Databricks-DE-Assoc Governance and Security Practice Question
A data engineer manages a Unity Catalog table `sales.raw.transactions` that contains a column `credit_card_number`. The security team requires that users in the `auditors` group can see the full credit card number, while all other users who have SELECT privileges on the table should see only the last four digits. The engineer decides to use a column mask. Which SQL statement should the engineer execute to meet this requirement?
⚠ Common exam trap
The trap here is believing that a DENY privilege exists in Unity Catalog or that masking can be done inline without a function, when in fact Unity Catalog uses additive grants and requires a user-defined function for column masks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CREATE FUNCTION mask_ccn(ccn STRING) RETURNS STRING RETURN CASE WHEN is_member('auditors') THEN ccn ELSE CONCAT('************', RIGHT(ccn, 4)) END; ALTER TABLE sales.raw.transactions ALTER COLUMN credit_card_number SET MASK mask_ccn;
The correct solution is to create a user-defined function that conditionally masks the credit card number based on membership in the auditors group, and then apply that function as a column mask using ALTER TABLE ... SET MASK. This allows auditors to see the full value while other users see only the last four digits. Unity Catalog column masks are applied at query time and require the function to be created in a schema accessible to users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CREATE VIEW sales.raw.transactions_masked AS SELECT *, CASE WHEN is_member('auditors') THEN credit_card_number ELSE CONCAT('************', RIGHT(credit_card_number, 4)) END AS credit_card_number FROM sales.raw.transactions;
Why it's wrong here
Creating a view with conditional logic is a valid alternative for masking, but it does not meet the requirement as directly as a column mask. The view would need to be used instead of the base table, and users would need to be granted access to the view, not the table. The question specifies using a column mask, and this option does not use the column mask feature. Additionally, the view approach requires managing permissions on the view and ensuring users do not access the base table.
- ✓
CREATE FUNCTION mask_ccn(ccn STRING) RETURNS STRING RETURN CASE WHEN is_member('auditors') THEN ccn ELSE CONCAT('************', RIGHT(ccn, 4)) END; ALTER TABLE sales.raw.transactions ALTER COLUMN credit_card_number SET MASK mask_ccn;
Why this is correct
This approach creates a user-defined function that checks group membership using is_member and applies the mask conditionally. Then, the ALTER TABLE statement sets the mask on the column. This is the correct way to implement column-level masking in Unity Catalog, as it allows dynamic masking based on the user's group membership. The function must be created in a schema that the users have access to, and the mask is applied at query time.
- ✗
GRANT SELECT ON TABLE sales.raw.transactions TO auditors; DENY SELECT ON TABLE sales.raw.transactions TO users;
Why it's wrong here
Unity Catalog does not support DENY statements. Privileges are additive, and access is determined by GRANTs. While you can grant SELECT to auditors, you cannot deny SELECT to other users. To restrict access, you would need to revoke privileges from other groups, but that would remove their ability to query the table entirely, not just mask the column. This approach does not achieve column-level masking.
- ✗
ALTER TABLE sales.raw.transactions ALTER COLUMN credit_card_number SET MASK CONCAT('************', RIGHT(credit_card_number, 4));
Why it's wrong here
The SET MASK clause expects a function name, not an inline expression. You cannot directly specify an expression like CONCAT in the ALTER TABLE statement. A user-defined function must be created first and then referenced by name. This option would result in a syntax error or fail to apply the mask correctly. The correct approach involves creating a function and then setting the mask to that function.
About these practice questions
Courseiva writes every Databricks-DE-Assoc question from scratch — 276 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.