Courseiva
Data Governance →easyMultiple Choice

Databricks-DE-Pro Data Governance Practice Question

A data engineer is asked to implement column-level masking for a Unity Catalog table `main.hr.employees` that contains a column `ssn` with Social Security numbers. The requirement is that only members of the `hr_group` should see the full SSN, while all other users should see only the last four digits (e.g., XXX-XX-1234). The engineer decides to use a column mask function. Which statement accurately describes how to apply the mask?

⚠ Common exam trap

The trap here is thinking that column-level grants or views can provide dynamic masking, when only a column mask function can return different values based on the user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a function that returns the masked value based on IS_MEMBER('hr_group'), then use ALTER TABLE ... ALTER COLUMN ssn SET MASK function_name.

Column masks in Unity Catalog are implemented via user-defined functions that can dynamically return different values based on the user's group membership. The function can use IS_MEMBER to check if the user is in hr_group and return either the full SSN or a masked version. The mask is attached to the column using ALTER TABLE ... ALTER COLUMN ... SET MASK. This enforces masking for all users except those in the specified group, meeting the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use row-level filters to exclude rows where the user is not in hr_group, effectively hiding sensitive data.

    Why it's wrong here

    Row-level filters restrict which rows are visible, not which column values are shown. Applying a row filter would hide entire rows for non-hr users, potentially removing all employee records, which is not the goal. The requirement is to mask the ssn column value, not to filter rows. Therefore, row-level filters are inappropriate for column masking.

  • ✗

    Create a view that selects all columns except ssn, and a separate view that includes ssn for hr_group, then grant appropriate privileges on each view.

    Why it's wrong here

    Using separate views can provide different column sets, but it does not dynamically mask the ssn column for non-hr users while still showing a masked value. The requirement is to show a masked ssn to all users, not to omit it. Moreover, managing multiple views increases complexity and does not leverage Unity Catalog's native masking capabilities. A column mask function is the intended solution.

  • ✓

    Create a function that returns the masked value based on IS_MEMBER('hr_group'), then use ALTER TABLE ... ALTER COLUMN ssn SET MASK function_name.

    Why this is correct

    Unity Catalog supports column masks via a user-defined function that dynamically returns a value based on the invoking user's group membership. The function can use IS_MEMBER to check if the user belongs to hr_group and return the full SSN or a masked version accordingly. The mask is applied using ALTER TABLE ... ALTER COLUMN ... SET MASK, which attaches the function to the column. This approach enforces the masking at query time for all users except those in the specified group.

  • ✗

    Grant SELECT on the ssn column only to hr_group, and revoke it from all other users.

    Why it's wrong here

    Column-level grants can restrict access to the entire column, but they do not allow partial masking; users either see the full column or none of it. The requirement is for other users to see a masked version, not to be denied access entirely. Therefore, column-level grants alone cannot satisfy the need for masked values. A column mask function is necessary to return transformed data based on group membership.

About these practice questions

Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.