Courseiva
Governance and Security →hardMultiple Choice

Databricks-DE-Assoc Governance and Security Practice Question

A data engineer has configured a storage credential in Unity Catalog to access an AWS S3 bucket. The credential uses an IAM role with a trust policy that allows Databricks to assume it. The engineer now needs to ensure that only a specific set of users can create external tables pointing to that S3 bucket. Which Unity Catalog object should be used to control this access?

⚠ Common exam trap

Watch out — candidates often confuse the storage credential, which authenticates to storage, with the external location, which governs user access to storage paths for table creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

External location

An external location in Unity Catalog associates a cloud storage path with a storage credential. By granting privileges on the external location, administrators control which users can create external tables that reference that path. This provides the necessary granularity to restrict table creation to a specific set of users for a given S3 bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Catalog

    Why it's wrong here

    A catalog is a logical container for schemas and tables. While you can grant privileges on a catalog, it does not directly govern access to external storage paths. To create an external table, the user needs privileges on the external location that maps to the storage path, not just on a catalog. Granting catalog-level privileges would not restrict which S3 paths can be used for external tables.

  • ✗

    Metastore

    Why it's wrong here

    The metastore is the top-level container for Unity Catalog objects. While it holds storage credentials and external locations, it does not directly control user permissions for creating external tables. Granting privileges at the metastore level would be too broad and would not meet the requirement of restricting access to a specific S3 bucket. The metastore is not the appropriate granularity for this control.

  • ✓

    External location

    Why this is correct

    An external location in Unity Catalog combines a storage path with a storage credential. By granting privileges on an external location, you control which users can create external tables that reference that path. This is the correct object to restrict table creation to specific users. The engineer should create an external location for the S3 bucket and grant CREATE EXTERNAL TABLE or other relevant privileges to the desired users.

  • ✗

    Storage credential

    Why it's wrong here

    A storage credential encapsulates the IAM role and trust relationship for accessing cloud storage. It is used by Unity Catalog to authenticate to the storage, but it does not control which users can create external tables. Access to the storage credential itself is managed via privileges, but the credential alone does not restrict table creation. The engineer needs a separate object to define the storage location and grant usage.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every Databricks-DE-Assoc question from scratch — 276 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.