Courseiva
Securing Data →mediumMultiple Choice

Databricks-DA-Assoc Securing Data Practice Question

A data analyst in the 'marketing' group needs to query the table `main.sales.leads` but should not be able to read the underlying data files directly. The analyst currently has `SELECT` on the table and `READ FILES` on the external location where the table's data resides. Which Unity Catalog privilege should the analyst's `READ FILES` on the external location be removed to enforce least privilege?

⚠ Common exam trap

The trap here is assuming that `READ FILES` is required for querying a table, when in fact `SELECT` on the table is sufficient and `READ FILES` only grants direct file access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

`READ FILES` on the external location

To enforce least privilege, the analyst should not have direct file access when table-level access suffices. `READ FILES` on the external location allows bypassing Unity Catalog table permissions, so it must be removed. `SELECT` on the table remains to allow querying, while `USAGE` on the schema and `BROWSE` on the catalog are unrelated to file-level reads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    `SELECT` on the table

    Why it's wrong here

    Revoking `SELECT` on the table would prevent the analyst from querying the table at all, which contradicts the requirement that the analyst must be able to query `main.sales.leads`. The issue is not table-level access but the unnecessary file-level permission. Removing `SELECT` would break the required functionality and does not address the over-privilege.

  • ✗

    `BROWSE` on the catalog `main`

    Why it's wrong here

    `BROWSE` on the catalog allows the analyst to discover objects but does not grant access to data. Revoking it would not prevent direct file reads; it would only limit visibility in the UI. The analyst's ability to read files comes from `READ FILES` on the external location, so removing `BROWSE` does not address the security concern and may hinder legitimate exploration.

  • ✓

    `READ FILES` on the external location

    Why this is correct

    Removing `READ FILES` on the external location prevents the analyst from bypassing Unity Catalog table-level controls and reading raw data files directly. The analyst retains `SELECT` on the table, so querying through SQL or DataFrames continues to work. This enforces least privilege because file-level access is no longer needed for the analyst's role, and Unity Catalog manages access at the table level.

  • ✗

    `USAGE` on the schema `main.sales`

    Why it's wrong here

    `USAGE` on the schema is required for the analyst to access any object within the schema, including the table. Revoking it would cause the analyst to lose the ability to query the table, which is not desired. The over-privilege is at the external location level, not at the schema level. Therefore, this action would not achieve least privilege for file access.

About these practice questions

Courseiva writes every Databricks-DA-Assoc question from scratch — 291 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.