Courseiva
Governance and Security →mediumMultiple Choice

Databricks-DE-Assoc Governance and Security Practice Question

A data engineer needs to grant a group `data_consumers` the ability to query a view `prod.reporting.sales_summary` that is defined on top of tables in the same catalog. The group currently has no privileges on the underlying tables. What is the minimum set of privileges the engineer must grant to `data_consumers` so they can query the view successfully?

⚠ Common exam trap

The trap here is assuming that consumers need `SELECT` on underlying tables, when Unity Catalog views use the owner's privileges for referenced objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant `SELECT` on the view, plus `USE CATALOG` on `prod` and `USE SCHEMA` on `reporting`.

In Unity Catalog, views execute with the view owner's privileges for referenced objects, so consumers do not need direct privileges on underlying tables. The minimum required set is `SELECT` on the view, `USE CATALOG` on the containing catalog, and `USE SCHEMA` on the containing schema. This allows querying while adhering to least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant `ALL PRIVILEGES` on the view and `USE SCHEMA` on `reporting`.

    Why it's wrong here

    `ALL PRIVILEGES` on the view grants more than needed, including `MODIFY`, which is not required for querying. `USE CATALOG` on `prod` is also missing. This over-grants and under-specifies the necessary navigation privileges, making it incorrect for least privilege.

  • ✓

    Grant `SELECT` on the view, plus `USE CATALOG` on `prod` and `USE SCHEMA` on `reporting`.

    Why this is correct

    To query a view, a user needs `SELECT` on the view and `USE CATALOG` and `USE SCHEMA` on the containing catalog and schema. Unity Catalog views run with the view owner's rights for referenced tables, so no direct privileges on underlying tables are needed. This is the minimum required set.

  • ✗

    Grant `SELECT` on the view and `SELECT` on the underlying tables.

    Why it's wrong here

    Granting `SELECT` on the underlying tables is not required for querying a view in Unity Catalog. Views execute with the view owner's privileges for the underlying objects, so the consumer only needs `SELECT` on the view itself. This option over-grants privileges and violates least privilege.

  • ✗

    Grant `SELECT` on the view and `BROWSE` on the underlying tables.

    Why it's wrong here

    `BROWSE` allows a user to see an object's metadata but not to read its data. It does not contribute to querying a view, and the underlying tables do not need any grant because the view uses the owner's privileges. This option is both insufficient and unnecessary.

About these practice questions

Courseiva writes every Databricks-DE-Assoc question from scratch — 276 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.