Databricks-DE-Assoc Governance and Security Practice Question
Exhibit
{
"type": "access_control_policy",
"principal": "analyst_group",
"action": "SELECT",
"condition": "WHERE region = 'US'"
}Refer to the exhibit. An organization needs to ensure that members of the 'analyst_group' can only view data where the region column equals 'US'. Based on the provided configuration, what is the best approach to implement this in Unity Catalog?
⚠ Common exam trap
Candidates often mistake standard table filtering or static views for row-level security solutions, overlooking that dynamic views use user-context functions to restrict rows dynamically at query time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Dynamic View with a WHERE clause and grant SELECT access to the view.
To implement row-level security in Databricks, developers use Dynamic Views. By defining a view that contains a filter clause, you can restrict which rows are returned to the user based on their context or group membership. This ensures that sensitive data is hidden at query time without physically duplicating data or creating multiple siloed tables for different regions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the policy directly to the table using an ALTER TABLE command.
Why it's wrong here
Databricks does not support applying access control policies directly to raw tables via an ALTER TABLE command. Instead, you must create a separate view object that encapsulates the filtering logic, allowing you to grant users access to the view while keeping the raw underlying table restricted.
- ✓
Create a Dynamic View with a WHERE clause and grant SELECT access to the view.
Why this is correct
Dynamic Views are the standard method for row-level and column-level security. By embedding the filter condition into the view definition, you ensure that any user querying the view only sees rows that satisfy the predicate, effectively masking data that does not meet the specified security criteria.
- ✗
Use the GRANT FILTER command to apply the condition to the analyst_group.
Why it's wrong here
There is no 'GRANT FILTER' command in Databricks SQL or Unity Catalog syntax. Access control is managed through the GRANT/REVOKE pattern, and row-level filtering must be implemented logically through the design of views rather than through an administrative filtering command applied to user roles.
- ✗
Enable Column-Level Security in the Unity Catalog metastore settings.
Why it's wrong here
While Unity Catalog supports column-level masking, the request specifically asks to filter rows based on a condition, not just mask columns. Enabling settings is insufficient; you must implement the logic using SQL, specifically through a view that evaluates the WHERE clause at execution time.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.