A data platform administrator needs to configure secure data access policies in Unity Catalog. Which TWO actions can the administrator perform to restrict access to sensitive columns within a Delta table? (Choose TWO)
Unity Catalog allows administrators to grant or revoke SELECT privileges at the individual column level. This capability ensures that users only query the specific attributes they are authorized to see, preventing unauthorized exposure of sensitive enterprise data fields.
Why this answer
Unity Catalog supports fine-grained governance through column-level access controls and dynamic masking functions. Administrators can restrict column visibility directly by revoking SELECT privileges on specific columns or by applying SQL-based masking functions that evaluate user attributes at query time. These native capabilities ensure sensitive information remains protected across all notebooks, dashboards, and SQL queries without duplicating physical data assets.
Exam trap
Candidates often assume that column-level security requires row-level filtering or physical data duplication, missing that Unity Catalog provides native SQL-based masking and privilege controls directly on the schema objects.