Courseiva
Securing Data →hardMultiple Choice

Databricks-DA-Assoc Securing Data Practice Question

A data analyst needs to grant a service principal read access to a specific external location in Unity Catalog so that a scheduled job can read data from an S3 bucket. The analyst has already created a storage credential that references an IAM role with the necessary S3 permissions. Which Unity Catalog object must the analyst grant the service principal access to, in addition to the storage credential?

⚠ Common exam trap

The trap here is assuming that access to the storage credential is sufficient for data access, when actually the external location is the securable that must be granted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The external location

To allow a service principal to read from an external location, the analyst must grant the service principal `READ FILES` on that external location. The external location is the Unity Catalog securable that combines the cloud storage path with the storage credential, and it is the object against which privileges are granted. The storage credential itself is not granted to users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The AWS IAM role

    Why it's wrong here

    The IAM role is an AWS identity that the storage credential assumes. The service principal does not directly assume the IAM role; Unity Catalog does. Granting the service principal access to the IAM role is not a Unity Catalog operation and would not grant the necessary permissions within Databricks. The correct object is the external location, which ties the storage credential to the path.

  • ✗

    The storage credential

    Why it's wrong here

    The storage credential encapsulates the IAM role and is used by Unity Catalog to access cloud storage, but it is not the object that grants data access to users or service principals. Users do not need direct privileges on the storage credential; instead, they need privileges on the external location that references it. Granting only the storage credential would not allow the service principal to read the data.

  • ✗

    The S3 bucket policy

    Why it's wrong here

    The S3 bucket policy is an AWS-level configuration that grants permissions to the IAM role. It does not control access for Databricks principals. The service principal needs Unity Catalog privileges on the external location to read files. Modifying the S3 bucket policy is not required if the IAM role already has the necessary S3 permissions, as stated in the scenario.

  • ✓

    The external location

    Why this is correct

    In Unity Catalog, an external location object combines a storage path with a storage credential. To read data from the S3 bucket, the service principal must have `READ FILES` on the external location. Granting access to the storage credential alone is insufficient; the external location is the securable object that maps the path to the credential and controls access to the data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This Databricks-DA-Assoc question is part of Courseiva's 291-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.