Courseiva

Databricks-DE-Pro Data Security and Compliance Practice Question

A Data Engineer is implementing column-level security on a Unity Catalog table `sales.customers` that contains `email`, `ssn`, and `region` columns. The requirement is that analysts in the `analyst` group see only the last four digits of `ssn` and a hashed `email`, while members of the `compliance` group see full values. The engineer plans to use column masks. Which TWO actions are required to meet the requirement? (Choose two.)

⚠ Common exam trap

The trap here is treating column masks as an access denial mechanism and revoking column SELECT, when masks are meant to transform values while SELECT remains granted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a masking function that inspects the invoking user's group membership and returns either the full value or a masked value.

Column masks require two things: a function that decides the returned value based on the invoking user's groups, and the ALTER TABLE statement that binds that function to each sensitive column. Together they let analysts see truncated SSN and hashed email while compliance sees full values. Revoking column SELECT breaks queries, row filters hide rows instead of transforming values, and USE SCHEMA is only a prerequisite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant the `analyst` group the `USE SCHEMA` privilege on the schema containing `sales.customers`.

    Why it's wrong here

    USE SCHEMA is a prerequisite for accessing objects in the schema, but it does not implement masking. Granting it alone leaves full values visible to analysts, violating the requirement. It is a necessary but insufficient setup step, and the question asks specifically which actions implement the column-level masking behavior, so this is not one of the required masking actions.

  • ✓

    Create a masking function that inspects the invoking user's group membership and returns either the full value or a masked value.

    Why this is correct

    A column mask function can branch on the current user's groups using functions such as `is_account_group_member`, returning the raw value for `compliance` and a masked value for everyone else. This centralizes the logic and ensures analysts receive only the truncated SSN or hashed email while compliance sees full data. Without this conditional function, the mask cannot differentiate the two groups.

  • ✓

    Apply the masking function to the `ssn` and `email` columns using ALTER TABLE ... ALTER COLUMN ... SET MASK.

    Why this is correct

    Attaching the function to each sensitive column with ALTER TABLE is what activates the mask at query time. The mask is evaluated per row and per invoking user, so the same table returns different values depending on group membership. Applying it to both `ssn` and `email` covers the two columns the requirement names, and the `region` column is left unmasked as intended.

  • ✗

    Revoke SELECT on the `ssn` and `email` columns from the `analyst` group before applying the mask.

    Why it's wrong here

    Revoking SELECT on the columns would prevent analysts from querying them at all, including the masked forms, which defeats the purpose of returning a partial SSN or hashed email. Column masks are designed to work alongside SELECT, transforming values rather than blocking access. Revoking the privilege would produce errors instead of masked output and does not satisfy the requirement.

  • ✗

    Create a row filter function that returns TRUE only for rows where the user belongs to the `compliance` group.

    Why it's wrong here

    A row filter hides entire rows, not individual column values. Applying it would cause analysts to see zero rows rather than masked SSN and email values, which is stricter than requested and breaks their legitimate analysis on `region`. The requirement is column-level transformation, so a row filter is the wrong control here.

About these practice questions

This Databricks-DE-Pro question is part of Courseiva's 267-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.