Databricks-DA-Assoc Securing Data Practice Question
A data analyst needs to grant a service principal read access to a specific external location in Unity Catalog so that a scheduled job can read data from an S3 bucket. The analyst has already created a storage credential that references an IAM role with the necessary S3 permissions. Which Unity Catalog object must the analyst grant the service principal access to, in addition to the storage credential?
⚠ Common exam trap
The trap here is assuming that access to the storage credential is sufficient for data access, when actually the external location is the securable that must be granted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The external location
To allow a service principal to read from an external location, the analyst must grant the service principal `READ FILES` on that external location. The external location is the Unity Catalog securable that combines the cloud storage path with the storage credential, and it is the object against which privileges are granted. The storage credential itself is not granted to users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The AWS IAM role
Why it's wrong here
The IAM role is an AWS identity that the storage credential assumes. The service principal does not directly assume the IAM role; Unity Catalog does. Granting the service principal access to the IAM role is not a Unity Catalog operation and would not grant the necessary permissions within Databricks. The correct object is the external location, which ties the storage credential to the path.
- ✗
The storage credential
Why it's wrong here
The storage credential encapsulates the IAM role and is used by Unity Catalog to access cloud storage, but it is not the object that grants data access to users or service principals. Users do not need direct privileges on the storage credential; instead, they need privileges on the external location that references it. Granting only the storage credential would not allow the service principal to read the data.
- ✗
The S3 bucket policy
Why it's wrong here
The S3 bucket policy is an AWS-level configuration that grants permissions to the IAM role. It does not control access for Databricks principals. The service principal needs Unity Catalog privileges on the external location to read files. Modifying the S3 bucket policy is not required if the IAM role already has the necessary S3 permissions, as stated in the scenario.
- ✓
The external location
Why this is correct
In Unity Catalog, an external location object combines a storage path with a storage credential. To read data from the S3 bucket, the service principal must have `READ FILES` on the external location. Granting access to the storage credential alone is insufficient; the external location is the securable object that maps the path to the credential and controls access to the data.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
This Databricks-DA-Assoc question is part of Courseiva's 291-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.