Databricks-DA-Assoc Understanding the Databricks Platform Practice Question
A data analyst needs to query a table that contains sensitive customer financial data. Company policy requires that analysts see only masked values for account numbers in query results, and the masking must apply regardless of which tool or user queries the table. Which Databricks capability should be used to enforce this consistently at the data layer?
⚠ Common exam trap
Watch out — candidates often confuse access control with value masking: permissions and views restrict who or what rows are returned, but only a column mask rewrites the actual values for unauthorized readers on every query path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Column masks applied to the table
Column masks attach a masking expression directly to a table column, so the transformation is evaluated at query time for every read, independent of the client or user. This data-layer enforcement is exactly what the policy demands: unauthorized analysts receive masked account numbers whether they query via a notebook, the SQL editor, or a BI tool, and authorized users can still see real values.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A view that filters rows before returning results
Why it's wrong here
A view performs row-level filtering or column projection, but it does not transform column values for different users based on identity. Analysts who can read the base table directly would still see raw account numbers, and the view would need to be the only access path. Since the requirement is value masking for every query path, a filtering view is not the correct control.
- ✓
Column masks applied to the table
Why this is correct
Column masks are table-level security features that evaluate a masking expression each time the column is read, returning masked values for unauthorized users. Because the mask is attached to the table itself, it applies no matter which client, notebook, or dashboard issues the query, satisfying the requirement that masking be enforced consistently at the data layer for all users.
- ✗
Workspace-level notebook permissions
Why it's wrong here
Notebook permissions control who can view, run, or edit a notebook, not what values a query returns. Even with restricted notebook access, a user who can query the table through another notebook, the SQL editor, or an external BI tool would still see unmasked account numbers. This approach cannot enforce masking consistently across all access paths, so it fails the scenario.
- ✗
Cluster access mode configuration
Why it's wrong here
Cluster access modes determine whether a cluster is shared or single-user and influence which identity runs queries, but they do not mask column values in results. Changing the access mode affects isolation and compatibility of workloads, not the visibility of sensitive fields. It therefore cannot deliver the required masked account numbers across all tools and users.
About these practice questions
One of 291 original Databricks-DA-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.