Courseiva
Governance and Security →mediumMultiple Select

Databricks-DE-Assoc Governance and Security Practice Question

A data engineer is tasked with securing sensitive PII data in Unity Catalog. Which THREE actions are recommended to ensure robust security and compliance?

⚠ Common exam trap

Candidates often select single-layer security approaches like only masking columns, ignoring that robust PII compliance requires a defense-in-depth strategy combining masking, auditing, and permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply Dynamic Data Masking to columns containing PII.

Implementing a defense-in-depth strategy is crucial for PII. Using Unity Catalog's fine-grained access controls, dynamic masking, and audit logs provides a layered approach to security. These tools allow organizations to restrict access, obscure sensitive values, and maintain a verifiable trail of who accessed what data, which is essential for meeting regulatory requirements and minimizing the risk of unauthorized data breaches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant SELECT access to all users to ensure data accessibility.

    Why it's wrong here

    Granting SELECT access to all users violates the principle of least privilege. Sensitive PII should be restricted only to authorized personnel. Broad access increases the risk of data leaks and makes it difficult to maintain audit compliance and demonstrate that the organization is properly protecting its data assets.

  • ✓

    Apply Dynamic Data Masking to columns containing PII.

    Why this is correct

    Dynamic Data Masking is a primary control for PII. By masking sensitive columns, you ensure that analysts can work with the data for aggregate statistics without actually seeing raw, identifiable information, which helps satisfy data privacy requirements while maintaining the utility of the dataset for authorized users.

  • ✓

    Enable Unity Catalog audit logs to monitor data access.

    Why this is correct

    Audit logs are critical for security and compliance. They provide a comprehensive record of all actions performed within Unity Catalog, including who accessed which tables and when. This visibility allows security teams to detect anomalies, investigate potential breaches, and provide documentation to auditors regarding data access patterns.

  • ✓

    Use table-level permissions to restrict access to sensitive datasets.

    Why this is correct

    Table-level permissions are a foundational security control in Unity Catalog. By isolating sensitive PII into specific tables and granting access only to those who strictly need it, you minimize the blast radius of potential unauthorized access and enforce a clear boundary for data privacy within your organization.

  • ✗

    Store all PII data in the root metastore directory for easy access.

    Why it's wrong here

    Storing data in the root directory is a security risk. You should follow a structured organizational approach where sensitive data is stored in specific schemas or catalogs with separate access controls. The root directory is not designed for granular access management and can lead to unauthorized data exposure.

About these practice questions

One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.