Courseiva
Governance and Security →hardMultiple Choice

Databricks-DE-Assoc Governance and Security Practice Question

A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The S3 bucket policy grants access to an IAM role. The data engineer creates a storage credential with that IAM role's ARN. However, when attempting to create an external location using this storage credential, the operation fails with an error indicating insufficient permissions. The data engineer verifies that the IAM role has the correct S3 permissions. What is the most likely cause of the failure?

⚠ Common exam trap

The trap here is focusing on S3 bucket permissions or Unity Catalog privileges while overlooking the IAM trust relationship required for role assumption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM role's trust policy does not allow the Databricks AWS account to assume the role.

When creating a storage credential, Databricks must be able to assume the IAM role. This requires a trust relationship between the IAM role and the Databricks AWS account. Even if the role has correct S3 permissions, without a proper trust policy, Databricks cannot assume the role, causing external location creation to fail. The trust policy is a separate configuration from permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The S3 bucket policy does not grant the necessary permissions to the IAM role.

    Why it's wrong here

    The scenario states that the data engineer verified the IAM role has the correct S3 permissions, implying the bucket policy is likely correct. While bucket policy issues could cause failures, the most likely cause given the verification is a trust policy problem. The trust policy allows Databricks to assume the role, which is separate from S3 permissions.

  • ✗

    The storage credential was created without the `READ FILES` privilege on the S3 bucket.

    Why it's wrong here

    `READ FILES` is a Unity Catalog privilege granted on external locations or storage credentials, not on S3 buckets directly. The failure occurs during external location creation, before any file access. The issue is with the underlying IAM role assumption, not with Unity Catalog file privileges.

  • ✗

    The storage credential was created without the `CREATE EXTERNAL LOCATION` privilege on the metastore.

    Why it's wrong here

    The `CREATE EXTERNAL LOCATION` privilege is required on the metastore, but the error indicates insufficient permissions when creating the external location. However, the data engineer likely already has this privilege if they are attempting the operation. The error is more specific to the storage credential's ability to assume the IAM role, not the metastore privilege.

  • ✓

    The IAM role's trust policy does not allow the Databricks AWS account to assume the role.

    Why this is correct

    For Databricks to use the IAM role specified in the storage credential, the role's trust policy must allow the Databricks AWS account (or the Unity Catalog service principal) to assume it. If the trust policy is missing or incorrect, Databricks cannot assume the role, leading to insufficient permissions when creating the external location. This is a common misconfiguration.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.