Databricks-DE-Assoc Governance and Security Practice Question
A data engineering team must implement dynamic row-level filtering on a customer analytics table in Unity Catalog so that regional analysts only view records corresponding to their assigned territory. Which TWO steps are required to achieve this using Unity Catalog features? (Choose 2)
⚠ Common exam trap
Candidates often select manual table duplication or standard view definitions instead of combining a custom SQL UDF with the ALTER TABLE row filter command for dynamic filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a SQL user-defined function (UDF) that returns a boolean expression evaluating user identity and territory.
Implementing row-level security in Unity Catalog requires creating a SQL user-defined function that evaluates the current user's identity or group membership against a territory mapping table, and then applying that function to the target table using an ALTER TABLE command.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a SQL user-defined function (UDF) that returns a boolean expression evaluating user identity and territory.
Why this is correct
Unity Catalog row filters are applied as a SQL user-defined function returning a boolean expression. The UDF evaluates the caller's identity against their assigned territory, so regional analysts only see matching rows, satisfying the stem's dynamic row-level filtering requirement.
- ✓
Apply the custom SQL UDF as a row filter to the target table using the ALTER TABLE command.
Why this is correct
Executing an ALTER TABLE statement to attach the SQL UDF as a row filter enforces the dynamic predicate transparently across all queries. Every access to the table automatically evaluates this function, ensuring strict adherence to regional security policies.
- ✗
Modify the underlying cloud storage bucket IAM policy to restrict read access based on user session tags.
Why it's wrong here
Modifying cloud IAM policies restricts access at the storage layer rather than the table level, making fine-grained row filtering impossible. Cloud object stores operate on file paths and prefixes, lacking the ability to evaluate row-level attributes inside Delta files.
- ✗
Create separate physical views for each regional analyst group and grant SELECT privileges exclusively on those views.
Why it's wrong here
Separate physical views duplicate the table per region and must be maintained individually, whereas Unity Catalog row filters and column masks apply centrally to one table. It is tempting because view-based access control is a familiar pattern, and would be correct on platforms lacking native row-level security.
- ✗
Configure cluster-level Spark configurations to automatically inject WHERE clauses into user queries.
Why it's wrong here
Cluster-level Spark configurations can be easily bypassed by users spinning up alternative clusters or using Databricks SQL endpoints. Security rules must be enforced centrally within the Unity Catalog metastore rather than relying on individual cluster configurations.
About these practice questions
This Databricks-DE-Assoc question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.