Databricks-DA-Assoc Developing AI/BI Genie Spaces Practice Question
You are auditing access to several AI/BI Genie Spaces. You discover that a group of users can ask questions but cannot see the underlying source tables in the Catalog Explorer. Is this a functional issue?
⚠ Common exam trap
Candidates frequently assume that users must have direct SELECT permissions on underlying tables to successfully query them through a Genie space, confusing direct and indirect access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No, this is a secure configuration that follows the principle of least privilege.
This is expected behavior and a sound security practice. Genie acts as an intermediary; users do not need to be able to browse or query the source tables directly to use the Genie interface. By decoupling the interface from direct data access, you simplify the user experience and maintain stricter control over how data is accessed, preventing users from bypassing the Genie's curated, secure environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Yes, users must have direct access to source tables to use Genie.
Why it's wrong here
Users do not require direct access to source tables. The Genie Space handles the interaction with the data through its own service identity or via the user's effective permissions. Requiring direct access would violate the principle of least privilege and expose internal data structures that users do not need to see.
- ✓
No, this is a secure configuration that follows the principle of least privilege.
Why this is correct
The current configuration is optimal. By granting access to the Genie Space but not the raw catalog objects, you ensure users can gain insights without exposing the underlying data architecture. This limits the attack surface and prevents users from running ad-hoc, potentially inefficient queries directly against the source tables.
- ✗
No, but it will prevent the Genie from generating any results.
Why it's wrong here
Genie is designed to function even when the user lacks direct browse access to the underlying catalog objects. The model executes queries within the context of the Genie Space, which is granted the necessary permissions to access the required data, allowing the user to get answers without direct exposure.
- ✗
Yes, the users will be unable to run any queries through Genie.
Why it's wrong here
The Genie engine has its own permission context. Provided the Space itself is configured to allow access to the tables, the user will be able to query them via the chat interface. Requiring the user to have direct table access is not a prerequisite for the Genie to generate valid SQL.
About these practice questions
One of 291 original Databricks-DA-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.