Databricks-DE-Assoc Governance and Security Practice Question
A data engineer needs to share a Delta table managed by Unity Catalog with external partners who do not have access to the Databricks workspace. Which feature should be used to securely grant read-only access to this table without replicating the data?
⚠ Common exam trap
Candidates often confuse Delta Sharing with standard workspace sharing or assume external partners need Databricks workspace accounts. Delta Sharing uses open protocols and recipient objects, removing the requirement for shared workspaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Delta Sharing share, add the table to the share, and grant access to a recipient object configured for the partners.
Delta Sharing is an open protocol for secure data sharing that allows organizations to share data directly from cloud storage without copying files. Unity Catalog integrates natively with Delta Sharing, enabling governance teams to manage access for external recipients securely using tokens and activation links, making it the ideal solution for cross-organization data collaboration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure cross-account IAM role assumption to grant direct AWS S3 bucket read permissions to the external partners.
Why it's wrong here
Granting direct cloud storage access exposes underlying infrastructure credentials and bypasses Unity Catalog governance controls. External partners should never receive direct access to raw cloud buckets due to security compliance risks and lack of granular table-level filtering capabilities.
- ✗
Set up a Databricks SQL endpoint and create individual workspace user accounts for every external partner.
Why it's wrong here
Creating workspace accounts requires partners to join the workspace and consumes licensed seats, and it does not by itself expose a single table read-only. It is tempting because workspace users can be granted table privileges, but it would be correct for internal colleagues, not external partners without workspace access.
- ✓
Create a Delta Sharing share, add the table to the share, and grant access to a recipient object configured for the partners.
Why this is correct
Delta Sharing is an open protocol that lets recipients read shared tables through a recipient object without workspace access or data replication. This satisfies the constraint of secure read-only external sharing while keeping a single governed copy.
- ✗
Export the Delta table to CSV format and upload the files to an external SFTP server on a nightly schedule.
Why it's wrong here
Nightly CSV exports over SFTP create replicated copies outside Unity Catalog governance, so access cannot be revoked or audited and the data is stale. It is tempting for one-off bulk handovers, but Delta Sharing is the correct choice for live read-only sharing without replication.
About these practice questions
This Databricks-DE-Assoc question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.