Courseiva

Databricks-DA-Assoc · topic practice

Securing Data practice questions

This domain covers how Databricks data analysts work with Unity Catalog security: privileges, dynamic views, row-level and column-level controls, and identity management across workspaces. Questions present concrete scenarios—querying a protected view, granting table access, restricting sensitive columns—and ask you to choose the correct SQL, privilege, or governance approach.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Securing Data

What the exam tests

What to know about Securing Data

Be able to write GRANT and REVOKE statements at the right Unity Catalog object level, and explain how dynamic views enforce row filters and column masks for users who lack direct table access. The key is granting least privilege on the exact object, not a broader container.

Unity Catalog privilege model: GRANT SELECT on tables, views, schemas, and catalogs

Dynamic views enforcing row-level security and column masking for analysts

Account-level identity management required for cross-workspace Unity Catalog governance

Column-level restrictions using GRANT/REVOKE and dynamic view masking functions

Watch out for

Common Securing Data exam traps

  • ▸Assuming SELECT on a dynamic view also requires SELECT on the underlying table; view owner privileges handle that
  • ▸Granting access at schema or catalog level when the question asks for one specific table only
  • ▸Confusing workspace-local metastore identity with account-level identity needed for centralized Unity Catalog governance

Practice set

Securing Data questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Securing Data explanation →

A data analyst needs to share a sensitive customer table with the marketing team in Databricks. The marketing team should only see customer records where the country is United States, and they must never see the credit_card column. Which Unity Catalog feature should be configured to meet both of these governance requirements simultaneously?

Question 2mediummultiple choice
Read the full Securing Data explanation →

A data analyst needs to share a sensitive table containing personally identifiable information (PII) with a regional team. The team should only see rows belonging to their specific region and must have the email column completely masked. Which combination of Unity Catalog features should be implemented?

A security administrator is configuring access control for a new Unity Catalog catalog containing financial reports. Which TWO actions can be performed by a user who has been granted the USE CATALOG privilege on this catalog? (Choose two.)

Question 4mediummultiple choice
Read the full Securing Data explanation →

A data analyst needs to grant a marketing user access to a specific table in Unity Catalog while ensuring they cannot see sensitive PII columns. Which Unity Catalog feature should the analyst implement?

Question 5hardmultiple choice
Read the full Securing Data explanation →

Refer to the exhibit. A user in the 'finance_team' reports they cannot see the 'main.sales.revenue' table in the Data Explorer UI. What is the most likely cause?

Exhibit

GRANT USAGE ON CATALOG main TO `finance_team`;
GRANT USAGE ON SCHEMA main.sales TO `finance_team`;
GRANT SELECT ON TABLE main.sales.revenue TO `finance_team`;
GRANT SELECT ON TABLE main.sales.cost TO `finance_team`;
Question 6mediummultiple choice
Read the full Securing Data explanation →

An enterprise data analytics team needs to grant a junior data analyst the ability to view rows in a customer table where the region column matches the analyst's assigned territory, without giving them permission to see rows from other regions. Which Unity Catalog feature should the data analyst administer to achieve this row-level security requirement?

Question 7hardmultiple choice
Read the full Securing Data explanation →

A security administrator is preparing to share sensitive customer data across different Databricks accounts using Delta Sharing. The administrator wants to ensure that specific personally identifiable information columns are completely hidden from the recipient without creating a separate filtered copy of the Delta table. Which approach fulfills this requirement efficiently?

Question 8mediummultiple choice
Read the full Securing Data explanation →

A data analyst at a healthcare company needs to give a team of nurses read access to a single column named 'patient_id' in the Unity Catalog table 'main.clinical.patients', while preventing them from seeing any other columns. The nurses already have USE CATALOG on 'main' and USE SCHEMA on 'clinical'. Which Unity Catalog privilege should the analyst grant to the nurses on the table?

A data analyst needs to share a sensitive table with a group of users in Unity Catalog. The users should only be able to see aggregated results, not individual rows. Which TWO actions should the analyst take to achieve this? (Choose two.)

A data analyst at a retail company needs to share a Unity Catalog table 'main.sales.transactions' with an external partner using Delta Sharing. The partner should be able to query the table but must not be able to see the 'credit_card_number' column. The analyst wants to create a share and add the table. Which TWO actions should the analyst take to meet these requirements? (Choose two.)

Question 11mediummultiple choice
Read the full Securing Data explanation →

A data analyst is working with a table that contains sensitive data and wants to ensure that only users from the 'finance' group can query it. The analyst decides to use Unity Catalog privileges. Which approach is most appropriate?

Question 12mediummulti select
Read the full Securing Data explanation →

A data analyst is configuring access control for a new Unity Catalog schema that will contain sensitive HR data. The analyst wants to ensure that only members of the `hr_team` group can query tables in the schema, and that they can also create new tables. Which two privileges should the analyst grant to the `hr_team` group on the schema? (Choose two.)

A data analyst is configuring dynamic view functions to enforce row-level security on a table `main.hr.employees`. The analyst wants to ensure that users in the 'hr_admins' group can see all rows, while other users can see only rows where `department` matches their group membership. Which TWO steps are required to implement this with Unity Catalog? (Choose two.)

Question 14mediummultiple choice
Read the full Securing Data explanation →

A data analyst is reviewing audit logs in Unity Catalog to investigate unauthorized access attempts to a sensitive table. Which audit log event should the analyst look for to identify failed attempts to read data from the table?

Question 15mediummultiple choice
Read the full Securing Data explanation →

A data analyst is preparing a Unity Catalog managed table that stores raw clickstream events. The security team requires that analysts who query this table must never see the raw IP address values, but the table must still be readable for aggregation. The analyst decides to use a column mask on the ip_address column. Which Unity Catalog privilege must the analyst hold to apply this column mask so that unauthorized users see a masked value instead of the real one?

Question 16mediummultiple choice
Read the full Securing Data explanation →

A data analyst needs to share a sensitive sales table with the marketing team in Databricks. The marketing team should only see rows where the region column matches 'North America' and should not have access to the credit_card column. Which Unity Catalog feature should the data analyst implement?

Question 17easymultiple choice
Read the full Securing Data explanation →

A data analyst needs to grant a colleague read access to a specific table named 'quarterly_sales' within Unity Catalog without exposing other tables in the same schema. Which SQL command should the analyst execute?

Question 18easymultiple choice
Read the full Securing Data explanation →

Which identity management approach is required to utilize Unity Catalog for centralized governance across multiple Databricks workspaces?

Question 19mediummultiple choice
Read the full Securing Data explanation →

An administrator needs to secure a table containing sensitive customer data. Which TWO options represent valid ways to restrict access using Unity Catalog?

Question 20mediummultiple choice
Read the full Securing Data explanation →

What is the primary function of a Storage Credential in Unity Catalog?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Securing Data sessions

Start a Securing Data only practice session

Every question in these sessions is drawn from the Securing Data domain — nothing else.

Related practice questions

Related Databricks-DA-Assoc topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Databricks-DA-Assoc exam test about Securing Data?
Be able to write GRANT and REVOKE statements at the right Unity Catalog object level, and explain how dynamic views enforce row filters and column masks for users who lack direct table access. The key is granting least privilege on the exact object, not a broader container.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Securing Data questions in a focused session?
Yes — the session launcher on this page draws every question from the Securing Data domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Databricks-DA-Assoc topics?
Use the topic links above to move to related areas, or go back to the Databricks-DA-Assoc question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Databricks-DA-Assoc exam covers. They are not copied from any real exam or dump site.