Courseiva
Governance and Security →mediumMultiple Choice

Databricks-DE-Assoc Governance and Security Practice Question

A data engineering team needs to restrict access to a sensitive customer table in Unity Catalog so that junior data engineers can only view non-PII columns, while senior engineers can view all columns. Which approach should be used to implement this requirement securely and efficiently?

⚠ Common exam trap

Candidates often assume they need to create separate physical tables for different user groups, which violates data governance best practices and creates maintenance overhead and data duplication risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define a SQL user-defined function combined with a dynamic view utilizing the IS_MEMBER function to conditionally mask sensitive columns based on the querying user's group membership.

Row and column-level security in Unity Catalog is implemented by defining SQL user-defined functions and applying dynamic views or masking policies. Creating a dynamic view using the IS_MEMBER function allows the database engine to evaluate user group membership at query execution time and conditionally mask or exclude sensitive columns without duplicating the underlying physical dataset, ensuring optimal storage and compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create separate physical copies of the customer table for junior and senior engineers, applying access control lists directly on the underlying files in cloud object storage using IAM policies.

    Why it's wrong here

    Unity Catalog enforces column-level privileges through GRANT SELECT on specific columns, so junior engineers can be restricted to non-PII fields without duplicating data. Copying tables and relying on cloud IAM policies bypasses Unity Catalog governance entirely, and IAM operates on storage paths, not columns. Physical copies suit air-gapped environments where separate storage accounts are genuinely required.

  • ✗

    Revoke ALL PRIVILEGES on the customer table from the junior engineers group and grant SELECT privilege only after they sign a data access request form stored in a shared workspace notebook.

    Why it's wrong here

    Revoking privileges and gating SELECT behind a signed form is a manual, out-of-band process that grants full-table access once approved, so junior engineers still see PII columns. Unity Catalog column-level GRANTs enforce non-PII visibility automatically. Privilege revocation suits offboarding or least-privilege baselines, not column-scoped read access.

  • ✓

    Define a SQL user-defined function combined with a dynamic view utilizing the IS_MEMBER function to conditionally mask sensitive columns based on the querying user's group membership.

    Why this is correct

    A dynamic view calling a SQL UDF that evaluates IS_MEMBER returns masked or full column values per group, so junior engineers see non-PII only while senior engineers see everything. This enforces row-and-column-level control centrally in Unity Catalog without duplicating tables.

  • ✗

    Apply table ACLs directly on the raw Delta table by executing GRANT SELECT ON TABLE customer TO `junior-engineers` while writing custom Spark UDFs in every notebook to drop PII columns.

    Why it's wrong here

    Table-level GRANT SELECT exposes every column, including PII, so junior engineers gain full visibility; notebook UDFs are advisory and unenforced, since any query bypassing those notebooks reads the raw columns. Unity Catalog column-level GRANTs restrict access at query time. Table ACLs are correct when a group needs all columns of a table and no finer granularity is required.

About these practice questions

One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.