Databricks-DE-Pro Data Governance Practice Question
A data engineer is designing a Unity Catalog governance model for a new data lakehouse. They need to ensure that data access is auditable and that sensitive data is protected. Which two actions should the engineer take to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is assuming that broad privileges or separate metastores provide security and auditability, when in fact they increase risk and complexity, while overlooking the native audit logging and tag-based ABAC features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable audit logging for the metastore to capture all access and permission changes.
Enabling audit logging captures all access and permission changes, providing the necessary audit trail. Applying tags to sensitive columns and using ABAC policies enforces fine-grained access control based on those tags, protecting sensitive data consistently. Together, these actions create a governance model that is both auditable and secure, leveraging Unity Catalog's native capabilities for centralized policy management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable audit logging for the metastore to capture all access and permission changes.
Why this is correct
Audit logging in Unity Catalog records detailed events such as data access, permission changes, and metadata operations. Enabling it provides the necessary audit trail to track who accessed what data and when, which is essential for compliance and security monitoring. This directly addresses the requirement for auditable data access.
- ✗
Use dynamic views to mask PII columns for all users except administrators.
Why it's wrong here
While dynamic views can mask PII, they require manual creation and maintenance for each table, which is less scalable than tag-based ABAC policies. They also do not inherently provide auditing. The requirement for auditable access is better met by audit logging, and for sensitive data protection, ABAC with tags is more centralized and less error-prone.
- ✓
Apply tags to sensitive columns and use attribute-based access control (ABAC) policies to restrict access.
Why this is correct
Tagging sensitive columns and defining ABAC policies allows centralized, policy-driven enforcement of access controls based on tags. This ensures that sensitive data is protected consistently, even as new tables are created with the same tags. It provides a scalable way to manage fine-grained access without manually granting permissions on each object.
- ✗
Create a separate metastore for each department to isolate data.
Why it's wrong here
Creating separate metastores per department increases complexity and prevents centralized governance and auditing. Unity Catalog is designed to provide a unified governance layer across the organization. Isolating metastores would fragment audit logs and make it harder to enforce consistent policies, thus not meeting the requirements for auditable and protected data access.
- ✗
Store all data in a single catalog and grant `ALL PRIVILEGES` to the data engineering team.
Why it's wrong here
Granting `ALL PRIVILEGES` to a broad group violates the principle of least privilege and does not protect sensitive data. This approach would make auditing more difficult because many users would have unrestricted access. It does not meet the requirement for protecting sensitive data and could lead to unauthorized access.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 267 original Databricks-DE-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.