Databricks-DE-Assoc Governance and Security Practice Question
A data engineer has a Unity Catalog table named `sales.raw.orders` that contains a column `credit_card` with sensitive data. The security team requires that users in the `analyst` group see only the last four digits of the credit card number when querying this table, while all other users with appropriate privileges see the full value. The data engineer wants to implement this with minimal disruption to existing queries. Which approach should the data engineer take?
⚠ Common exam trap
A common mix-up: candidates confuse column masks with row filters, or assuming that a view is required to implement dynamic masking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a column mask function to the `credit_card` column that checks if the user is in the `analyst` group and, if so, returns only the last four digits.
Unity Catalog column masks allow dynamic data masking at query time without altering the underlying data or requiring separate views. A mask function can evaluate the current user's group memberships and return a transformed value, such as the last four digits. This meets the security requirement while preserving existing queries and access patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a column mask function with Unity Catalog to apply row-level filtering based on the user's group membership.
Why it's wrong here
Column masks are applied to columns, not rows. Row-level filtering is achieved with row filters, not column masks. The scenario requires masking the credit card column, not filtering rows. Using a column mask function is correct, but the description mentions row-level filtering, which is incorrect for this use case.
- ✗
Create a row filter on the table that restricts analysts to rows where the credit card number ends with certain digits, and grant them access to the table.
Why it's wrong here
Row filters restrict which rows are returned based on a condition, not which columns or values are visible. This would not mask the credit card column for analysts; it would hide entire rows, which is not the requirement. Additionally, it does not provide partial masking of the column value.
- ✓
Apply a column mask function to the `credit_card` column that checks if the user is in the `analyst` group and, if so, returns only the last four digits.
Why this is correct
Unity Catalog supports column masks, which are functions that transform column values at query time based on the invoking user's identity. By applying a mask that checks group membership, analysts see masked data while others see full values. This satisfies the requirement without changing existing queries or table references.
- ✗
Create a dynamic view that applies a masking function to the `credit_card` column, and grant the `analyst` group access to the view instead of the table.
Why it's wrong here
A dynamic view can mask data, but it requires redirecting all queries to the view and managing separate grants. This disrupts existing queries that reference the table directly, and it does not automatically apply to users based on group membership without additional logic. The requirement is to minimize disruption, so this approach is not optimal.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.