Courseiva
Governance and Security →mediumMultiple Choice

Databricks-DE-Assoc Governance and Security Practice Question

A data engineer is configuring a storage credential in Unity Catalog to access an AWS S3 bucket. The engineer creates an IAM role with the necessary permissions and sets up the storage credential using the role ARN. What additional step is required to allow Databricks to assume the role?

⚠ Common exam trap

The trap here is thinking that permissions policies on the role are sufficient, when actually the trust relationship is what allows Databricks to assume the role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the role's trust policy to allow the Databricks AWS account to assume it.

For Databricks to assume an IAM role, the role's trust policy must explicitly allow the Databricks AWS account to assume it. This is a critical step in setting up a storage credential. The trust policy defines which principals can assume the role, and without it, the assumption fails regardless of the role's permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS IAM Identity Center and configure SAML federation for the role.

    Why it's wrong here

    AWS IAM Identity Center and SAML federation are used for human user authentication, not for service-to-service access like Databricks assuming a role to access S3. This option confuses identity federation for users with role assumption for services. It is not required and would not enable the storage credential to work.

  • ✗

    Create an access key and secret key for the IAM role and store them in Databricks secrets.

    Why it's wrong here

    Using access keys and secrets is not recommended for Unity Catalog storage credentials. Unity Catalog uses IAM role assumption for secure, keyless access. Storing long-term credentials in secrets is less secure and not the intended method. This option introduces unnecessary security risks and does not follow best practices.

  • ✗

    Attach an IAM policy to the role that grants sts:AssumeRole to the Databricks AWS account.

    Why it's wrong here

    Attaching an IAM policy to the role that grants sts:AssumeRole to the Databricks AWS account is not the correct approach. The trust relationship is configured on the role itself, not via an identity-based policy. The Databricks AWS account needs to be allowed to assume the role through the role's trust policy. This option misplaces the permission.

  • ✓

    Modify the role's trust policy to allow the Databricks AWS account to assume it.

    Why this is correct

    To allow Databricks to assume the IAM role, the role's trust policy must include a principal for the Databricks AWS account (or the specific Databricks IAM role) and grant sts:AssumeRole. This establishes the trust relationship. Without this, Databricks cannot assume the role even if the role has the correct permissions to access S3.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every Databricks-DE-Assoc question from scratch — 276 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.