A data analyst needs to share a sensitive customer table with the marketing team in Databricks. The marketing team should only see customer records where the country is United States, and they must never see the credit_card column. Which Unity Catalog feature should be configured to meet both of these governance requirements simultaneously?
Trap 1: Create a standard SQL view that filters rows and omits the…
Creating separate views introduces data proliferation and maintenance overhead. Users can often bypass views if they retain direct SELECT privileges on the underlying base table, making this approach unreliable for strict enterprise security compliance and auditing.
Trap 2: Configure a table-level access control list (ACL) to restrict the…
Table-level ACLs in Unity Catalog only permit granting or revoking privileges on entire tables or schemas. They do not support column-level restrictions or row-level filtering natively without the use of specialized masking functions.
Trap 3: Set up table access properties in the Hive metastore using…
The legacy Hive metastore lacks native, dynamic column masking and row filtering capabilities. Relying on the legacy metastore for modern governance is discouraged and fails to provide secure, centralized auditing across workspaces.
- A
Create a standard SQL view that filters rows and omits the sensitive column, then grant access to the view.
Why it fails: Creating separate views introduces data proliferation and maintenance overhead. Users can often bypass views if they retain direct SELECT privileges on the underlying base table, making this approach unreliable for strict enterprise security compliance and auditing.
- B
Apply a dynamic row filter function for the country column and a column masking function for the credit_card column on the base table.
Unity Catalog enables simultaneous row-level filtering and column-level masking directly on the base table using custom SQL functions. This approach preserves data lineage, avoids table duplication, and securely enforces access policies across all downstream queries and BI tools.
- C
Configure a table-level access control list (ACL) to restrict the marketing team from querying the credit_card column directly.
Why it fails: Table-level ACLs in Unity Catalog only permit granting or revoking privileges on entire tables or schemas. They do not support column-level restrictions or row-level filtering natively without the use of specialized masking functions.
- D
Set up table access properties in the Hive metastore using traditional GRANT and REVOKE statements for column security.
Why it fails: The legacy Hive metastore lacks native, dynamic column masking and row filtering capabilities. Relying on the legacy metastore for modern governance is discouraged and fails to provide secure, centralized auditing across workspaces.