Courseiva

Databricks-DE-Pro Data Security and Compliance Practice Question

A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The organization's security policy requires that Databricks assumes an IAM role, and that no long-lived AWS access keys are stored in Databricks. The engineer has created an IAM role with a trust policy and an external ID. Which action must the engineer take to complete the storage credential configuration in Unity Catalog?

⚠ Common exam trap

The trap here is thinking that an instance profile or a Databricks service principal can serve as a Unity Catalog storage credential for S3, when the supported method is an IAM role with a trust policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Specify the IAM role ARN and the external ID in the storage credential, and ensure the role's trust policy allows the Databricks AWS account to assume it.

For Unity Catalog to access S3 without long-lived AWS keys, a storage credential must reference an IAM role that Databricks assumes. The role's trust policy must permit the Databricks AWS account to assume it, and an external ID can be used to prevent the confused deputy problem. This design centralizes credential management and avoids storing static keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Specify the IAM role ARN and the external ID in the storage credential, and ensure the role's trust policy allows the Databricks AWS account to assume it.

    Why this is correct

    Unity Catalog storage credentials for S3 use an IAM role that Databricks assumes. The credential stores the role ARN, and the trust policy must allow the Databricks AWS account principal to assume the role, optionally with an external ID for confused deputy protection. This meets the no-long-lived-keys requirement and is the standard secure configuration.

  • ✗

    Provide the AWS access key ID and secret access key of an IAM user that has permissions to the S3 bucket.

    Why it's wrong here

    Storing long-lived IAM user access keys in a storage credential violates the requirement to avoid long-lived AWS credentials. Unity Catalog supports IAM role assumption precisely to avoid this. Providing access keys would also make rotation and auditing more difficult and does not leverage the external ID already configured in the trust policy.

  • ✗

    Attach an instance profile to the cluster and grant the cluster's IAM role access to the S3 bucket, then create the storage credential without an IAM role.

    Why it's wrong here

    Instance profiles are used for cluster-level access to data in the classic data plane, but Unity Catalog storage credentials are not based on instance profiles. Unity Catalog requires a storage credential that encapsulates the IAM role. Relying on an instance profile would bypass Unity Catalog's centralized access control and audit logging for the storage location.

  • ✗

    Configure a service principal in Databricks, assign it the S3 bucket policy, and use its client ID and secret as the storage credential.

    Why it's wrong here

    A Databricks service principal is an identity within Databricks, not an AWS IAM entity. It cannot be directly granted S3 bucket permissions. Using its client ID and secret as a storage credential is not a supported mechanism; storage credentials must reference an AWS IAM role for S3 access, with the trust relationship configured on the AWS side.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This Databricks-DE-Pro question is part of Courseiva's 267-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.