A data engineer is tasked with securing sensitive PII data in Unity Catalog. Which THREE actions are recommended to ensure robust security and compliance?
Dynamic Data Masking is a primary control for PII. By masking sensitive columns, you ensure that analysts can work with the data for aggregate statistics without actually seeing raw, identifiable information, which helps satisfy data privacy requirements while maintaining the utility of the dataset for authorized users.
Why this answer
Implementing a defense-in-depth strategy is crucial for PII. Using Unity Catalog's fine-grained access controls, dynamic masking, and audit logs provides a layered approach to security. These tools allow organizations to restrict access, obscure sensitive values, and maintain a verifiable trail of who accessed what data, which is essential for meeting regulatory requirements and minimizing the risk of unauthorized data breaches.
Exam trap
Candidates often select single-layer security approaches like only masking columns, ignoring that robust PII compliance requires a defense-in-depth strategy combining masking, auditing, and permissions.