Databricks-DA-Assoc Securing Data Practice Question
A data analyst is reviewing audit logs in Databricks to investigate unauthorized access attempts to a sensitive table. Which audit log event type should the analyst filter on to find failed attempts to query the table?
⚠ Common exam trap
The trap here is assuming that `tableAccess` logs include failed attempts, when in fact `tableAccess` only records successful accesses; failures are logged as `permissionDenied`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
`permissionDenied`
To investigate unauthorized access attempts, the analyst should filter audit logs for `permissionDenied` events. These events are generated when a user lacks the required privileges for an action, such as querying a table. Other event types like `tableAccess` or `sqlQuery` focus on successful operations or query details, not permission failures. `login` events are about authentication, not table access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
`login`
Why it's wrong here
`login` events record authentication attempts, both successful and failed. While failed logins could indicate unauthorized access, they do not capture attempts to query a specific table after authentication. The scenario is about unauthorized access attempts to a table, which would be logged as permission denials, not login failures. Thus, `login` is not the right filter.
- ✗
`tableAccess`
Why it's wrong here
`tableAccess` events record successful access to tables, such as when a user queries a table. They do not specifically capture failed attempts; failed attempts are logged under a different event type. Filtering on `tableAccess` would show successful queries, not the unauthorized attempts the analyst is investigating.
- ✓
`permissionDenied`
Why this is correct
`permissionDenied` events are generated when a user attempts an action but lacks the necessary privileges. These events capture failed attempts to access tables, including queries that are denied due to insufficient permissions. Filtering on `permissionDenied` allows the analyst to identify unauthorized access attempts. This is the correct event type for investigating security violations.
- ✗
`sqlQuery`
Why it's wrong here
`sqlQuery` events log SQL queries executed, but they may not distinguish between successful and failed permission checks. They are more about the query text and execution details. Unauthorized attempts that fail due to permissions are better captured by `permissionDenied`. Filtering on `sqlQuery` might show the query attempt but not the denial, making it less direct for identifying unauthorized access.
About these practice questions
This Databricks-DA-Assoc question is part of Courseiva's 291-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.