Databricks-DE-Assoc Governance and Security Practice Question
A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The S3 bucket policy grants access to an IAM role. The data engineer creates a storage credential with that IAM role's ARN. However, when attempting to create an external location using this storage credential, the operation fails with an error indicating insufficient permissions. The data engineer verifies that the IAM role has the correct S3 permissions. What is the most likely cause of the failure?
⚠ Common exam trap
The trap here is focusing on S3 bucket permissions or Unity Catalog privileges while overlooking the IAM trust relationship required for role assumption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM role's trust policy does not allow the Databricks AWS account to assume the role.
When creating a storage credential, Databricks must be able to assume the IAM role. This requires a trust relationship between the IAM role and the Databricks AWS account. Even if the role has correct S3 permissions, without a proper trust policy, Databricks cannot assume the role, causing external location creation to fail. The trust policy is a separate configuration from permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The S3 bucket policy does not grant the necessary permissions to the IAM role.
Why it's wrong here
The scenario states that the data engineer verified the IAM role has the correct S3 permissions, implying the bucket policy is likely correct. While bucket policy issues could cause failures, the most likely cause given the verification is a trust policy problem. The trust policy allows Databricks to assume the role, which is separate from S3 permissions.
- ✗
The storage credential was created without the `READ FILES` privilege on the S3 bucket.
Why it's wrong here
`READ FILES` is a Unity Catalog privilege granted on external locations or storage credentials, not on S3 buckets directly. The failure occurs during external location creation, before any file access. The issue is with the underlying IAM role assumption, not with Unity Catalog file privileges.
- ✗
The storage credential was created without the `CREATE EXTERNAL LOCATION` privilege on the metastore.
Why it's wrong here
The `CREATE EXTERNAL LOCATION` privilege is required on the metastore, but the error indicates insufficient permissions when creating the external location. However, the data engineer likely already has this privilege if they are attempting the operation. The error is more specific to the storage credential's ability to assume the IAM role, not the metastore privilege.
- ✓
The IAM role's trust policy does not allow the Databricks AWS account to assume the role.
Why this is correct
For Databricks to use the IAM role specified in the storage credential, the role's trust policy must allow the Databricks AWS account (or the Unity Catalog service principal) to assume it. If the trust policy is missing or incorrect, Databricks cannot assume the role, leading to insufficient permissions when creating the external location. This is a common misconfiguration.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.