Courseiva
Securing Data →mediumMultiple Select

Databricks-DA-Assoc Securing Data Practice Question

A data platform administrator needs to configure secure data access policies in Unity Catalog. Which TWO actions can the administrator perform to restrict access to sensitive columns within a Delta table? (Choose TWO)

⚠ Common exam trap

Candidates often assume that column-level security requires row-level filtering or physical data duplication, missing that Unity Catalog provides native SQL-based masking and privilege controls directly on the schema objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant SELECT privilege on the specific sensitive columns to authorized users while withholding it on other columns in the table.

Unity Catalog supports fine-grained governance through column-level access controls and dynamic masking functions. Administrators can restrict column visibility directly by revoking SELECT privileges on specific columns or by applying SQL-based masking functions that evaluate user attributes at query time. These native capabilities ensure sensitive information remains protected across all notebooks, dashboards, and SQL queries without duplicating physical data assets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant SELECT privilege on the specific sensitive columns to authorized users while withholding it on other columns in the table.

    Why this is correct

    Unity Catalog allows administrators to grant or revoke SELECT privileges at the individual column level. This capability ensures that users only query the specific attributes they are authorized to see, preventing unauthorized exposure of sensitive enterprise data fields.

  • ✓

    Apply a Unity Catalog column mask using a SQL function that transforms or redacts sensitive values based on the querying user's identity.

    Why this is correct

    A column mask applies a SQL function at query time, returning transformed or redacted values unless the querying user matches an authorised condition. This restricts sensitive column visibility without altering stored data, satisfying Unity Catalog's fine-grained access requirement.

  • ✗

    Modify the cloud storage bucket permissions in AWS S3 or Azure Blob Storage to block read access to individual table files containing sensitive columns.

    Why it's wrong here

    Cloud storage permissions operate at the file or bucket level rather than individual columns within Parquet files. Delta tables store multiple columns within shared data files, making cloud storage ACLs incapable of enforcing column-level security restrictions.

  • ✗

    Enable row-level security filters on the table to automatically exclude rows containing sensitive attribute values from query results.

    Why it's wrong here

    Row filters control record visibility rather than column visibility. While row filters restrict access horizontally based on criteria like region or department, they do not hide specific columns or attributes vertically across the remaining visible rows.

  • ✗

    Create a static clone of the table using the CLONE command and delete the sensitive columns from the cloned copy for general users.

    Why it's wrong here

    A static clone creates a separate physical copy, so the original table's sensitive columns remain readable and the clone drifts out of sync. It is tempting for producing a sanitised dataset for analysts, but column-level access control is enforced through Unity Catalog row filters and column masks on the source table.

About these practice questions

One of 291 original Databricks-DA-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.