Databricks-DA-Assoc Understanding the Databricks Platform Practice Question
A data analyst needs to share a notebook with a colleague who should be able to run the code but not modify it. Which permission level should the analyst grant to the colleague?
⚠ Common exam trap
Candidates often select 'Can Edit' or 'Can Manage' out of habit, ignoring the principle of least privilege. They fail to realize 'Can Run' is sufficient for executing code without altering logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Can Run
The 'Can Run' permission is designed for scenarios where users need to execute code within a notebook without altering the underlying logic. In the Databricks access control model, this permission ensures that the notebook's integrity remains intact while still allowing collaborative execution. It is a critical security practice to follow the principle of least privilege, ensuring users have only the necessary permissions for their specific analytical tasks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Can Manage
Why it's wrong here
Granting 'Can Manage' provides full administrative control, allowing the user to change permissions, delete the notebook, and modify all content. This level of access is far too broad for a user who only needs execution rights and poses a significant security risk to the notebook's stability and integrity.
- ✓
Can Run
Why this is correct
The 'Can Run' permission allows a user to attach the notebook to a cluster and execute its cells. It specifically prevents the user from modifying the notebook's code or changing its settings, making it the appropriate choice for analysts who need to run reports without altering the source data processing logic.
- ✗
Can Edit
Why it's wrong here
The 'Can Edit' permission allows a user to modify the notebook's content, add or remove cells, and change the code structure. This level of access exceeds the requirement, as the user should be restricted from making changes, and unintended edits could disrupt the results of the analytical pipeline.
- ✗
Can View
Why it's wrong here
The 'Can View' permission allows a user to open and read the notebook but does not provide the capability to execute code cells. Since the analyst specifically requires the colleague to run the code, this permission is insufficient to meet the functional requirements of the task at hand.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every Databricks-DA-Assoc question from scratch — 291 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.