tables inaccessible. Schema- or catalog-level grants are broader and would inadvertently expose additional data, so they are not suitable for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GRANT SELECT ON SCHEMA main.sales TO `user@example.com`;
Why it's wrong here
Granting SELECT on the entire schema would allow the user to read all tables within that schema, including 'customer_orders', but also any other tables present. This violates the requirement to restrict access to only the specified table. Schema-level grants are broader and not appropriate when table-level isolation is needed.
- ✓
GRANT SELECT ON TABLE main.sales.customer_orders TO `user@example.com`;
Why this is correct
This command grants the SELECT privilege on the specific table 'main.sales.customer_orders' to the user. In Unity Catalog, table-level grants are supported and allow fine-grained access control, enabling the user to query only that table without access to other tables in the schema. This directly satisfies the requirement.
- ✗
GRANT USAGE ON TABLE main.sales.customer_orders TO `user@example.com`;
Why it's wrong here
USAGE is not a valid privilege for tables in Unity Catalog; it applies to catalogs and schemas. Granting USAGE on a table would not grant the ability to query data. The correct privilege for reading table data is SELECT, not USAGE. This command would likely fail or have no effect.
- ✗
GRANT SELECT ON CATALOG main TO `user@example.com`;
Why it's wrong here
Granting SELECT on the entire catalog would give the user read access to all tables in every schema within the catalog, far exceeding the intended scope. This violates the principle of least privilege and does not meet the requirement to limit access to a single table.
About these practice questions
Courseiva writes every Databricks-DA-Assoc question from scratch — 291 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.