Databricks-DE-Assoc Governance and Security Practice Question
A data engineer is configuring Unity Catalog governance for a multi-department organization. Which TWO actions require the metastore admin or catalog owner to have a workspace-independent metastore assigned? (Choose TWO)
⚠ Common exam trap
Test-takers frequently assume routine table-level operations or basic user grants require a metastore-level scope, confusing everyday data engineering tasks with account-level administrative actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binding a workspace to a Unity Catalog metastore to enable catalog-level data access.
A Unity Catalog metastore is the top-level container for metadata, governing three levels of namespacing (catalog, schema, table). Certain administrative tasks like assigning a metastore to workspaces or managing root storage locations require specific privileges and architectural scopes, ensuring centralized security governance across multiple workspaces.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Creating a new catalog inside the Unity Catalog metastore.
Why it's wrong here
Metastore admins or users granted CREATE CATALOG privileges can create catalogs within an active metastore directly from any attached workspace. This operation does not require workspace-independent configuration changes since the metastore is already provisioned and linked.
- ✓
Binding a workspace to a Unity Catalog metastore to enable catalog-level data access.
Why this is correct
Workspace binding enforces security isolation by mapping specific workspaces to a Unity Catalog metastore. This administrative configuration ensures that data assets governed by the metastore are only accessible through authorized workspaces, requiring proper metastore administration.
- ✗
Granting the SELECT privilege on a specific schema to a group of data analysts.
Why it's wrong here
Granting data privileges such as SELECT on schemas or tables is a routine data governance task performed by catalog or schema owners using standard SQL GRANT statements. It does not require metastore-level architectural binding or workspace-independent setup.
- ✓
Configuring the root storage location for the metastore using a secure cloud storage container.
Why this is correct
Defining the root storage location establishes the foundational storage layer for managed tables within the metastore. This critical setup requires high-level administrative permissions and infrastructure provisioning before any workspace users can interact with managed data.
- ✗
Defining a custom dynamic view with column-level masking functions for auditing.
Why it's wrong here
Creating dynamic views with masking functions relies on standard SQL capabilities and row/column security features available to table owners. It operates within existing catalog schemas and does not involve metastore-level workspace binding or administrative provisioning.
About these practice questions
This Databricks-DE-Assoc question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.