Databricks-DE-Assoc Governance and Security Practice Question
A data engineer has a Unity Catalog table `prod.sales.orders` containing a column `customer_email`. Company policy requires that users in the `analyst_group` see only the domain part of the email (e.g., `***@example.com`), while members of `pii_admin_group` must see the full email. The engineer wants to enforce this at query time without creating separate views. Which approach should the engineer use?
⚠ Common exam trap
Candidates often confuse row-level filtering with column-level masking, when the requirement is specifically to obscure a column value rather than hide rows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a column mask function that returns the full email for `pii_admin_group` and a masked email otherwise, then apply it to the `customer_email` column.
Column masks in Unity Catalog let you attach a user-defined function to a specific column so that different users see different values for the same data. The function can inspect `is_account_group_member()` to return the raw email for the privileged group and a masked string for everyone else. This enforces the policy dynamically at query time and avoids creating separate views or duplicating the table.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a table-level tag `pii` to `prod.sales.orders` and configure a tag-based policy that automatically masks all string columns for non-admin users.
Why it's wrong here
Tag-based policies in Unity Catalog can drive attribute-based access control, but they do not automatically mask every string column. A tag alone does not transform values; you still need an explicit column mask function attached to the column, so this option would not produce the required email masking.
- ✗
Grant `SELECT` on `prod.sales.orders` only to `pii_admin_group` and grant `SELECT` on a view that excludes `customer_email` to `analyst_group`.
Why it's wrong here
This approach requires creating and maintaining a separate view, which the engineer explicitly wants to avoid. It also removes the email domain entirely for analysts rather than showing the masked domain, so it does not meet the stated requirement of displaying `***@example.com` to the analyst group.
- ✗
Create a row filter function that returns TRUE for `pii_admin_group` and FALSE for others, then apply it to `prod.sales.orders`.
Why it's wrong here
Row filters control which rows are visible, not which column values are shown. Applying a row filter here would either hide entire rows or expose full emails, failing the requirement to mask only the email column for non-admin users. Column-level masking requires a column mask function, not a row filter.
- ✓
Create a column mask function that returns the full email for `pii_admin_group` and a masked email otherwise, then apply it to the `customer_email` column.
Why this is correct
Column masks in Unity Catalog evaluate the current user's group membership at query time and return a transformed value per row. Applying a mask function to `customer_email` lets `pii_admin_group` see the raw value while others receive the masked domain-only output, satisfying the policy without duplicating the table.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.