Courseiva

CCNA Governance and Security Questions

46 questions · Governance and Security · All types, answers revealed

1
Multi-Selectmedium

A data engineer is tasked with securing sensitive PII data in Unity Catalog. Which THREE actions are recommended to ensure robust security and compliance?

Select 3 answers
A.Grant SELECT access to all users to ensure data accessibility.
B.Apply Dynamic Data Masking to columns containing PII.
C.Enable Unity Catalog audit logs to monitor data access.
D.Use table-level permissions to restrict access to sensitive datasets.
E.Store all PII data in the root metastore directory for easy access.
AnswersB, C, D

Dynamic Data Masking is a primary control for PII. By masking sensitive columns, you ensure that analysts can work with the data for aggregate statistics without actually seeing raw, identifiable information, which helps satisfy data privacy requirements while maintaining the utility of the dataset for authorized users.

Why this answer

Implementing a defense-in-depth strategy is crucial for PII. Using Unity Catalog's fine-grained access controls, dynamic masking, and audit logs provides a layered approach to security. These tools allow organizations to restrict access, obscure sensitive values, and maintain a verifiable trail of who accessed what data, which is essential for meeting regulatory requirements and minimizing the risk of unauthorized data breaches.

Exam trap

Candidates often select single-layer security approaches like only masking columns, ignoring that robust PII compliance requires a defense-in-depth strategy combining masking, auditing, and permissions.

2
MCQhard

Which of the following describes the correct order of operations to configure a new external location in Unity Catalog?

A.Grant privileges, create location, create credential.
B.Create credential, create location, grant privileges.
C.Create location, grant privileges, create credential.
D.Create credential, grant privileges, create location.
AnswerB

This is the correct sequence. A storage credential encapsulates the cloud permissions required to access the files. Then, the location maps that credential to a specific path. Finally, granting privileges allows users to interact with the data at that location, ensuring a secure and ordered governance workflow.

Why this answer

The process begins with creating a storage credential, which holds the cloud-specific security details (like an IAM role or service account). This credential is then used to define the external location, which points to a specific path in cloud storage. Finally, you grant the user or service the 'READ FILES' or 'WRITE FILES' privilege on the external location to permit interaction with the underlying data files within the Unity Catalog framework.

Exam trap

Candidates often attempt to create an external location before setting up the underlying storage credential, forgetting that the location explicitly depends on a pre-existing credential object.

3
MCQeasy

Which feature in Unity Catalog is primarily used to track data movement and transformation history for compliance and auditing?

A.Audit Logs
B.Data Lineage
C.Delta Sharing
D.Catalog Explorer
AnswerB

Data lineage captures the dependencies between tables, views, and notebooks. It shows the flow of data through transformations, which is essential for auditability. By tracking these relationships, data engineers and security officers can verify the provenance of data and fulfill regulatory requirements regarding data processing and handling.

Why this answer

Data lineage provides a graphical and programmatic representation of data flow from source tables to downstream targets. It is vital for governance as it allows administrators to see exactly where data came from and how it was processed. This transparency is critical for compliance audits, allowing teams to quickly identify the impact of changes or potential data leakage points within the entire data ecosystem.

Exam trap

Candidates often mistake 'Data Lineage' for 'Audit Logs' or 'Query History'. While audit logs track access, only Data Lineage specifically tracks the transformation and flow of data objects.

4
MCQmedium

A data engineering team needs to restrict access to a sensitive customer table in Unity Catalog so that junior data engineers can only view non-PII columns, while senior engineers can view all columns. Which approach should be used to implement this requirement securely and efficiently?

A.Create separate physical copies of the customer table for junior and senior engineers, applying access control lists directly on the underlying files in cloud object storage using IAM policies.
B.Revoke ALL PRIVILEGES on the customer table from the junior engineers group and grant SELECT privilege only after they sign a data access request form stored in a shared workspace notebook.
C.Define a SQL user-defined function combined with a dynamic view utilizing the IS_MEMBER function to conditionally mask sensitive columns based on the querying user's group membership.
D.Apply table ACLs directly on the raw Delta table by executing GRANT SELECT ON TABLE customer TO `junior-engineers` while writing custom Spark UDFs in every notebook to drop PII columns.
AnswerC

A dynamic view calling a SQL UDF that evaluates IS_MEMBER returns masked or full column values per group, so junior engineers see non-PII only while senior engineers see everything. This enforces row-and-column-level control centrally in Unity Catalog without duplicating tables.

Why this answer

Row and column-level security in Unity Catalog is implemented by defining SQL user-defined functions and applying dynamic views or masking policies. Creating a dynamic view using the IS_MEMBER function allows the database engine to evaluate user group membership at query execution time and conditionally mask or exclude sensitive columns without duplicating the underlying physical dataset, ensuring optimal storage and compliance.

Exam trap

Candidates often assume they need to create separate physical tables for different user groups, which violates data governance best practices and creates maintenance overhead and data duplication risks.

5
Multi-Selecthard

A data engineer is configuring Unity Catalog governance for a multi-department organization. Which TWO actions require the metastore admin or catalog owner to have a workspace-independent metastore assigned? (Choose TWO)

Select 2 answers
A.Creating a new catalog inside the Unity Catalog metastore.
B.Binding a workspace to a Unity Catalog metastore to enable catalog-level data access.
C.Granting the SELECT privilege on a specific schema to a group of data analysts.
D.Configuring the root storage location for the metastore using a secure cloud storage container.
E.Defining a custom dynamic view with column-level masking functions for auditing.
AnswersB, D

Workspace binding enforces security isolation by mapping specific workspaces to a Unity Catalog metastore. This administrative configuration ensures that data assets governed by the metastore are only accessible through authorized workspaces, requiring proper metastore administration.

Why this answer

A Unity Catalog metastore is the top-level container for metadata, governing three levels of namespacing (catalog, schema, table). Certain administrative tasks like assigning a metastore to workspaces or managing root storage locations require specific privileges and architectural scopes, ensuring centralized security governance across multiple workspaces.

Exam trap

Test-takers frequently assume routine table-level operations or basic user grants require a metastore-level scope, confusing everyday data engineering tasks with account-level administrative actions.

6
Multi-Selecthard

A data engineer is migrating legacy tables to Unity Catalog. Which TWO of the following statements regarding the transition to three-level namespace (catalog.schema.table) are true?

Select 2 answers
A.Three-level namespace applies to all Unity Catalog objects.
B.Hive Metastore objects are automatically migrated to Unity Catalog.
C.Permissions at the catalog level cascade to all child schemas and tables.
D.External locations are not required for three-level namespace tables.
E.Three-level namespace is optional in Unity Catalog.
AnswersA, C

Unity Catalog enforces a strict hierarchy consisting of catalog, schema, and table or view. This structure provides a unified way to manage permissions and lineage across different workspaces. Every managed or external object must adhere to this naming convention to be correctly registered within the Unity Catalog metadata store.

Why this answer

Unity Catalog introduces a hierarchical namespace that forces a clear separation between data assets. Understanding this structure is critical for governance, as permissions are inherited down from the catalog and schema levels. By adopting this structure, organizations can enforce consistent policies across environments, simplify cross-workspace data sharing, and ensure that all metadata is discoverable through a centralized catalog that replaces the legacy Hive Metastore structure.

Exam trap

Candidates often assume permissions must be explicitly assigned at the table level, overlooking the inheritance model where catalog-level grants automatically cascade down to schemas and tables.

7
MCQmedium

Which security feature should a data engineer configure to ensure that audit logs from all Databricks workspaces are captured and stored in a single, centralized location?

A.Cluster event logs.
B.Diagnostic logs.
C.System schema (system.access).
D.Workspace-local storage.
AnswerB

Diagnostic logs are the official channel for exporting audit data from Databricks. By streaming these to a workspace-external destination, administrators can aggregate audit data from multiple workspaces into one place, enabling a unified view of all user activity, configuration changes, and data access events for audit and security analysis.

Why this answer

Databricks diagnostic logs are the primary mechanism for collecting security, governance, and operational audit information. By configuring diagnostic log streaming to a centralized location, such as a cloud-native log repository (e.g., Azure Log Analytics or AWS S3), organizations can perform centralized monitoring, anomaly detection, and compliance reporting across their entire Databricks estate, ensuring no audit trail is lost or siloed in individual workspaces.

Exam trap

Candidates frequently confuse standard cluster log delivery with audit logs, missing that security events and governance tracking across workspaces require configuring diagnostic logs.

8
MCQmedium

Refer to the exhibit. A data engineer attempts to run the GRANT statement above in a Databricks SQL query editor. What is the most likely reason for failure?

A.The syntax of the GRANT statement is incorrect.
B.The table does not exist.
C.The table must be referenced using a three-level namespace.
D.The group 'data_scientists' does not exist.
AnswerC

Unity Catalog requires the fully qualified name (catalog.schema.table). Providing only the table name causes the operation to fail because the metastore cannot resolve the resource context. This forces explicit identification of the data, which is a security best practice to prevent unauthorized or unintended access to tables.

Why this answer

The command fails because Unity Catalog requires the full three-level namespace (catalog.schema.table). Without specifying 'main.prod.sales_data', the engine cannot locate the table within the hierarchical metadata store. This strict requirement ensures that all data access is explicitly scoped, preventing ambiguity in multi-catalog or multi-schema environments, which is a fundamental tenet of Unity Catalog's governance model for enterprise-grade security and asset management.

Exam trap

Candidates often assume that the current active catalog and schema context apply to GRANT statements, forgetting that Unity Catalog strictly mandates the full three-level namespace.

9
MCQmedium

Refer to the exhibit. A user who is a member of 'data_analysts_group' reports they cannot see the 'orders' table in the Catalog Explorer. What is the most likely cause?

A.The user lacks the 'SELECT' privilege.
B.The user lacks the 'USAGE' privilege on the parent objects.
C.The table is not registered in the Hive Metastore.
D.The group does not exist in the workspace.
AnswerB

Unity Catalog requires USAGE on the catalog and schema to navigate to the table. If these permissions were missing, the user would not be able to traverse the path to the table in Catalog Explorer, even if they had SELECT permissions on the table itself. This is a common security configuration error.

Why this answer

In Unity Catalog, the 'USAGE' privilege is a mandatory prerequisite for navigating any parent object. Even if the user has SELECT access on the table, they must also hold USAGE on the parent catalog and schema to traverse the hierarchy and discover the table. Without these permissions, the object remains invisible to the user in the UI, even if they have technical access to the underlying data records.

Exam trap

Candidates focus solely on table-level permissions and overlook the requirement for 'USAGE' privileges on the parent catalog and schema, which are mandatory for object discovery in the UI.

10
MCQmedium

A data engineer needs to share a subset of a table with an external partner who does not have access to the internal Databricks workspace. What is the most appropriate method to achieve this?

A.Create a service principal with restricted access.
B.Export data to CSV and email it.
C.Use Delta Sharing to share a table.
D.Grant the partner access to a shared S3 bucket.
AnswerC

Delta Sharing provides a secure and governed way to share data with third parties. It does not require the recipient to be a user in the provider's environment, thereby keeping the internal workspace secure while allowing controlled access to specific datasets through signed URLs and the Delta protocol.

Why this answer

Delta Sharing is the secure, open-standard solution for sharing data externally. It allows the recipient to access data directly from cloud storage without needing to provision an account in the provider's Databricks workspace. This process is secure because it uses short-lived tokens and does not require complex credential management, ensuring that data stays governed and that the provider retains control over what is being shared.

Exam trap

Candidates often choose 'exporting to CSV' or 'creating a shared volume,' failing to realize that Delta Sharing is the only native, secure, and governance-compliant method for sharing data outside the Databricks ecosystem.

11
MCQmedium

A data engineer is configuring audit logging for a Databricks workspace that uses Unity Catalog. The security team requires that all access to data in Unity Catalog be logged and available for analysis in a centralized location. The data engineer wants to enable the delivery of audit logs to an AWS S3 bucket. Which configuration should the data engineer use?

A.Configure an audit log delivery in the account console, specifying the S3 bucket and IAM role for delivery.
B.Enable diagnostic logging in the Databricks workspace and configure it to send logs to S3.
C.Enable Unity Catalog audit logs in the workspace settings and specify an S3 path for storage.
D.Use the Databricks REST API to stream audit logs to an S3 bucket via a custom script.
AnswerA

Unity Catalog audit logs are delivered via a system table or to a cloud storage location configured at the account level. The account console allows setting up audit log delivery to an S3 bucket with an IAM role that grants write access. This centralizes logs for security analysis.

Why this answer

Databricks audit logs, including Unity Catalog data access, can be delivered to an AWS S3 bucket through account-level configuration. This involves setting up a delivery mechanism with an IAM role that has write permissions to the bucket. The account console provides the interface for this setup, ensuring centralized log collection.

Exam trap

The trap here is confusing workspace-level diagnostic logging with account-level audit log delivery, or assuming audit logs are configured per workspace.

12
Multi-Selectmedium

A data engineer is managing a Unity Catalog table that contains sensitive financial data. The table is owned by the 'finance' group, and the data engineer needs to allow the 'auditors' group to read the table but not modify it. Additionally, the data engineer wants to ensure that the 'auditors' group can see the table's metadata (e.g., column names and types) but cannot access the underlying data files directly. Which TWO actions should the data engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Grant READ FILES on the external location to the 'auditors' group.
B.Grant MODIFY on the table to the 'auditors' group.
C.Grant USAGE on the schema containing the table to the 'auditors' group.
D.Grant ALL PRIVILEGES on the table to the 'auditors' group.
E.Grant SELECT on the table to the 'auditors' group.
AnswersC, E

USAGE on the schema is required for any user to access objects within that schema. Without USAGE, even if SELECT is granted on the table, the auditors cannot resolve the table's fully qualified name. This is a necessary prerequisite for table access in Unity Catalog.

Why this answer

To allow read-only access, the data engineer must grant SELECT on the table and USAGE on the containing schema. SELECT provides read access and metadata visibility, while USAGE is required to access any object within the schema. Granting MODIFY or ALL PRIVILEGES would allow modifications, and READ FILES would bypass table-level security.

These two privileges together satisfy the requirements without over-provisioning.

Exam trap

The trap here is forgetting that USAGE on the schema is a prerequisite for table access, or mistakenly granting file-level permissions that circumvent governance.

13
MCQmedium

A data engineer needs to allow a service principal to read data from a Unity Catalog table `sales.orders` and also write to a volume `sales.raw_data`. Which set of privileges should be granted to the service principal?

A.ALL PRIVILEGES on table sales.orders, and WRITE VOLUME on volume sales.raw_data.
B.SELECT on table sales.orders, and WRITE VOLUME on volume sales.raw_data.
C.SELECT on table sales.orders, and READ VOLUME on volume sales.raw_data.
D.MODIFY on table sales.orders, and WRITE VOLUME on volume sales.raw_data.
AnswerB

SELECT on the table grants read access to its data. WRITE VOLUME on the volume grants the ability to write files to that volume. Together, these privileges meet the requirement for the service principal to read from the table and write to the volume. This combination is precise and follows the principle of least privilege.

Why this answer

To read from a Unity Catalog table, the service principal needs SELECT on the table. To write to a volume, it needs WRITE VOLUME on the volume. These privileges are the minimal required to perform the specified actions, adhering to the principle of least privilege.

Other options either grant insufficient access to the volume or excessive access to the table.

Exam trap

The trap here is confusing READ VOLUME with WRITE VOLUME, or granting MODIFY instead of SELECT on the table, leading to over-privilege.

14
MCQeasy

A data engineer needs to grant the `analyst` group the ability to read data from a Unity Catalog table `sales.fact_orders`. They also want to ensure that members of `analyst` can see the table in the catalog explorer but cannot modify it. Which privilege should be granted to the `analyst` group on the table?

A.GRANT USAGE ON TABLE sales.fact_orders TO `analyst`;
B.GRANT MODIFY ON TABLE sales.fact_orders TO `analyst`;
C.GRANT ALL PRIVILEGES ON TABLE sales.fact_orders TO `analyst`;
D.GRANT SELECT ON TABLE sales.fact_orders TO `analyst`;
AnswerD

The SELECT privilege allows users to read data from the table, which includes querying it and viewing its metadata in Catalog Explorer. It does not grant the ability to modify data or table structure. This is the minimum privilege required for read-only access, aligning with the requirement.

Why this answer

To allow read-only access to a Unity Catalog table, the SELECT privilege is granted. It permits querying and viewing metadata without modification rights. MODIFY would allow changes, ALL PRIVILEGES is excessive, and USAGE is not applicable to tables.

SELECT is the least privilege that meets the requirement.

Exam trap

The trap here is confusing USAGE with SELECT; USAGE is for catalogs and schemas, not tables, and does not grant data access.

15
Multi-Selectmedium

A data engineer is designing an access control model in Unity Catalog for a new catalog `finance`. The team wants to follow the principle of least privilege while still enabling collaboration. Which TWO of the following practices best align with Unity Catalog's privilege model? (Choose two.)

Select 2 answers
A.Use account-level groups as principals for grants rather than individual users, so membership changes automatically update effective permissions.
B.Grant `SELECT` on all tables in `finance` to the `public` group to ensure no one is blocked during onboarding.
C.Grant `ALL PRIVILEGES` on the `finance` catalog to the engineering group to simplify administration.
D.Grant `USE CATALOG` on `finance` to all users who need to query any table in that catalog, and grant `USE SCHEMA` only on the specific schemas they need.
E.Grant `MANAGE` on the `finance` catalog to the data engineering group so they can delegate privileges to others.
AnswersA, D

Unity Catalog supports account-level groups as principals. Granting privileges to groups means that when users are added or removed from the group, their effective permissions change without re-issuing grants. This simplifies administration and aligns with least privilege by managing access at the group level rather than per user.

Why this answer

Least privilege in Unity Catalog is achieved by granting `USE CATALOG` broadly only where navigation is needed, limiting `USE SCHEMA` to required schemas, and using account-level groups as principals so membership changes propagate automatically. Broad grants such as `ALL PRIVILEGES`, `SELECT` to `public`, or `MANAGE` to large groups violate least privilege and should be avoided.

Exam trap

The trap here is equating `USE CATALOG` with data access, when it only enables navigation and must be paired with object-level privileges to read data.

16
MCQmedium

A data engineer needs to share a table in Unity Catalog with a partner organization using a different Databricks account. Which feature should be used to provide secure access without moving the data?

A.Databricks File System (DBFS) mount points
B.Unity Catalog External Locations
C.Delta Sharing
D.Cross-account IAM Role Assumption
AnswerC

Delta Sharing is specifically designed for secure data exchange across different platforms and accounts. It utilizes an open-source protocol that allows the recipient to query data directly from your storage without needing to copy the data, ensuring the provider maintains full control over access policies and auditing throughout the process.

Why this answer

Delta Sharing is the industry-standard open protocol for secure data sharing across organizational boundaries in Databricks. By utilizing Unity Catalog, Delta Sharing allows data providers to share live data directly from the storage layer without replicating files. This ensures governance, auditing, and real-time data access while maintaining strict security boundaries, which is critical for compliance and data sovereignty in modern enterprise data architectures.

Exam trap

Candidates often mistake traditional data replication, cloning, or workspace sharing for Delta Sharing when collaborating securely with external organizations across different Databricks accounts.

17
MCQmedium

A data engineer has a Unity Catalog table `prod.sales.orders` that contains a column `customer_email`. They need to allow analysts in the `marketing` group to query the table but only see a masked version of `customer_email` (e.g., `a***@example.com`). The masking logic is implemented as a SQL user-defined function `prod.security.mask_email`. Which statement should the engineer execute to apply the mask?

A.ALTER TABLE prod.sales.orders ALTER COLUMN customer_email SET MASK prod.security.mask_email;
B.CREATE VIEW prod.sales.orders_masked AS SELECT customer_email, prod.security.mask_email(customer_email) AS customer_email FROM prod.sales.orders;
C.ALTER TABLE prod.sales.orders SET TBLPROPERTIES ('mask.customer_email' = 'prod.security.mask_email');
D.GRANT SELECT ON TABLE prod.sales.orders TO `marketing` WITH MASK prod.security.mask_email ON customer_email;
AnswerA

This is the correct syntax to apply a column mask function in Unity Catalog. The ALTER TABLE ... ALTER COLUMN ... SET MASK command associates the masking UDF with the column. When users without UNMASK privilege query the table, the function is applied to the column value, returning the masked result. Users with UNMASK privilege see the original data.

Why this answer

Unity Catalog column masks are applied using ALTER TABLE ... ALTER COLUMN ... SET MASK <function>.

This associates a user-defined function with the column. Users without the UNMASK privilege automatically see the function's output, while privileged users see raw data. The other options either use invalid syntax or fail to enforce masking at the column level.

Exam trap

The trap here is assuming that masking can be granted via GRANT or set as a table property, rather than using the dedicated ALTER COLUMN ... SET MASK command.

18
MCQhard

A data engineer manages a Unity Catalog table `sales.raw.transactions` that contains a column `credit_card_number`. The security team requires that users in the `auditors` group can see the full credit card number, while all other users who have SELECT privileges on the table should see only the last four digits. The engineer decides to use a column mask. Which SQL statement should the engineer execute to meet this requirement?

A.CREATE VIEW sales.raw.transactions_masked AS SELECT *, CASE WHEN is_member('auditors') THEN credit_card_number ELSE CONCAT('************', RIGHT(credit_card_number, 4)) END AS credit_card_number FROM sales.raw.transactions;
B.CREATE FUNCTION mask_ccn(ccn STRING) RETURNS STRING RETURN CASE WHEN is_member('auditors') THEN ccn ELSE CONCAT('************', RIGHT(ccn, 4)) END; ALTER TABLE sales.raw.transactions ALTER COLUMN credit_card_number SET MASK mask_ccn;
C.GRANT SELECT ON TABLE sales.raw.transactions TO auditors; DENY SELECT ON TABLE sales.raw.transactions TO users;
D.ALTER TABLE sales.raw.transactions ALTER COLUMN credit_card_number SET MASK CONCAT('************', RIGHT(credit_card_number, 4));
AnswerB

This approach creates a user-defined function that checks group membership using is_member and applies the mask conditionally. Then, the ALTER TABLE statement sets the mask on the column. This is the correct way to implement column-level masking in Unity Catalog, as it allows dynamic masking based on the user's group membership. The function must be created in a schema that the users have access to, and the mask is applied at query time.

Why this answer

The correct solution is to create a user-defined function that conditionally masks the credit card number based on membership in the auditors group, and then apply that function as a column mask using ALTER TABLE ... SET MASK. This allows auditors to see the full value while other users see only the last four digits.

Unity Catalog column masks are applied at query time and require the function to be created in a schema accessible to users.

Exam trap

The trap here is believing that a DENY privilege exists in Unity Catalog or that masking can be done inline without a function, when in fact Unity Catalog uses additive grants and requires a user-defined function for column masks.

19
MCQmedium

Which of the following is the best practice for managing service principals in a Databricks workspace?

A.Use the workspace admin's personal access token for all automated jobs.
B.Store service principal credentials in plaintext variables within notebook code.
C.Assign the service principal a dedicated identity with scoped permissions.
D.Grant the service principal 'Admin' rights to avoid configuration errors.
AnswerC

Assigning a dedicated identity allows for granular control over what the automated job can access. By applying the principle of least privilege, you limit the blast radius if the service principal's credentials are ever leaked, ensuring that the automation can only access the specific resources required for its task.

Why this answer

Service principals are non-human identities used for automated processes. The best practice is to assign them only the minimum privileges required for the task (least privilege), store their credentials in a secure secrets manager (like Databricks Secrets or Azure Key Vault), and treat them as distinct entities from human users to ensure that automated jobs are isolated and easily auditable.

Exam trap

Candidates mistakenly suggest using a personal user account for jobs, failing to realize that service principals are the only secure, non-human identity recommended for automated production workloads.

20
MCQmedium

A data engineer needs to share a table in Unity Catalog with external partners who do not have access to the Databricks workspace. Which feature should the data engineer configure?

A.Configure cross-workspace table linking using standard Spark mount points.
B.Create a shared Unity Catalog metastore and provision external IAM database users.
C.Create a Delta Sharing recipient and publish tables to a sharing share object.
D.Export the Delta table files to CSV format and upload them to a public cloud bucket.
AnswerC

Publishing tables to a sharing object and defining a Delta Sharing recipient is the native architectural pattern. This permits secure, token-based data consumption by external entities directly from cloud storage without exposing internal metastores or workspace credentials.

Why this answer

Delta Sharing enables secure data sharing with external organizations without requiring recipients to have access to your Databricks workspace or even be on the same cloud platform. It leverages cloud object storage credentials and open protocols to ensure governed data exchange.

Exam trap

Candidates often confuse Delta Sharing with standard workspace sharing or external table grants, assuming external partners need direct workspace access or cloud credentials to query data.

21
MCQmedium

A data engineer has a Unity Catalog table `prod.sales.orders` containing a column `customer_email`. Company policy requires that users in the `analyst_group` see only the domain part of the email (e.g., `***@example.com`), while members of `pii_admin_group` must see the full email. The engineer wants to enforce this at query time without creating separate views. Which approach should the engineer use?

A.Apply a table-level tag `pii` to `prod.sales.orders` and configure a tag-based policy that automatically masks all string columns for non-admin users.
B.Grant `SELECT` on `prod.sales.orders` only to `pii_admin_group` and grant `SELECT` on a view that excludes `customer_email` to `analyst_group`.
C.Create a row filter function that returns TRUE for `pii_admin_group` and FALSE for others, then apply it to `prod.sales.orders`.
D.Create a column mask function that returns the full email for `pii_admin_group` and a masked email otherwise, then apply it to the `customer_email` column.
AnswerD

Column masks in Unity Catalog evaluate the current user's group membership at query time and return a transformed value per row. Applying a mask function to `customer_email` lets `pii_admin_group` see the raw value while others receive the masked domain-only output, satisfying the policy without duplicating the table.

Why this answer

Column masks in Unity Catalog let you attach a user-defined function to a specific column so that different users see different values for the same data. The function can inspect `is_account_group_member()` to return the raw email for the privileged group and a masked string for everyone else. This enforces the policy dynamically at query time and avoids creating separate views or duplicating the table.

Exam trap

The trap here is confusing row-level filtering with column-level masking, when the requirement is specifically to obscure a column value rather than hide rows.

22
MCQmedium

A data engineer is configuring a storage credential in Unity Catalog to access an AWS S3 bucket. The engineer creates an IAM role with the necessary permissions and sets up the storage credential using the role ARN. What additional step is required to allow Databricks to assume the role?

A.Enable AWS IAM Identity Center and configure SAML federation for the role.
B.Create an access key and secret key for the IAM role and store them in Databricks secrets.
C.Attach an IAM policy to the role that grants sts:AssumeRole to the Databricks AWS account.
D.Modify the role's trust policy to allow the Databricks AWS account to assume it.
AnswerD

To allow Databricks to assume the IAM role, the role's trust policy must include a principal for the Databricks AWS account (or the specific Databricks IAM role) and grant sts:AssumeRole. This establishes the trust relationship. Without this, Databricks cannot assume the role even if the role has the correct permissions to access S3.

Why this answer

For Databricks to assume an IAM role, the role's trust policy must explicitly allow the Databricks AWS account to assume it. This is a critical step in setting up a storage credential. The trust policy defines which principals can assume the role, and without it, the assumption fails regardless of the role's permissions.

Exam trap

The trap here is thinking that permissions policies on the role are sufficient, when actually the trust relationship is what allows Databricks to assume the role.

23
MCQmedium

A data engineer stores a Delta table in Unity Catalog at the managed location of the schema 'sales'. The table is later dropped using DROP TABLE. What happens to the underlying data files?

A.The data files remain in the managed storage location and can be re-registered later.
B.The data files are deleted after the default retention period of 30 days.
C.The data files are deleted from the managed storage location.
D.The data files are moved to a recycle bin and can be restored by an account admin.
AnswerC

Dropping a Unity Catalog managed table removes both the metadata and the underlying data files from the managed storage location. This is a key distinction from external tables, where only metadata is removed. The deletion is part of the managed lifecycle and happens automatically, so the data is no longer accessible via the table or directly in storage.

Why this answer

In Unity Catalog, managed tables have their data lifecycle controlled by the metastore. When you drop a managed table, the system deletes the data files from the managed storage location. This contrasts with external tables, where the data remains in the external location.

Understanding this behavior is critical for data retention and cost management, as dropping a managed table permanently removes the data.

Exam trap

The trap here is assuming that dropping a managed table behaves like dropping an external table, where data files persist in the external location.

24
MCQmedium

A data engineer needs to grant a group `data_consumers` the ability to query a view `prod.reporting.sales_summary` that is defined on top of tables in the same catalog. The group currently has no privileges on the underlying tables. What is the minimum set of privileges the engineer must grant to `data_consumers` so they can query the view successfully?

A.Grant `ALL PRIVILEGES` on the view and `USE SCHEMA` on `reporting`.
B.Grant `SELECT` on the view, plus `USE CATALOG` on `prod` and `USE SCHEMA` on `reporting`.
C.Grant `SELECT` on the view and `SELECT` on the underlying tables.
D.Grant `SELECT` on the view and `BROWSE` on the underlying tables.
AnswerB

To query a view, a user needs `SELECT` on the view and `USE CATALOG` and `USE SCHEMA` on the containing catalog and schema. Unity Catalog views run with the view owner's rights for referenced tables, so no direct privileges on underlying tables are needed. This is the minimum required set.

Why this answer

In Unity Catalog, views execute with the view owner's privileges for referenced objects, so consumers do not need direct privileges on underlying tables. The minimum required set is `SELECT` on the view, `USE CATALOG` on the containing catalog, and `USE SCHEMA` on the containing schema. This allows querying while adhering to least privilege.

Exam trap

The trap here is assuming that consumers need `SELECT` on underlying tables, when Unity Catalog views use the owner's privileges for referenced objects.

25
MCQmedium

An organization requires that all data access logs across multiple Databricks workspaces be captured and sent to a centralized security information and event management (SIEM) system. Which Databricks feature should be configured to capture these audit events?

A.Enable Spark event logs in the cluster configuration UI for every running compute cluster.
B.Configure diagnostic log delivery to stream account and workspace audit logs to cloud storage or event hubs.
C.Run a nightly notebook that queries the system.information schema for active user sessions.
D.Install a Python logging package on every cluster driver node to intercept SQL queries.
AnswerB

Diagnostic log delivery streams account and workspace audit logs to cloud storage or event hubs, giving the centralised feed the SIEM requires. This directly satisfies the requirement to capture audit events across multiple workspaces into one security information and event management system.

Why this answer

Databricks audit logs capture workspace-level and account-level user activities, including data access, administrative actions, and permission changes. Organizations configure audit log delivery to route these JSON event logs directly to cloud storage buckets, where SIEM tools like Splunk or Datadog can ingest and analyze them for compliance.

Exam trap

Candidates often confuse cluster logs or driver logs with audit logs, forgetting that compliance and security event tracking for SIEM ingestion require diagnostic log delivery configurations.

26
MCQhard

A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The S3 bucket policy grants access to an IAM role. The data engineer creates a storage credential with that IAM role's ARN. However, when attempting to create an external location using this storage credential, the operation fails with an error indicating insufficient permissions. The data engineer verifies that the IAM role has the correct S3 permissions. What is the most likely cause of the failure?

A.The S3 bucket policy does not grant the necessary permissions to the IAM role.
B.The storage credential was created without the `READ FILES` privilege on the S3 bucket.
C.The storage credential was created without the `CREATE EXTERNAL LOCATION` privilege on the metastore.
D.The IAM role's trust policy does not allow the Databricks AWS account to assume the role.
AnswerD

For Databricks to use the IAM role specified in the storage credential, the role's trust policy must allow the Databricks AWS account (or the Unity Catalog service principal) to assume it. If the trust policy is missing or incorrect, Databricks cannot assume the role, leading to insufficient permissions when creating the external location. This is a common misconfiguration.

Why this answer

When creating a storage credential, Databricks must be able to assume the IAM role. This requires a trust relationship between the IAM role and the Databricks AWS account. Even if the role has correct S3 permissions, without a proper trust policy, Databricks cannot assume the role, causing external location creation to fail.

The trust policy is a separate configuration from permissions.

Exam trap

The trap here is focusing on S3 bucket permissions or Unity Catalog privileges while overlooking the IAM trust relationship required for role assumption.

27
Multi-Selecthard

A data engineering team must implement dynamic row-level filtering on a customer analytics table in Unity Catalog so that regional analysts only view records corresponding to their assigned territory. Which TWO steps are required to achieve this using Unity Catalog features? (Choose 2)

Select 2 answers
A.Create a SQL user-defined function (UDF) that returns a boolean expression evaluating user identity and territory.
B.Apply the custom SQL UDF as a row filter to the target table using the ALTER TABLE command.
C.Modify the underlying cloud storage bucket IAM policy to restrict read access based on user session tags.
D.Create separate physical views for each regional analyst group and grant SELECT privileges exclusively on those views.
E.Configure cluster-level Spark configurations to automatically inject WHERE clauses into user queries.
AnswersA, B

Unity Catalog row filters are applied as a SQL user-defined function returning a boolean expression. The UDF evaluates the caller's identity against their assigned territory, so regional analysts only see matching rows, satisfying the stem's dynamic row-level filtering requirement.

Why this answer

Implementing row-level security in Unity Catalog requires creating a SQL user-defined function that evaluates the current user's identity or group membership against a territory mapping table, and then applying that function to the target table using an ALTER TABLE command.

Exam trap

Candidates often select manual table duplication or standard view definitions instead of combining a custom SQL UDF with the ALTER TABLE row filter command for dynamic filtering.

28
MCQeasy

A data engineer needs to ensure that all queries against a Unity Catalog table are logged for audit purposes. The logs must include the user identity, the query text, and the timestamp. Which Databricks feature should be enabled to capture this information?

A.Query history
B.Unity Catalog data lineage
C.Delta Live Tables event log
D.Audit logs
AnswerD

Audit logs in Databricks capture detailed information about user activities, including query text, user identity, and timestamps. They are designed for security and compliance auditing. Enabling audit logs and delivering them to a central location satisfies the requirement to log all queries against Unity Catalog tables. This is the correct feature to use.

Why this answer

Audit logs are the Databricks feature designed to capture detailed activity logs, including query text, user identity, and timestamps. They are essential for security auditing and compliance. Enabling audit logs and configuring delivery to a central system meets the requirement to log all queries against Unity Catalog tables.

Exam trap

The trap here is confusing query history, which is user-facing and limited, with audit logs, which are comprehensive and intended for security auditing.

29
MCQhard

A data engineer has configured a storage credential in Unity Catalog to access an AWS S3 bucket. The credential uses an IAM role with a trust policy that allows Databricks to assume it. The engineer now needs to ensure that only a specific set of users can create external tables pointing to that S3 bucket. Which Unity Catalog object should be used to control this access?

A.Catalog
B.Metastore
C.External location
D.Storage credential
AnswerC

An external location in Unity Catalog combines a storage path with a storage credential. By granting privileges on an external location, you control which users can create external tables that reference that path. This is the correct object to restrict table creation to specific users. The engineer should create an external location for the S3 bucket and grant CREATE EXTERNAL TABLE or other relevant privileges to the desired users.

Why this answer

An external location in Unity Catalog associates a cloud storage path with a storage credential. By granting privileges on the external location, administrators control which users can create external tables that reference that path. This provides the necessary granularity to restrict table creation to a specific set of users for a given S3 bucket.

Exam trap

The trap here is confusing the storage credential, which authenticates to storage, with the external location, which governs user access to storage paths for table creation.

30
Multi-Selectmedium

Which THREE of the following represent core security principles enforced by Unity Catalog?

Select 3 answers
A.Centralized access control
B.Unified audit logging
C.Data lineage tracking
D.Direct cloud storage access via IAM
E.Workspace-specific metastores
AnswersA, B, C

Unity Catalog provides a single point of control for managing permissions across all tables, schemas, and catalogs. This centralization eliminates the need for managing separate security policies in multiple workspaces, thereby reducing the risk of misconfiguration and ensuring consistent compliance with organizational data access policies and security standards.

Why this answer

Unity Catalog simplifies security by moving away from cloud-specific credential management to a unified identity-based model. By centralizing access control, audit logs, and data lineage, it ensures consistent security posture across all Databricks workspaces. This consolidation reduces the complexity of managing disparate security policies, ensuring that governance is applied uniformly and that administrators can easily monitor and report on data access across the entire data estate.

Exam trap

Candidates often include legacy Hive metastore characteristics or workspace-local security settings, missing that Unity Catalog centralizes security, auditing, and lineage globally across workspaces.

31
MCQeasy

A data engineer is asked to ensure that all queries against a Unity Catalog table are recorded for auditing, including the identity of the user and the query text. Which Databricks feature should the engineer enable to capture this information?

A.Enable Unity Catalog metastore-level lineage tracking to record all query statements.
B.Enable audit logs at the workspace level and configure delivery to a cloud storage location.
C.Configure a cluster log delivery to a DBFS path and parse the logs for query text.
D.Enable table access control (legacy) on the cluster to log all table reads.
AnswerB

Audit logs record events such as query execution, user identity, and access to Unity Catalog objects. Enabling audit logs and delivering them to cloud storage provides the required traceability for compliance. This is the standard mechanism for capturing query activity across a workspace.

Why this answer

Audit logs in Databricks capture detailed events including query execution, user identity, and access to Unity Catalog objects. Delivering these logs to cloud storage or a SIEM allows security teams to review and retain records for compliance. This is the appropriate feature for recording queries against Unity Catalog tables.

Exam trap

The trap here is confusing lineage tracking with auditing, when lineage records dependencies rather than user activity and query text.

32
MCQmedium

A data engineer needs to share a Delta table managed by Unity Catalog with external partners who do not have access to the Databricks workspace. Which feature should be used to securely grant read-only access to this table without replicating the data?

A.Configure cross-account IAM role assumption to grant direct AWS S3 bucket read permissions to the external partners.
B.Set up a Databricks SQL endpoint and create individual workspace user accounts for every external partner.
C.Create a Delta Sharing share, add the table to the share, and grant access to a recipient object configured for the partners.
D.Export the Delta table to CSV format and upload the files to an external SFTP server on a nightly schedule.
AnswerC

Delta Sharing is an open protocol that lets recipients read shared tables through a recipient object without workspace access or data replication. This satisfies the constraint of secure read-only external sharing while keeping a single governed copy.

Why this answer

Delta Sharing is an open protocol for secure data sharing that allows organizations to share data directly from cloud storage without copying files. Unity Catalog integrates natively with Delta Sharing, enabling governance teams to manage access for external recipients securely using tokens and activation links, making it the ideal solution for cross-organization data collaboration.

Exam trap

Candidates often confuse Delta Sharing with standard workspace sharing or assume external partners need Databricks workspace accounts. Delta Sharing uses open protocols and recipient objects, removing the requirement for shared workspaces.

33
MCQmedium

What is the primary role of a 'Metastore Admin' in a Databricks Unity Catalog environment?

A.Creating and managing workspace-level notebooks.
B.Managing users and groups in the identity provider.
C.Managing permissions and resources at the catalog level.
D.Running cluster maintenance and patching.
AnswerC

The Metastore Admin manages all Unity Catalog resources. They have the authority to grant permissions, manage storage credentials, and create catalogs. This central control is fundamental for the security model, as it ensures there is always an owner with the necessary power to audit and control access.

Why this answer

The Metastore Admin is the highest-level security role within the Unity Catalog architecture. They possess full control over the metastore, including the ability to grant and revoke access to all objects, create catalogs, and manage storage credentials. This role is crucial for establishing the initial governance structure and delegating permissions to lower-level administrators while maintaining ultimate authority over the organization's entire data inventory and access security policies.

Exam trap

Test-takers frequently confuse the Metastore Admin role with standard workspace admins or account admins, overlooking that metastore admins govern top-level metastore resources and catalog permissions.

34
MCQmedium

What must be configured to allow Databricks to access cloud storage on behalf of a user without the user needing to provide their own cloud credentials?

A.Credential Passthrough
B.Storage Credential
C.Table ACLs
D.Instance Profiles
AnswerB

Storage credentials are the fundamental objects in Unity Catalog that manage cloud-provider access. They hold the necessary permissions for Databricks to interact with cloud storage, allowing administrators to centralize and secure the connection without exposing sensitive cloud keys or requiring users to manage their own cloud identities.

Why this answer

A storage credential acts as a secure wrapper around cloud-provider authentication (like an IAM role or service account). By creating a storage credential in Unity Catalog, the administrator gives Databricks the permission to access the storage. Users then interact with 'External Locations' that reference these credentials, effectively decoupling user identity from raw cloud infrastructure access, which is the cornerstone of Unity Catalog's secure data governance model.

Exam trap

Candidates confuse 'Storage Credential' with 'External Location' or 'Access Connector,' failing to identify the specific object that stores the cloud provider authentication used by Databricks to access storage.

35
MCQmedium

Refer to the exhibit. An organization needs to ensure that members of the 'analyst_group' can only view data where the region column equals 'US'. Based on the provided configuration, what is the best approach to implement this in Unity Catalog?

A.Apply the policy directly to the table using an ALTER TABLE command.
B.Create a Dynamic View with a WHERE clause and grant SELECT access to the view.
C.Use the GRANT FILTER command to apply the condition to the analyst_group.
D.Enable Column-Level Security in the Unity Catalog metastore settings.
AnswerB

Dynamic Views are the standard method for row-level and column-level security. By embedding the filter condition into the view definition, you ensure that any user querying the view only sees rows that satisfy the predicate, effectively masking data that does not meet the specified security criteria.

Why this answer

To implement row-level security in Databricks, developers use Dynamic Views. By defining a view that contains a filter clause, you can restrict which rows are returned to the user based on their context or group membership. This ensures that sensitive data is hidden at query time without physically duplicating data or creating multiple siloed tables for different regions.

Exam trap

Candidates often mistake standard table filtering or static views for row-level security solutions, overlooking that dynamic views use user-context functions to restrict rows dynamically at query time.

36
MCQmedium

Which THREE of the following are benefits of using Unity Catalog over the legacy Hive Metastore?

A.Support for data lineage at the column level.
B.Single control plane for multiple workspaces.
C.Automated data replication to other cloud vendors.
D.Centralized auditing and monitoring for all access.
E.Automatic hardware upgrades for all clusters.
AnswerA, B, D

Unity Catalog tracks data movement and transformations automatically. This column-level lineage is invaluable for debugging data pipelines, ensuring regulatory compliance, and understanding the impact of changes to downstream reports and dashboards, which was not natively available in the legacy Hive Metastore architecture.

Why this answer

Unity Catalog provides a unified, centralized governance layer that spans all workspaces, clouds, and regions. Unlike the legacy Hive Metastore, which is often siloed and lacks granular control, Unity Catalog offers robust auditing, data lineage, and simplified access management. These features are vital for modern enterprises managing complex, multi-workspace environments that require consistent security postures and comprehensive visibility into data movement and usage patterns.

Exam trap

Candidates often include 'increased query performance' as a benefit of Unity Catalog, which is incorrect; Unity Catalog is for governance and security, not a tool for optimizing raw query execution speed.

37
MCQmedium

A data engineer has a Unity Catalog table named `sales.raw.orders` that contains a column `credit_card` with sensitive data. The security team requires that users in the `analyst` group see only the last four digits of the credit card number when querying this table, while all other users with appropriate privileges see the full value. The data engineer wants to implement this with minimal disruption to existing queries. Which approach should the data engineer take?

A.Use a column mask function with Unity Catalog to apply row-level filtering based on the user's group membership.
B.Create a row filter on the table that restricts analysts to rows where the credit card number ends with certain digits, and grant them access to the table.
C.Apply a column mask function to the `credit_card` column that checks if the user is in the `analyst` group and, if so, returns only the last four digits.
D.Create a dynamic view that applies a masking function to the `credit_card` column, and grant the `analyst` group access to the view instead of the table.
AnswerC

Unity Catalog supports column masks, which are functions that transform column values at query time based on the invoking user's identity. By applying a mask that checks group membership, analysts see masked data while others see full values. This satisfies the requirement without changing existing queries or table references.

Why this answer

Unity Catalog column masks allow dynamic data masking at query time without altering the underlying data or requiring separate views. A mask function can evaluate the current user's group memberships and return a transformed value, such as the last four digits. This meets the security requirement while preserving existing queries and access patterns.

Exam trap

The trap here is confusing column masks with row filters, or assuming that a view is required to implement dynamic masking.

38
Multi-Selecthard

A data engineer is configuring Unity Catalog row-level security on a table `prod.finance.transactions`. They want to ensure that users in the `us_team` group can only see rows where `region = 'US'`, while users in the `eu_team` group can only see rows where `region = 'EU'`. They create a row filter function `prod.security.region_filter`. Which TWO statements accurately describe how to implement and manage this row-level security? (Choose two.)

Select 2 answers
A.Row filters can only be applied to external tables, not managed tables, because managed tables do not support fine-grained access control.
B.The row filter function must accept the column(s) as parameters and return a BOOLEAN value indicating whether the row should be visible.
C.The row filter function must be defined in the same schema as the table it protects.
D.Apply the row filter using: ALTER TABLE prod.finance.transactions SET ROW FILTER prod.security.region_filter ON (region);
E.Users with the MODIFY privilege on the table automatically bypass the row filter and see all rows.
AnswersB, D

Unity Catalog row filter functions are SQL UDFs that take one or more column values as input and return a boolean. The function evaluates to TRUE for rows the user is allowed to see. It can reference the current user or group via functions like is_account_group_member(), enabling dynamic filtering based on identity.

Why this answer

Row-level security in Unity Catalog is implemented by attaching a row filter function to a table using ALTER TABLE ... SET ROW FILTER. The function receives column values and returns a boolean, often using identity functions to filter based on group membership.

Both managed and external tables support row filters, and bypassing them requires the BYPASS ROW FILTER privilege.

Exam trap

The trap here is thinking that MODIFY privilege bypasses row filters or that row filters are limited to external tables, when in fact a dedicated BYPASS ROW FILTER privilege is required and both table types support filters.

39
MCQhard

Refer to the exhibit. A data engineer is configuring an IAM policy for a Databricks storage credential. Which of the following is the most significant security risk in this configuration?

A.The policy restricts access to only a single file.
B.The policy lacks an explicit 'Deny' statement for all other resources.
C.The policy allows access to all objects in the bucket rather than using specific prefixes.
D.The policy is missing a condition to require multi-factor authentication (MFA).
AnswerC

Granting access to the entire bucket via 'arn:aws:s3:::my-bucket/*' is a significant risk. If multiple datasets or environments share a bucket, any cluster using this policy could potentially read or list data it is not authorized to access. Scoping policies to specific prefixes is a mandatory security best practice.

Why this answer

The policy uses overly permissive resource definitions and potentially excessive actions if not scoped correctly. In production environments, adhering to the principle of least privilege is critical. Granting broad 's3:ListBucket' or 's3:GetObject' access to an entire bucket without specific prefix scoping can lead to data exfiltration risks or unauthorized access to non-production data stored in the same bucket.

Exam trap

Candidates often ignore the scope of the IAM policy, failing to realize that granting access to an entire bucket rather than a specific prefix violates the principle of least privilege.

40
MCQhard

Which of the following best describes the purpose of 'Credential Passthrough' in Databricks?

A.It allows a Databricks cluster to automatically scale based on storage latency.
B.It enables users to access cloud storage using their own identity rather than the cluster's service principal.
C.It encrypts data in transit between the Databricks workspace and the cloud storage.
D.It forces all notebook users to use a single shared service principal for security.
AnswerB

This feature maps the identity of the user running a notebook or job to the storage access request. Instead of the cluster using a single shared service principal, each user's individual permissions are applied, ensuring that the cloud provider's access logs accurately reflect individual user actions during query execution.

Why this answer

Credential Passthrough allows users to authenticate to cloud storage using their own identity from the Databricks environment. By passing the user's credentials to the storage layer, Databricks ensures that the storage provider enforces access policies, creating a seamless audit trail and simplifying security management in environments that require strict alignment between user access in Databricks and direct cloud storage access.

Exam trap

Candidates often confuse Credential Passthrough with instance profiles, mistakenly believing it allows the cluster to use a single shared administrative service principal for all users instead of individual user identities.

41
MCQeasy

Which security feature in Databricks allows administrators to mask sensitive data, such as email addresses or social security numbers, in query results based on user-defined functions?

A.Row-Level Security
B.Dynamic Data Masking
C.Table ACLs
D.Workspace-level isolation
AnswerB

Dynamic Data Masking allows you to apply a masking function to columns, ensuring that users only see redacted or transformed versions of sensitive data. This is the precise feature designed to protect PII, such as emails or IDs, while still allowing data analysis on the non-sensitive parts.

Why this answer

Dynamic Data Masking allows you to define a masking function that hides or transforms data based on the user's role. By applying these functions to specific columns in a view or table, sensitive information is obscured in the results returned to the user, providing an effective way to maintain compliance with data privacy regulations like GDPR or HIPAA.

Exam trap

Candidates confuse static table partitioning or column dropping with Dynamic Data Masking, which obscures sensitive field values on-the-fly based on user identity.

42
MCQeasy

What is the primary function of an 'Access Connector' for Azure Databricks when using Unity Catalog?

A.It acts as a firewall between the Databricks workspace and the public internet.
B.It allows Databricks to access storage without managing account keys directly.
C.It automatically scales the compute resources of the cluster.
D.It provides a user interface for browsing the storage account content.
AnswerB

The Access Connector enables managed identity authentication, which is the most secure way to connect Databricks to ADLS. By leveraging Azure Active Directory (now Microsoft Entra ID) identities, it removes the need for managing sensitive storage keys, which are prone to leaks and difficult to rotate securely across large teams.

Why this answer

An Access Connector is a dedicated Azure resource that provides a secure, identity-based bridge between Unity Catalog and Azure Data Lake Storage (ADLS). It manages the identity used by Databricks to read and write data, ensuring that Unity Catalog can enforce access policies without requiring the storage account keys to be shared directly with users or hard-coded into notebooks.

Exam trap

Test-takers frequently assume the Access Connector is used for user authentication, confusing it with credential passthrough rather than recognizing it as a secure system-level bridge for Unity Catalog.

43
Multi-Selectmedium

Which TWO of the following are benefits of using Unity Catalog over the legacy Hive Metastore?

Select 2 answers
A.Unified governance across all workspaces.
B.Support for more SQL dialects.
C.Automatic data lineage for all operations.
D.Increased query performance.
E.Lower storage costs.
AnswersA, C

Unity Catalog provides a single metadata store for all workspaces in an account. This eliminates the need to synchronize metadata manually or manage disparate security configurations across different environments. It ensures a consistent view of data, which is essential for scaling data operations securely and efficiently across a large enterprise.

Why this answer

Unity Catalog represents a modern approach to data governance, solving the fragmentation caused by having separate metastores in every workspace. By providing a centralized, account-level view of all data, it enables enterprise-wide discovery, consistent security policies, and deep integration with lineage and audit features. This shift simplifies the data engineer's job by reducing configuration overhead while significantly improving the organization's security posture and audit readiness for compliance requirements.

Exam trap

Candidates often select 'improved compute performance' or 'automatic data partitioning' as benefits of Unity Catalog, which are incorrect; the primary benefits are governance, security, and centralized management.

44
MCQmedium

A data engineer is configuring Unity Catalog to allow a service principal to run a Databricks job that writes to a Delta table in an external location. The service principal has been granted USAGE on the catalog and schema, and MODIFY on the table. However, the job fails with an error indicating that the service principal cannot access the external location. What is the most likely missing privilege?

A.The service principal needs SELECT on the table.
B.The service principal needs READ FILES on the external location.
C.The service principal needs CREATE on the external location.
D.The service principal needs WRITE FILES on the external location.
AnswerD

When a table is stored in an external location, writing to it requires WRITE FILES on that external location, in addition to MODIFY on the table. Without WRITE FILES, the service principal cannot write the data files, resulting in an access error. This privilege is often overlooked when granting table-level permissions.

Why this answer

For an external table, writing data requires both MODIFY on the table and WRITE FILES on the external location. The service principal has MODIFY but lacks WRITE FILES, causing the access error. Granting WRITE FILES on the external location will allow the job to write the underlying data files.

Other privileges like SELECT, READ FILES, or CREATE do not address the write requirement.

Exam trap

The trap here is assuming that table-level MODIFY is sufficient for writes, overlooking the need for file-level privileges on the external location.

45
MCQmedium

Which identity management approach is mandatory for the implementation of Unity Catalog within a Databricks environment?

A.Workspace-local users
B.Account-level identities
C.Local SQL-only credentials
D.Personal access tokens for every user
AnswerB

Unity Catalog relies on account-level identities to manage access. This enables a single source of truth for user and group definitions, allowing administrators to apply permissions once and have them respected across all workspaces. This centralization is essential for maintaining consistent security posture and simplifying identity lifecycle management.

Why this answer

Unity Catalog requires users to be managed at the account level, rather than at the individual workspace level. This synchronization ensures that permissions and identities are consistent across all workspaces in the account, which is a fundamental requirement for the unified governance model that Unity Catalog provides to the Databricks platform.

Exam trap

Candidates often assume legacy workspace-level user management is sufficient, overlooking Unity Catalog's strict requirement for centralized account-level identities.

46
MCQeasy

A data engineer needs to ensure that only members of the 'finance' group can view a specific column containing credit card numbers in a Unity Catalog table. Which feature should be used?

A.Column-level privileges with GRANT SELECT ON COLUMN
B.Row-level security with filter conditions
C.Dynamic views with CASE statements
D.Column masks
AnswerD

Column masks in Unity Catalog allow you to apply a masking function to a column so that users see either the actual value or a masked value based on their group membership. This is the precise feature for restricting access to specific columns. You can define a mask that returns the actual value for the 'finance' group and a masked value for others.

Why this answer

Column masks are designed to control access to specific columns by applying a masking function that evaluates the user's identity or group membership. This allows sensitive data like credit card numbers to be visible only to authorized groups. Other features like row-level security or dynamic views address different aspects of data access and are not the direct solution for column-level control.

Exam trap

The trap here is confusing column-level security with row-level security, or assuming that column-level privileges can be granted directly.

Ready to test yourself?

Try a timed practice session using only Governance and Security questions.