Databricks-DA-Assoc Data Modeling with Databricks SQL Practice Question
An organization requires that certain sensitive columns be removed from a table for specific groups of users. Which Databricks feature should be used to enforce this at the data modeling level?
⚠ Common exam trap
Candidates often get confused between 'Data Masking' and 'Row Filters'. They might select row-level security when the requirement specifically asks for column-level removal or obscuring of sensitive data attributes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Delta Lake dynamic masking.
Dynamic Data Masking and Row-Level Security are the preferred methods for controlling access to sensitive data within Databricks SQL. By using SQL functions to define masking policies, administrators can ensure that users only see the data they are authorized to view. This approach keeps the underlying data intact while providing secure, role-based access control, ensuring compliance with data privacy regulations without duplicating data for different security profiles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create separate physical tables for each security level.
Why it's wrong here
Managing separate tables for security introduces massive redundancy, synchronization challenges, and storage overhead. It is a highly inefficient way to handle access control and makes schema evolution nearly impossible to manage correctly. Modern Databricks security features allow for granular control without needing to physically separate the data architecture.
- ✓
Use Delta Lake dynamic masking.
Why this is correct
Dynamic masking allows for the definition of policies that transform or redact column content based on the user's role at query time. This ensures security is enforced consistently across all applications and users, without altering the underlying data on disk, which is vital for maintaining data governance and compliance standards.
- ✗
Change the file format to JSON to strip sensitive fields.
Why it's wrong here
Changing file formats does not provide security or access control. Anyone with access to the storage layer could still read the files. Furthermore, JSON format is significantly less performant for analytical queries than Delta Lake, making this an inappropriate choice for both security and performance optimization in Databricks SQL.
- ✗
Hard-code the filtering logic in every user's SQL query.
Why it's wrong here
Relying on end-users to apply security filters is a major security risk, as it is prone to human error and bypasses. Security must be enforced at the platform level (Unity Catalog) to ensure it is consistent, immutable, and auditable, which is the standard practice in a mature data governance framework.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 291 original Databricks-DA-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.