Databricks-DE-Assoc Governance and Security Practice Question
A data engineer has configured a storage credential in Unity Catalog to access an AWS S3 bucket. The credential uses an IAM role with a trust policy that allows Databricks to assume it. The engineer now needs to ensure that only a specific set of users can create external tables pointing to that S3 bucket. Which Unity Catalog object should be used to control this access?
⚠ Common exam trap
Watch out — candidates often confuse the storage credential, which authenticates to storage, with the external location, which governs user access to storage paths for table creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External location
An external location in Unity Catalog associates a cloud storage path with a storage credential. By granting privileges on the external location, administrators control which users can create external tables that reference that path. This provides the necessary granularity to restrict table creation to a specific set of users for a given S3 bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Catalog
Why it's wrong here
A catalog is a logical container for schemas and tables. While you can grant privileges on a catalog, it does not directly govern access to external storage paths. To create an external table, the user needs privileges on the external location that maps to the storage path, not just on a catalog. Granting catalog-level privileges would not restrict which S3 paths can be used for external tables.
- ✗
Metastore
Why it's wrong here
The metastore is the top-level container for Unity Catalog objects. While it holds storage credentials and external locations, it does not directly control user permissions for creating external tables. Granting privileges at the metastore level would be too broad and would not meet the requirement of restricting access to a specific S3 bucket. The metastore is not the appropriate granularity for this control.
- ✓
External location
Why this is correct
An external location in Unity Catalog combines a storage path with a storage credential. By granting privileges on an external location, you control which users can create external tables that reference that path. This is the correct object to restrict table creation to specific users. The engineer should create an external location for the S3 bucket and grant CREATE EXTERNAL TABLE or other relevant privileges to the desired users.
- ✗
Storage credential
Why it's wrong here
A storage credential encapsulates the IAM role and trust relationship for accessing cloud storage. It is used by Unity Catalog to authenticate to the storage, but it does not control which users can create external tables. Access to the storage credential itself is managed via privileges, but the credential alone does not restrict table creation. The engineer needs a separate object to define the storage location and grant usage.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every Databricks-DE-Assoc question from scratch — 276 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.