Databricks-DE-Assoc Governance and Security Practice Question
A data engineer is managing a Unity Catalog table that contains sensitive financial data. The table is owned by the 'finance' group, and the data engineer needs to allow the 'auditors' group to read the table but not modify it. Additionally, the data engineer wants to ensure that the 'auditors' group can see the table's metadata (e.g., column names and types) but cannot access the underlying data files directly. Which TWO actions should the data engineer take to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is forgetting that USAGE on the schema is a prerequisite for table access, or mistakenly granting file-level permissions that circumvent governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant USAGE on the schema containing the table to the 'auditors' group.
To allow read-only access, the data engineer must grant SELECT on the table and USAGE on the containing schema. SELECT provides read access and metadata visibility, while USAGE is required to access any object within the schema. Granting MODIFY or ALL PRIVILEGES would allow modifications, and READ FILES would bypass table-level security. These two privileges together satisfy the requirements without over-provisioning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant READ FILES on the external location to the 'auditors' group.
Why it's wrong here
READ FILES allows direct access to the underlying files, bypassing table-level governance. This would let auditors see raw data files and potentially other data in the same location, which is not desired. Unity Catalog's security model is designed to prevent direct file access when using managed tables or external tables without explicit file grants.
- ✗
Grant MODIFY on the table to the 'auditors' group.
Why it's wrong here
MODIFY allows inserting, updating, and deleting data, which violates the requirement that auditors must not modify the table. This privilege is too permissive and would allow changes to the sensitive financial data. It is not appropriate for a read-only auditor role.
- ✓
Grant USAGE on the schema containing the table to the 'auditors' group.
Why this is correct
USAGE on the schema is required for any user to access objects within that schema. Without USAGE, even if SELECT is granted on the table, the auditors cannot resolve the table's fully qualified name. This is a necessary prerequisite for table access in Unity Catalog.
- ✗
Grant ALL PRIVILEGES on the table to the 'auditors' group.
Why it's wrong here
ALL PRIVILEGES includes MODIFY, which would allow auditors to change data. It also grants other privileges not needed for read-only access. This over-provisions rights and violates the principle of least privilege. It is not the correct action for this scenario.
- ✓
Grant SELECT on the table to the 'auditors' group.
Why this is correct
Granting SELECT on the table allows the 'auditors' group to read the data, which is a requirement. In Unity Catalog, SELECT also implicitly grants the ability to see metadata such as column names and types. This is the correct privilege to provide read access without modification rights.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.