Databricks-DA-Assoc Securing Data Practice Question
Which identity management approach is required to utilize Unity Catalog for centralized governance across multiple Databricks workspaces?
⚠ Common exam trap
Candidates frequently confuse local workspace-level user management with the account-level SCIM provisioning required for Unity Catalog governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Account-level identity provisioning using SCIM.
Unity Catalog requires that all users and groups are managed at the account level rather than individual workspace levels. By using an Account-level metastore, Databricks ensures a single source of truth for identities and permissions. This centralized model simplifies auditing, security, and data sharing, as permissions propagate consistently across all workspaces linked to that specific metastore.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local workspace-level user management.
Why it's wrong here
Local workspace-level management creates fragmented identities that are incompatible with Unity Catalog's centralized governance model. Relying on local users prevents the effective application of consistent security policies across multiple workspaces, as identity mappings would not be synchronized or recognized by the global Unity Catalog metastore configuration.
- ✓
Account-level identity provisioning using SCIM.
Why this is correct
SCIM provisioning at the account level ensures that identities are synchronized from your identity provider directly to the Databricks account. This is the prerequisite for Unity Catalog because it provides a unified identity namespace, allowing for consistent access control policies across all connected workspaces and catalogs within the metastore.
- ✗
Database-level authentication via JDBC drivers.
Why it's wrong here
JDBC authentication is a legacy method for connecting external tools to Databricks clusters and does not manage internal user identities. Unity Catalog relies on the Databricks platform's internal identity model, which is managed via Account Console or SCIM, not through database connection strings or traditional external database authentication protocols.
- ✗
Private Link connectivity for all users.
Why it's wrong here
Private Link handles network security and traffic isolation between your VPC and Databricks. While important for enterprise networking, it does not define or manage the identity lifecycle required for Unity Catalog. You can have Private Link without Unity Catalog, and you need account-level identities regardless of network configuration.
About these practice questions
One of 291 original Databricks-DA-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.