Courseiva
Governance and Security →mediumMultiple Choice

Databricks-DE-Assoc Governance and Security Practice Question

What must be configured to allow Databricks to access cloud storage on behalf of a user without the user needing to provide their own cloud credentials?

⚠ Common exam trap

Candidates confuse 'Storage Credential' with 'External Location' or 'Access Connector,' failing to identify the specific object that stores the cloud provider authentication used by Databricks to access storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Storage Credential

A storage credential acts as a secure wrapper around cloud-provider authentication (like an IAM role or service account). By creating a storage credential in Unity Catalog, the administrator gives Databricks the permission to access the storage. Users then interact with 'External Locations' that reference these credentials, effectively decoupling user identity from raw cloud infrastructure access, which is the cornerstone of Unity Catalog's secure data governance model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Credential Passthrough

    Why it's wrong here

    Credential passthrough is a legacy feature that maps a user's cloud identity to the cluster. This is the opposite of the Unity Catalog model, where you want to remove the need for users to have direct cloud access. Unity Catalog uses storage credentials to abstract this complexity away from users.

  • ✓

    Storage Credential

    Why this is correct

    Storage credentials are the fundamental objects in Unity Catalog that manage cloud-provider access. They hold the necessary permissions for Databricks to interact with cloud storage, allowing administrators to centralize and secure the connection without exposing sensitive cloud keys or requiring users to manage their own cloud identities.

  • ✗

    Table ACLs

    Why it's wrong here

    Table ACLs manage access to objects within a database, not the connection to the underlying cloud storage itself. They are a legacy security feature that does not provide the capability to abstract cloud-level authentication in the way that Unity Catalog storage credentials and external locations do.

  • ✗

    Instance Profiles

    Why it's wrong here

    Instance profiles are attached to clusters to give the cluster itself permission to access storage. While they work, Unity Catalog's storage credential approach is more granular and secure, as it allows for managing access at the catalog and location level rather than globally for the entire cluster compute environment.

About these practice questions

This Databricks-DE-Assoc question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.