Databricks-DE-Assoc Governance and Security Practice Question
Which identity management approach is mandatory for the implementation of Unity Catalog within a Databricks environment?
⚠ Common exam trap
Candidates often assume legacy workspace-level user management is sufficient, overlooking Unity Catalog's strict requirement for centralized account-level identities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Account-level identities
Unity Catalog requires users to be managed at the account level, rather than at the individual workspace level. This synchronization ensures that permissions and identities are consistent across all workspaces in the account, which is a fundamental requirement for the unified governance model that Unity Catalog provides to the Databricks platform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Workspace-local users
Why it's wrong here
Unity Catalog does not support workspace-local users. All users must be defined at the account level to ensure that access control policies can be consistently applied across different workspaces connected to the same metastore. Relying on workspace-local users would create identity silos and prevent centralized governance.
- ✓
Account-level identities
Why this is correct
Unity Catalog relies on account-level identities to manage access. This enables a single source of truth for user and group definitions, allowing administrators to apply permissions once and have them respected across all workspaces. This centralization is essential for maintaining consistent security posture and simplifying identity lifecycle management.
- ✗
Local SQL-only credentials
Why it's wrong here
Unity Catalog does not use local SQL-only credentials. It integrates with your identity provider (like Microsoft Entra ID or Okta) via SCIM provisioning at the account level. Relying on local SQL users would bypass modern identity standards and prevent the integration of existing enterprise security policies into your Databricks governance.
- ✗
Personal access tokens for every user
Why it's wrong here
Personal access tokens (PATs) are used for authentication to APIs, not for identity management or Unity Catalog authorization. Identity management must be handled through an external identity provider integrated with the Databricks account. PATs are credentials, not identities, and cannot define security access in Unity Catalog.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.