Courseiva
Governance and Security →hardMultiple Select

Databricks-DE-Assoc Governance and Security Practice Question

A data engineer is configuring Unity Catalog row-level security on a table `prod.finance.transactions`. They want to ensure that users in the `us_team` group can only see rows where `region = 'US'`, while users in the `eu_team` group can only see rows where `region = 'EU'`. They create a row filter function `prod.security.region_filter`. Which TWO statements accurately describe how to implement and manage this row-level security? (Choose two.)

⚠ Common exam trap

The trap here is thinking that MODIFY privilege bypasses row filters or that row filters are limited to external tables, when in fact a dedicated BYPASS ROW FILTER privilege is required and both table types support filters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The row filter function must accept the column(s) as parameters and return a BOOLEAN value indicating whether the row should be visible.

Row-level security in Unity Catalog is implemented by attaching a row filter function to a table using ALTER TABLE ... SET ROW FILTER. The function receives column values and returns a boolean, often using identity functions to filter based on group membership. Both managed and external tables support row filters, and bypassing them requires the BYPASS ROW FILTER privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Row filters can only be applied to external tables, not managed tables, because managed tables do not support fine-grained access control.

    Why it's wrong here

    Row filters are supported on both managed and external tables in Unity Catalog. Managed tables fully support fine-grained access control including row filters and column masks. The distinction between managed and external tables relates to storage lifecycle and governance, not the ability to apply row-level security.

  • ✓

    The row filter function must accept the column(s) as parameters and return a BOOLEAN value indicating whether the row should be visible.

    Why this is correct

    Unity Catalog row filter functions are SQL UDFs that take one or more column values as input and return a boolean. The function evaluates to TRUE for rows the user is allowed to see. It can reference the current user or group via functions like is_account_group_member(), enabling dynamic filtering based on identity.

  • ✗

    The row filter function must be defined in the same schema as the table it protects.

    Why it's wrong here

    The row filter function can be defined in any schema within the same Unity Catalog metastore, as long as the user applying it has the necessary privileges. It does not need to reside in the same schema as the table. However, the function must be fully qualified when referenced in the ALTER TABLE statement.

  • ✓

    Apply the row filter using: ALTER TABLE prod.finance.transactions SET ROW FILTER prod.security.region_filter ON (region);

    Why this is correct

    This is the correct syntax to attach a row filter function to a table in Unity Catalog. The SET ROW FILTER clause specifies the function and the columns it receives as arguments. The function must return a boolean expression that determines which rows are visible. This enforces row-level security dynamically based on the user's group membership.

  • ✗

    Users with the MODIFY privilege on the table automatically bypass the row filter and see all rows.

    Why it's wrong here

    Bypassing row filters requires the BYPASS ROW FILTER privilege, not MODIFY. MODIFY allows writing to the table but does not grant visibility to all rows. Without BYPASS ROW FILTER, even users who can modify data are subject to the row filter when reading. This ensures that write access does not inadvertently expose sensitive rows.

About these practice questions

This Databricks-DE-Assoc question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.