Courseiva
Securing Data →mediumMultiple Choice

Databricks-DA-Assoc Securing Data Practice Question

A data analyst needs to share a sensitive sales table with the marketing team in Databricks. The marketing team should only see rows where the region column matches 'North America' and should not have access to the credit_card column. Which Unity Catalog feature should the data analyst implement?

⚠ Common exam trap

Candidates often incorrectly suggest creating separate physical views or duplicating data for different teams. They overlook that Unity Catalog features allow applying these restrictions directly to the base table object.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply row filters and column masks using SQL functions within Unity Catalog to restrict data visibility dynamically for the marketing group.

Row-level and column-level filtering in Unity Catalog allow administrators and data owners to secure fine-grained access to tables using SQL functions. By applying a dynamic view with conditional logic, users see only permitted rows and columns. This ensures regulatory compliance and data minimization principles are met without duplicating physical storage assets across different business units.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a static clone of the table, drop the restricted column, and grant SELECT permission on the clone to the marketing group.

    Why it's wrong here

    Static cloning creates an expensive duplicate copy of the data that immediately drifts from the source table. Maintaining synchronized updates requires complex engineering pipelines, violating the single source of truth principle within the Unity Catalog architecture.

  • ✓

    Apply row filters and column masks using SQL functions within Unity Catalog to restrict data visibility dynamically for the marketing group.

    Why this is correct

    Unity Catalog row filters and column masks dynamically filter rows and redact column values at query time based on user identity or group membership. This approach eliminates data duplication, ensures real-time updates, and provides robust governance security.

  • ✗

    Configure an access control list on the parent catalog to deny SELECT access on specific columns for the marketing group.

    Why it's wrong here

    Unity Catalog access control lists operate at the catalog, schema, table, and view levels. They do not support denying access to individual columns or filtering specific rows natively through catalog permissions alone.

  • ✗

    Export the filtered subset of data into CSV files and upload them to a secured volume inside the marketing team's schema.

    Why it's wrong here

    Exporting data to flat files introduces severe security risks, including unmanaged data proliferation, lack of audit trails, and stale data snapshots. It circumvents the centralized governance and security auditing capabilities provided by Unity Catalog.

About these practice questions

One of 291 original Databricks-DA-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.