Courseiva
Data Governance →mediumMultiple Choice

Databricks-DE-Pro Data Governance Practice Question

A data engineer is configuring a Unity Catalog metastore to use a customer-managed key (CMK) for encryption at rest. The engineer has created the necessary Key Vault and key in Azure. Which additional configuration is required to enable CMK for the metastore?

⚠ Common exam trap

Candidates often confuse the access connector identity with the metastore managed identity, or assuming network configurations like private endpoints are required for CMK.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the Key Vault Crypto Service Encryption User role to the Databricks managed identity used for the metastore.

Unity Catalog CMK for Azure requires that the Databricks managed identity for the metastore has the Key Vault Crypto Service Encryption User role on the Key Vault. This role allows Databricks to perform wrap and unwrap operations with the key. Without this role assignment, the metastore cannot use the CMK for encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a private endpoint for the Key Vault.

    Why it's wrong here

    A private endpoint secures network access to the Key Vault but is not required for CMK encryption. CMK configuration focuses on permissions and key policies, not network isolation. Private endpoints are for enhanced security but not a prerequisite for CMK.

  • ✓

    Assign the Key Vault Crypto Service Encryption User role to the Databricks managed identity used for the metastore.

    Why this is correct

    To use CMK for Unity Catalog metastore encryption, you must grant the Databricks managed identity (the one associated with the metastore) the Key Vault Crypto Service Encryption User role on the Key Vault. This allows Databricks to use the key for encrypting the metastore's data.

  • ✗

    Grant the Databricks access connector the Key Vault Crypto Service Encryption User role.

    Why it's wrong here

    The access connector is used for data access, not for CMK encryption. For CMK, the Databricks first-party service principal or managed identity needs permissions on the Key Vault. Granting the access connector this role does not enable CMK for the metastore.

  • ✗

    Enable soft delete on the Key Vault.

    Why it's wrong here

    Soft delete is a data protection feature that allows recovery of deleted keys, but it is not required for CMK configuration. While it is a best practice, it does not grant the necessary permissions for Databricks to use the key.

About these practice questions

Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.