Courseiva

Databricks-DE-Assoc · topic practice

Governance and Security practice questions

This domain covers Unity Catalog governance on Databricks: access control, row and column-level security, audit logging, and lineage. Questions present organizational requirements and ask you to select the correct Unity Catalog feature, privilege model, or configuration to satisfy least-privilege access and compliance needs.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Governance and Security

What the exam tests

What to know about Governance and Security

Be able to choose and configure Unity Catalog features that enforce least-privilege access: dynamic views or row filter functions for row-level security, column masks for column-level security, and audit log delivery to a SIEM. The most important thing is matching the requirement to the correct Unity Catalog mechanism.

Unity Catalog privileges: GRANT/REVOKE, catalog/schema/table hierarchy, and securable objects

Row-level security via dynamic views and row filter functions on Unity Catalog tables

Column masking using column mask functions and attribute-based access control

Audit logs and system tables for centralized SIEM ingestion and lineage tracking

Watch out for

Common Governance and Security exam traps

  • ▸Assuming table-level GRANTs alone enforce row filtering; row-level security requires dynamic views or row filter functions.
  • ▸Confusing Unity Catalog lineage with audit logs; lineage tracks data movement, audit logs capture access events.
  • ▸Granting privileges at catalog or schema level when least privilege requires table or column scope.

Practice set

Governance and Security questions

20 questions · select your answer, then reveal the explanation

An enterprise data governance team needs to ensure that junior data analysts can view customer transaction records, but their view must automatically mask the primary credit card number column. Which Unity Catalog feature accomplishes this requirement?

Which TWO of the following statements accurately describe the behavior and characteristics of managed tables versus external tables in Unity Catalog? (Choose TWO)

A data engineer needs to ensure that PII data in a 'users' table is masked for all users except those in the 'HR' group. Which Unity Catalog feature should be used to implement this requirement?

Which TWO of the following are true regarding the use of Personal Access Tokens (PATs) versus Service Principals for automated jobs in Unity Catalog?

If an organization wants to ensure that no data can be accessed unless it is explicitly granted, which Unity Catalog setting should be enforced?

Refer to the exhibit. What is the final effective permission for 'data_scientists' on the 'sensitive_data' table?

Exhibit

GRANT SELECT ON TABLE sensitive_data TO `data_scientists`;
REVOKE SELECT ON TABLE sensitive_data FROM `data_scientists`;
GRANT SELECT ON TABLE sensitive_data TO `data_scientists`;

A data engineer is configuring Unity Catalog access control. Which TWO of the following statements accurately describe how privileges are inherited or applied in the hierarchy?

Refer to the exhibit. A data engineer executes the provided commands. However, users in the 'data-analyst-group' report they still cannot query the 'main.sales.sales_data' table. What is the most likely cause?

Exhibit

GRANT SELECT ON TABLE sales_data TO `data-analyst-group`;
GRANT USE CATALOG ON CATALOG main TO `data-analyst-group`;
GRANT USE SCHEMA ON SCHEMA main.sales TO `data-analyst-group`;

Refer to the exhibit. A data engineer runs the SQL commands shown to grant table access to a group in Unity Catalog. However, members of the `finance-team` group still encounter a permission denied error when attempting to query the table. What is missing?

Exhibit

GRANT USE CATALOG ON CATALOG main TO `finance-team`;
GRANT USE SCHEMA ON SCHEMA main.silver TO `finance-team`;
GRANT SELECT ON TABLE main.silver.transactions TO `finance-team`;

A data engineer needs to grant a user permission to query a specific table in Unity Catalog without allowing them to view the underlying data definition or metadata of the schema. Which command should the engineer execute?

A Databricks administrator is configuring access control for a workspace. Which TWO statements accurately describe the behavior of Unity Catalog's security model?

Refer to the exhibit. A user is attempting to query a table located in the 'finance' catalog but receives the provided error. What is the minimum permission required to resolve this issue?

Exhibit

Error: [UNAUTHORIZED_ACCESS] User 'user@example.com' does not have USE CATALOG privilege on catalog 'finance'.

A data engineer needs to grant a group of data analysts read-only access to a specific schema named `finance_analytics` within Unity Catalog. Which SQL command correctly grants the required privileges according to Unity Catalog security standards?

A data engineer wants to grant a group 'analysts' the ability to read all current and future tables in the schema 'sales' without granting access to other schemas in the same catalog. Which SQL statement should be used?

A data engineer is designing a Unity Catalog hierarchy for a new project. The project requires that data analysts can query tables in the `finance` schema but must not be able to see or query tables in the `hr` schema. Both schemas are in the same catalog `prod`. Which two privileges should be granted to the data analysts to achieve this? (Choose two.)

A data engineer needs to allow a service principal `etl_sp` to read from an external location `s3://corp-data/raw/` in Unity Catalog. The storage credential `s3_cred` already exists and has been granted to the `etl_sp` service principal. The engineer also creates an external location `raw_loc` pointing to `s3://corp-data/raw/` and grants `READ FILES` on `raw_loc` to `etl_sp`. When `etl_sp` runs a query reading a Parquet file from that path, it fails with a permission error. What is the most likely cause?

Question 17mediummultiple choice
Study the full Python automation breakdown →

A data engineer has a Unity Catalog table named sales.orders that contains a column customer_email. The security team requires that analysts in the group 'analysts' see a masked version of customer_email (e.g., a***@example.com) when they query the table, while members of the group 'auditors' must see the full email address. The data engineer wants to implement this with minimal administrative overhead and ensure the masking is applied consistently across all query engines (SQL, Python, and Scala). Which approach should the data engineer use?

A data engineer is managing access to a Unity Catalog table `finance.transactions` that contains sensitive financial data. The table is owned by the `finance_admin` group. The data engineer needs to ensure that members of the `auditor` group can query the table but cannot modify its structure or data. Additionally, the `auditor` group should be able to grant `SELECT` privileges on the table to other users. Which two privileges should be granted to the `auditor` group to meet these requirements? (Choose two.)

A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The S3 bucket has a bucket policy that allows access only from a specific IAM role. The data engineer creates a storage credential with an IAM role ARN and then creates an external location using that storage credential. When querying a table at that external location, users receive an access denied error. The data engineer verifies that the IAM role has the correct S3 permissions and the bucket policy allows the role. What is the most likely cause of the error?

A data engineer is setting up a new Unity Catalog metastore for an organization. The organization has multiple Databricks workspaces in different regions and wants to ensure that all workspaces can access the same Unity Catalog data and governance policies. What is the correct approach to configure the metastore?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Governance and Security sessions

Start a Governance and Security only practice session

Every question in these sessions is drawn from the Governance and Security domain — nothing else.

Related practice questions

Related Databricks-DE-Assoc topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Databricks-DE-Assoc exam test about Governance and Security?
Be able to choose and configure Unity Catalog features that enforce least-privilege access: dynamic views or row filter functions for row-level security, column masks for column-level security, and audit log delivery to a SIEM. The most important thing is matching the requirement to the correct Unity Catalog mechanism.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Governance and Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Governance and Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Databricks-DE-Assoc topics?
Use the topic links above to move to related areas, or go back to the Databricks-DE-Assoc question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Databricks-DE-Assoc exam covers. They are not copied from any real exam or dump site.