Courseiva

CCNA Securing Data Questions

24 questions · Securing Data · All types, answers revealed

1
Multi-Selectmedium

A data platform administrator needs to configure secure data access policies in Unity Catalog. Which TWO actions can the administrator perform to restrict access to sensitive columns within a Delta table? (Choose TWO)

Select 2 answers
A.Grant SELECT privilege on the specific sensitive columns to authorized users while withholding it on other columns in the table.
B.Apply a Unity Catalog column mask using a SQL function that transforms or redacts sensitive values based on the querying user's identity.
C.Modify the cloud storage bucket permissions in AWS S3 or Azure Blob Storage to block read access to individual table files containing sensitive columns.
D.Enable row-level security filters on the table to automatically exclude rows containing sensitive attribute values from query results.
E.Create a static clone of the table using the CLONE command and delete the sensitive columns from the cloned copy for general users.
AnswersA, B

Unity Catalog allows administrators to grant or revoke SELECT privileges at the individual column level. This capability ensures that users only query the specific attributes they are authorized to see, preventing unauthorized exposure of sensitive enterprise data fields.

Why this answer

Unity Catalog supports fine-grained governance through column-level access controls and dynamic masking functions. Administrators can restrict column visibility directly by revoking SELECT privileges on specific columns or by applying SQL-based masking functions that evaluate user attributes at query time. These native capabilities ensure sensitive information remains protected across all notebooks, dashboards, and SQL queries without duplicating physical data assets.

Exam trap

Candidates often assume that column-level security requires row-level filtering or physical data duplication, missing that Unity Catalog provides native SQL-based masking and privilege controls directly on the schema objects.

2
MCQhard

A data analyst needs to grant a service principal read access to a specific external location in Unity Catalog so that a scheduled job can read data from an S3 bucket. The analyst has already created a storage credential that references an IAM role with the necessary S3 permissions. Which Unity Catalog object must the analyst grant the service principal access to, in addition to the storage credential?

A.The AWS IAM role
B.The storage credential
C.The S3 bucket policy
D.The external location
AnswerD

In Unity Catalog, an external location object combines a storage path with a storage credential. To read data from the S3 bucket, the service principal must have `READ FILES` on the external location. Granting access to the storage credential alone is insufficient; the external location is the securable object that maps the path to the credential and controls access to the data.

Why this answer

To allow a service principal to read from an external location, the analyst must grant the service principal `READ FILES` on that external location. The external location is the Unity Catalog securable that combines the cloud storage path with the storage credential, and it is the object against which privileges are granted. The storage credential itself is not granted to users.

Exam trap

The trap here is assuming that access to the storage credential is sufficient for data access, when actually the external location is the securable that must be granted.

3
MCQhard

Refer to the exhibit. This IAM policy is attached to a Storage Credential. A user tries to run 'DROP TABLE' on a table stored in this bucket and fails. Why?

A.The user lacks the 'DROP' privilege in Unity Catalog.
B.The IAM policy does not include 's3:DeleteObject'.
C.The bucket is marked as 'Read Only' in Unity Catalog.
D.The table is owned by the metastore admin.
AnswerB

To successfully drop a table, Databricks must be able to delete the underlying objects in S3. The provided IAM policy only contains read-level permissions ('GetObject', 'ListBucket'). Without the 'DeleteObject' permission, the cloud provider will reject the request, preventing Databricks from completing the deletion process, regardless of internal permissions.

Why this answer

The IAM policy only grants 's3:GetObject' and 's3:ListBucket', which are read-only permissions. The 'DROP TABLE' command in Databricks requires 's3:DeleteObject' permission on the underlying data to remove the files from S3. Because the policy lacks delete permissions, the operation is blocked by the cloud provider, even if the user has the 'DROP' privilege in Databricks.

Exam trap

Test-takers assume Databricks SQL permissions override cloud IAM restrictions, forgetting that cloud-level missing delete policies will block operations.

4
MCQmedium

A data analyst is reviewing audit logs in Databricks to investigate unauthorized access attempts to a sensitive table. Which audit log event type should the analyst filter on to find failed attempts to query the table?

A.`login`
B.`tableAccess`
C.`permissionDenied`
D.`sqlQuery`
AnswerC

`permissionDenied` events are generated when a user attempts an action but lacks the necessary privileges. These events capture failed attempts to access tables, including queries that are denied due to insufficient permissions. Filtering on `permissionDenied` allows the analyst to identify unauthorized access attempts. This is the correct event type for investigating security violations.

Why this answer

To investigate unauthorized access attempts, the analyst should filter audit logs for `permissionDenied` events. These events are generated when a user lacks the required privileges for an action, such as querying a table. Other event types like `tableAccess` or `sqlQuery` focus on successful operations or query details, not permission failures. `login` events are about authentication, not table access.

Exam trap

The trap here is assuming that `tableAccess` logs include failed attempts, when in fact `tableAccess` only records successful accesses; failures are logged as `permissionDenied`.

5
MCQmedium

A data analyst has a Unity Catalog table `main.finance.payroll` that contains a column `ssn` with sensitive data. The analyst wants to allow the HR team to query the table but mask the `ssn` column so that only users in the `hr_admins` group see the actual values; all other users should see `***` instead. Which Unity Catalog feature should the analyst use to achieve this?

A.Column-level masking using a user-defined function (UDF) applied via `ALTER TABLE ... ALTER COLUMN ... SET MASK`.
B.Table ACLs granting SELECT only to `hr_admins` and denying SELECT to others.
C.Dynamic view that selects all columns except `ssn` for non-admin users.
D.Row-level security using a filter expression on the table.
AnswerA

Unity Catalog supports column masks that invoke a user-defined function to transform the column value at query time. The mask function can check the user's group membership and return the original value for members of `hr_admins` and a redacted value for others. This directly meets the requirement of conditional masking based on group membership.

Why this answer

Column masks in Unity Catalog allow conditional redaction of sensitive column values based on the querying user's identity or group memberships. By applying a mask function to the `ssn` column, the analyst can ensure that only members of `hr_admins` see the real values, while others see a masked placeholder. This satisfies the requirement without changing how users query the table.

Exam trap

The trap here is confusing column masking with row-level security, which filters rows rather than altering column values.

6
MCQhard

Refer to the exhibit. A data scientist can query both tables, but the join fails with a permission error. What is the most likely reason?

A.The user lacks SELECT access on the 'prod' catalog.
B.The user lacks USAGE on the 'default' schema.
C.The join condition requires elevated privileges.
D.The tables are in different catalogs.
AnswerB

Unity Catalog requires USAGE privileges on all containers in the hierarchy, including the schema. If the 'data_scientists' group does not have the USAGE privilege on the 'default' schema, they cannot resolve the tables for the join, even if they have individual SELECT access to the tables within that same schema.

Why this answer

In Unity Catalog, the user must have the USAGE privilege on every schema involved in a query, even if they have SELECT access on the tables within those schemas. If the 'default' schema lacks the USAGE grant for the group, the query engine cannot validate the path to the data, causing the join to fail at the permission check level despite table-level SELECT access.

Exam trap

Candidates assume having SELECT on the tables in a join is sufficient, forgetting that USAGE is required on every participating schema.

7
MCQmedium

Which audit log category is most useful for identifying unauthorized attempts to access sensitive tables?

A.Cluster-level Spark logs.
B.Unity Catalog audit logs.
C.Job run output logs.
D.Workspace-level login logs.
AnswerB

Unity Catalog audit logs provide a comprehensive record of all metadata and data access events. These logs capture who requested data, which table they accessed, and whether the request was granted or denied. This makes them the primary source for security investigations and auditing of data access activities within the workspace.

Why this answer

The 'Unity Catalog' audit log category records all actions performed within the metastore, including access attempts. By monitoring this log, security analysts can identify unauthorized 'SELECT' or 'DESCRIBE' attempts that failed due to permission denials. This is critical for detecting potential internal threats or misconfigured access policies that could lead to unauthorized data exposure.

Exam trap

Test-takers often choose generic cluster or workspace logs instead of identifying Unity Catalog audit logs, which specifically track data access and permission denials.

8
MCQmedium

Which THREE actions are required to successfully secure an external location in Unity Catalog?

A.Create a Storage Credential in Databricks.
B.Grant the 'READ FILES' or 'WRITE FILES' privilege on the external location.
C.Create an External Location object in Unity Catalog.
D.Manually update the cluster's Spark configuration.
E.Provide all users the 'Owner' role on the metastore.
AnswerA, B, C

A Storage Credential object is required to store the cloud provider credentials that allow Databricks to access your storage account. This is the first step in the process, as the External Location depends on this credential to perform any read or write operations against the underlying cloud storage provider.

Why this answer

Securing an external location in Unity Catalog involves creating a Storage Credential, linking that credential to an External Location, and granting specific permissions on that location. This layered approach ensures that access is controlled at both the cloud identity level and the Databricks governance level, allowing administrators to audit all access to external storage paths through Unity Catalog logs.

Exam trap

Students often forget that securing an external location requires both a storage credential and an explicit file-level privilege grant like READ FILES.

9
MCQmedium

What is the primary function of a Storage Credential in Unity Catalog?

A.To encrypt files stored in the S3 bucket.
B.To provide a secure way to access cloud storage locations.
C.To manage user passwords for the Databricks workspace.
D.To define table schema definitions for external tables.
AnswerB

Storage credentials act as a secure bridge, allowing the Databricks platform to assume a managed identity to perform operations on behalf of the user. This architecture prevents the need for embedding raw access keys in notebooks or cluster configurations, significantly reducing the surface area for credential leakage or misuse.

Why this answer

A Storage Credential is an object in Unity Catalog that encapsulates long-term cloud provider credentials (like an AWS IAM role or Azure Service Principal). It allows Databricks to access data in cloud storage without requiring users to configure individual cloud credentials on every cluster. This centralizes security by keeping sensitive cloud keys away from end users and developers.

Exam trap

Many candidates confuse storage credentials with individual user cloud logins, failing to understand that credentials decouple cloud access from end users.

10
MCQhard

A data analyst is using Databricks SQL to query a table `main.sales.orders` that has a column `credit_card` containing sensitive data. The analyst needs to run a query that aggregates orders by region but must not see the actual credit card numbers. Which Unity Catalog feature should be used to mask the `credit_card` column for this analyst?

A.Granting `SELECT` only on specific columns
B.Using `REDACT` function in the query
C.Column-level dynamic data masking using a user-defined function
D.Row-level security using a dynamic view
AnswerC

Column-level dynamic data masking allows you to apply a function to a column that transforms the data based on the querying user's identity or group. This masks sensitive values like credit card numbers while still allowing aggregations and queries. The analyst can run the aggregation without seeing the actual data. This is the recommended approach in Unity Catalog for column-level security.

Why this answer

Column-level dynamic data masking in Unity Catalog allows administrators to attach a masking function to a column. The function can return a masked value (e.g., '****') for unauthorized users while returning the actual value for authorized users. This enables the analyst to run aggregations without seeing sensitive data.

Other options either do not address column masking or are not supported features.

Exam trap

The trap here is confusing row-level security with column-level masking; row-level security filters rows, while masking transforms column values.

11
MCQeasy

When sharing data with external organizations using Delta Sharing, which component manages the secure exchange of data?

A.Unity Catalog metastore.
B.Workspace-local Hive metastore.
C.Databricks File System (DBFS) Root.
D.User-managed S3 bucket policies.
AnswerA

The Unity Catalog metastore serves as the governance layer that defines and tracks Delta Shares. It holds the metadata about the share, including which tables are included and which recipients have access. Without the metastore, there is no central mechanism to authorize or audit the external sharing of data assets.

Why this answer

Delta Sharing is an open protocol that enables the secure exchange of data across different organizations without requiring them to have accounts in the same Databricks workspace. The Unity Catalog metastore acts as the central control point for these shares. By creating a 'Share' object, an administrator defines exactly which tables are shared, and the recipient uses a token to access that data securely.

Exam trap

Many candidates mistakenly believe that individual clusters, notebooks, or workspace admins manage Delta Sharing instead of recognizing the central role of the Unity Catalog metastore.

12
MCQmedium

A data analyst has been asked to grant a new team member read access to a specific table named 'customer_orders' in Unity Catalog. The analyst wants to ensure the team member can query the table but cannot see any other tables in the schema. Which SQL command should the analyst use?

A.GRANT SELECT ON SCHEMA main.sales TO `user@example.com`;
B.GRANT SELECT ON TABLE main.sales.customer_orders TO `user@example.com`;
C.GRANT USAGE ON TABLE main.sales.customer_orders TO `user@example.com`;
D.GRANT SELECT ON CATALOG main TO `user@example.com`;
AnswerB

This command grants the SELECT privilege on the specific table 'main.sales.customer_orders' to the user. In Unity Catalog, table-level grants are supported and allow fine-grained access control, enabling the user to query only that table without access to other tables in the schema. This directly satisfies the requirement.

Why this answer

To grant read access to a specific table in Unity Catalog, the SELECT privilege must be granted on that table. This allows the user to query the table's data while leaving other tables inaccessible. Schema- or catalog-level grants are broader and would inadvertently expose additional data, so they are not suitable for this scenario.

Exam trap

The trap here is confusing the USAGE privilege with SELECT for tables, or assuming that schema-level grants are necessary for table access.

13
MCQmedium

An administrator needs to secure a table containing sensitive customer data. Which TWO options represent valid ways to restrict access using Unity Catalog?

A.Use GRANT SELECT on the table to specific users or groups.
B.Delete the sensitive rows from the table manually.
C.Implement column masking policies on sensitive columns.
D.Rotate the workspace passwords weekly.
E.Disable the table for all users except the owner.
AnswerA, C

Standard SQL access controls allow administrators to explicitly define who can read a table. This is the fundamental mechanism for data governance in Unity Catalog, ensuring that only authorized users or service principals can execute queries against the sensitive data, adhering to the principle of least privilege.

Why this answer

Unity Catalog provides robust security primitives including standard SQL GRANT/REVOKE commands and dynamic masking. By using these features, administrators can define who sees what data without altering the underlying data files. These two methods are the standard, best-practice approaches for ensuring that sensitive data is protected while maintaining a clean, performant analytics environment for end users.

Exam trap

Candidates frequently select broad workspace-level admin roles or native cloud storage policies instead of focusing on Unity Catalog native primitives like GRANT and column masking.

14
MCQeasy

A data analyst is reviewing audit logs in Databricks to investigate who accessed a sensitive table 'main.finance.payroll'. The analyst needs to identify the user, the timestamp, and the action performed. Which audit log service should the analyst query to find this information?

A.The 'unityCatalog' audit log service
B.The 'jobs' audit log service
C.The 'notebook' audit log service
D.The 'clusters' audit log service
AnswerA

The 'unityCatalog' audit log service records events related to Unity Catalog, including data access, privilege changes, and table operations. It captures the user, timestamp, and action for queries against tables like 'main.finance.payroll'. This is the correct service to query for access details.

Why this answer

Unity Catalog audit logs capture data access events, including user, timestamp, and action, for tables governed by Unity Catalog. The 'unityCatalog' service is the correct source for investigating access to 'main.finance.payroll'.

Exam trap

The trap here is confusing cluster or job logs with data access logs; only Unity Catalog logs record table-level access details.

15
MCQeasy

A data analyst wants to share a Unity Catalog table with an external partner using Delta Sharing. The partner uses a non-Databricks client that supports the Delta Sharing protocol. Which Unity Catalog object must the analyst create to enable the partner to access the shared data?

A.A share
B.A recipient
C.A provider
D.A storage credential
AnswerA

A share is the Unity Catalog object that packages tables to be shared via Delta Sharing. The analyst creates a share, adds the table to it, and then grants the recipient access to the share. The recipient can then use the Delta Sharing protocol to read the shared data. This is the correct object to create for sharing data externally.

Why this answer

To share a table with an external partner, the analyst must create a share in Unity Catalog, add the table to the share, and then grant the recipient access to the share. The recipient can then use the Delta Sharing protocol to read the data. A share is the container for shared data, while a recipient identifies the external party.

Exam trap

The trap here is confusing the roles of share, recipient, and provider in Delta Sharing, and thinking that a recipient or provider is the object that directly holds the shared data.

16
MCQmedium

A data analyst needs to share a sensitive sales table with the marketing team in Databricks. The marketing team should only see rows where the region column matches 'North America' and should not have access to the credit_card column. Which Unity Catalog feature should the data analyst implement?

A.Create a static clone of the table, drop the restricted column, and grant SELECT permission on the clone to the marketing group.
B.Apply row filters and column masks using SQL functions within Unity Catalog to restrict data visibility dynamically for the marketing group.
C.Configure an access control list on the parent catalog to deny SELECT access on specific columns for the marketing group.
D.Export the filtered subset of data into CSV files and upload them to a secured volume inside the marketing team's schema.
AnswerB

Unity Catalog row filters and column masks dynamically filter rows and redact column values at query time based on user identity or group membership. This approach eliminates data duplication, ensures real-time updates, and provides robust governance security.

Why this answer

Row-level and column-level filtering in Unity Catalog allow administrators and data owners to secure fine-grained access to tables using SQL functions. By applying a dynamic view with conditional logic, users see only permitted rows and columns. This ensures regulatory compliance and data minimization principles are met without duplicating physical storage assets across different business units.

Exam trap

Candidates often incorrectly suggest creating separate physical views or duplicating data for different teams. They overlook that Unity Catalog features allow applying these restrictions directly to the base table object.

17
MCQhard

A data analyst at a multinational bank needs to ensure that queries against a Unity Catalog table 'main.risk.transactions' automatically hide the 'customer_ssn' column for users in the 'contractors' group, while all other users see the full data. The analyst wants to implement this without creating separate views for each user group. Which Unity Catalog feature should the analyst use?

A.Row-level security with a filter function
B.Column mask with a masking function
C.Attribute-based access control (ABAC) with tags
D.Dynamic view with a CASE statement
AnswerB

Column masks allow you to apply a function to a column that returns a masked value based on the user's group membership. The analyst can create a mask that returns NULL or a redacted value for the 'contractors' group and the original value for others. This meets the requirement without separate views.

Why this answer

Column masks in Unity Catalog allow you to apply a masking function to a column that evaluates the user's identity and returns a masked value for specific groups. This directly satisfies the requirement to hide 'customer_ssn' for contractors while showing it to others.

Exam trap

The trap here is confusing row-level security with column-level masking; row filters hide rows, not columns.

18
MCQmedium

An organization stores sensitive financial records in a Unity Catalog managed Delta table stored in cloud object storage. To comply with corporate security mandates, all data at rest must be encrypted using a customer-managed encryption key rather than the default cloud provider-managed keys. Where must the administrator configure this encryption setting?

A.Inside the Databricks notebook before executing any SQL queries against the sensitive financial Delta table.
B.Within the Unity Catalog metastore root storage configuration using a cloud-provider storage credential linked to a customer-managed key.
C.By modifying the Spark session configuration spark.databricks.io.encryption.enabled to true in the cluster policy.
D.Through the Apache Spark dataframe write option by setting the encryption parameter to customer_managed prior to saving.
AnswerB

Unity Catalog managed tables inherit encryption from the metastore root storage location, so the customer-managed key must be attached there via a storage credential. Table-level or workspace settings cannot override the root storage encryption for managed data at rest.

Why this answer

Customer-managed keys (CMK) for managed storage in Unity Catalog are configured at the storage credential or metastore level when establishing the root storage location. This ensures that all managed tables and volumes created within that storage root automatically leverage the specified encryption key, enforcing enterprise compliance policies transparently across all downstream data assets and analytics workloads.

Exam trap

Candidates often mistakenly believe encryption keys are configured at the individual table or schema level, failing to realize that Unity Catalog root storage encryption must be set at the metastore or storage credential level.

19
MCQhard

A data analyst is using a Databricks SQL warehouse to query a table that is protected by row-level security using dynamic views in Unity Catalog. The analyst has SELECT on the view but not on the underlying table. When querying the view, the analyst receives an error about insufficient privileges on the base table. What is the most likely cause?

A.The analyst needs to be granted SELECT on the base table directly to query the view.
B.The view owner does not have SELECT privilege on the underlying table, so the view cannot access it.
C.The view is defined with SQL SECURITY INVOKER, which requires the analyst to have base table access.
D.The view was created without the SECURITY DEFINER clause, so the analyst's permissions are used to access the base table.
AnswerB

In Unity Catalog, views run with the view owner's privileges. If the owner lacks SELECT on the base table, the view cannot retrieve data, causing an error for any user querying the view. The analyst's own privileges are irrelevant because the view executes as the owner. Thus, the owner must have the necessary privileges on the base table.

Why this answer

In Unity Catalog, views execute with the permissions of the view owner, not the querying user. If the view owner lacks SELECT on the underlying table, the view cannot access the data, resulting in a permission error for any user. The analyst's privileges on the view are sufficient, but the owner must have the necessary privileges on the base table.

Exam trap

The trap here is assuming that the querying user needs direct privileges on the base table, when in fact the view owner's privileges are what matter.

20
MCQeasy

A data analyst needs to grant a team member the ability to view the metadata of a table `main.finance.transactions` in Unity Catalog, but not query the data. Which privilege should the analyst grant?

A.`BROWSE`
B.`MODIFY`
C.`SELECT`
D.`USAGE`
AnswerA

`BROWSE` allows a user to view an object's metadata, such as its schema and properties, without granting access to the underlying data. This matches the requirement to view metadata only. It is a relatively new privilege in Unity Catalog designed for discovery without data access. Granting `BROWSE` on the table or its parent catalog/schema enables the team member to see the table in the UI and describe it.

Why this answer

The `BROWSE` privilege in Unity Catalog is specifically designed to allow users to discover and view metadata of objects without accessing the data. Granting `BROWSE` on the table or its parent objects satisfies the requirement. Other privileges like `SELECT`, `USAGE`, or `MODIFY` either grant data access or are insufficient for metadata visibility.

Exam trap

The trap here is assuming that `USAGE` on a schema grants metadata visibility on tables, when in fact `BROWSE` is the privilege that allows viewing metadata without data access.

21
MCQeasy

What is the purpose of the 'Account Admin' role in Databricks?

A.To manage SQL queries for a specific user.
B.To configure metastores, identities, and settings.
C.To monitor the performance of all SQL Warehouses.
D.To create tables in the metastore.
AnswerB

Account Admins are responsible for the highest-level configuration tasks, such as creating and managing Unity Catalog metastores, provisioning users via SCIM, and defining global security settings. They act as the governance leads who establish the environment's security perimeter, ensuring that all workspaces and catalogs comply with organizational security and operational requirements.

Why this answer

The Account Admin role is the highest level of privilege in Databricks, providing control over the entire account including metastore creation, user provisioning, and billing. This role is responsible for the foundational security configuration of the environment. Because of its power, this role should be restricted to a very small number of individuals to prevent unauthorized changes to security or governance policies.

Exam trap

Candidates confuse the Account Admin role with Workspace Admins or metastore-specific owners, missing the global scope of account-level configurations.

22
MCQeasy

Which identity management approach is required to utilize Unity Catalog for centralized governance across multiple Databricks workspaces?

A.Local workspace-level user management.
B.Account-level identity provisioning using SCIM.
C.Database-level authentication via JDBC drivers.
D.Private Link connectivity for all users.
AnswerB

SCIM provisioning at the account level ensures that identities are synchronized from your identity provider directly to the Databricks account. This is the prerequisite for Unity Catalog because it provides a unified identity namespace, allowing for consistent access control policies across all connected workspaces and catalogs within the metastore.

Why this answer

Unity Catalog requires that all users and groups are managed at the account level rather than individual workspace levels. By using an Account-level metastore, Databricks ensures a single source of truth for identities and permissions. This centralized model simplifies auditing, security, and data sharing, as permissions propagate consistently across all workspaces linked to that specific metastore.

Exam trap

Candidates frequently confuse local workspace-level user management with the account-level SCIM provisioning required for Unity Catalog governance.

23
MCQeasy

A data analyst needs to grant a colleague read access to a specific table named 'quarterly_sales' within Unity Catalog without exposing other tables in the same schema. Which SQL command should the analyst execute?

A.GRANT SELECT ON TABLE quarterly_sales TO `colleague@company.com`;
B.GRANT ALL PRIVILEGES ON SCHEMA sales_schema TO `colleague@company.com`;
C.GRANT READ ACCESS ON CATALOG main TO `colleague@company.com`;
D.GRANT USE TABLE ON quarterly_sales TO `colleague@company.com`;
AnswerA

Granting the SELECT privilege directly on a specific table provides precise access control. This ensures the recipient can query only the targeted dataset while adhering strictly to the principle of least privilege across the schema.

Why this answer

Granting granular access in Unity Catalog is performed using standard SQL GRANT syntax. To allow a user to read data from a specific table, the SELECT privilege must be granted directly on that table securable object while ensuring parent container traversal permissions are present.

Exam trap

Candidates often confuse object-level privileges with administrative commands or forget that parent containers like schemas and catalogs require traversal permissions (USAGE) in addition to the table-level SELECT privilege.

24
MCQmedium

A data analyst in the 'marketing' group needs to query the table `main.sales.leads` but should not be able to read the underlying data files directly. The analyst currently has `SELECT` on the table and `READ FILES` on the external location where the table's data resides. Which Unity Catalog privilege should the analyst's `READ FILES` on the external location be removed to enforce least privilege?

A.`SELECT` on the table
B.`BROWSE` on the catalog `main`
C.`READ FILES` on the external location
D.`USAGE` on the schema `main.sales`
AnswerC

Removing `READ FILES` on the external location prevents the analyst from bypassing Unity Catalog table-level controls and reading raw data files directly. The analyst retains `SELECT` on the table, so querying through SQL or DataFrames continues to work. This enforces least privilege because file-level access is no longer needed for the analyst's role, and Unity Catalog manages access at the table level.

Why this answer

To enforce least privilege, the analyst should not have direct file access when table-level access suffices. `READ FILES` on the external location allows bypassing Unity Catalog table permissions, so it must be removed. `SELECT` on the table remains to allow querying, while `USAGE` on the schema and `BROWSE` on the catalog are unrelated to file-level reads.

Exam trap

The trap here is assuming that `READ FILES` is required for querying a table, when in fact `SELECT` on the table is sufficient and `READ FILES` only grants direct file access.

Ready to test yourself?

Try a timed practice session using only Securing Data questions.