Databricks-DE-Assoc Governance and Security Practice Question
A data engineer has a Unity Catalog table `prod.sales.orders` that contains a column `customer_email`. They need to allow analysts in the `marketing` group to query the table but only see a masked version of `customer_email` (e.g., `a***@example.com`). The masking logic is implemented as a SQL user-defined function `prod.security.mask_email`. Which statement should the engineer execute to apply the mask?
⚠ Common exam trap
The trap here is assuming that masking can be granted via GRANT or set as a table property, rather than using the dedicated ALTER COLUMN ... SET MASK command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ALTER TABLE prod.sales.orders ALTER COLUMN customer_email SET MASK prod.security.mask_email;
Unity Catalog column masks are applied using ALTER TABLE ... ALTER COLUMN ... SET MASK <function>. This associates a user-defined function with the column. Users without the UNMASK privilege automatically see the function's output, while privileged users see raw data. The other options either use invalid syntax or fail to enforce masking at the column level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ALTER TABLE prod.sales.orders ALTER COLUMN customer_email SET MASK prod.security.mask_email;
Why this is correct
This is the correct syntax to apply a column mask function in Unity Catalog. The ALTER TABLE ... ALTER COLUMN ... SET MASK command associates the masking UDF with the column. When users without UNMASK privilege query the table, the function is applied to the column value, returning the masked result. Users with UNMASK privilege see the original data.
- ✗
CREATE VIEW prod.sales.orders_masked AS SELECT customer_email, prod.security.mask_email(customer_email) AS customer_email FROM prod.sales.orders;
Why it's wrong here
Creating a view with the mask function applied manually would expose the original column and require granting access to the view instead of the table. It does not use Unity Catalog's column mask feature, so users could still query the base table if granted access. It also duplicates logic and does not dynamically apply masking based on privileges.
- ✗
ALTER TABLE prod.sales.orders SET TBLPROPERTIES ('mask.customer_email' = 'prod.security.mask_email');
Why it's wrong here
Table properties are used for metadata and configuration but do not enforce column-level security. There is no built-in property named 'mask.customer_email' that applies a masking function. Unity Catalog column masks must be applied via the ALTER COLUMN ... SET MASK syntax, so this approach would not mask any data.
- ✗
GRANT SELECT ON TABLE prod.sales.orders TO `marketing` WITH MASK prod.security.mask_email ON customer_email;
Why it's wrong here
GRANT does not support a WITH MASK clause. Column masking is configured via ALTER TABLE ... ALTER COLUMN ... SET MASK, not through GRANT. This statement would fail with a syntax error. Granting SELECT with a mask is not a valid Unity Catalog privilege syntax, so it cannot achieve the required masking behavior.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.