Courseiva

Databricks-DE-Pro Data Security and Compliance Practice Question

A data engineer is implementing fine-grained access control on a Delta table in Unity Catalog that contains sensitive customer data. The requirement is to mask the `credit_card` column for all users except members of the `finance` group, and to filter out rows where the `region` column is not in the user's allowed regions. Which two Unity Catalog features should the engineer use? (Choose two.)

⚠ Common exam trap

The trap here is assuming that table ACLs support column-level grants, when Unity Catalog achieves column-level security through column masks or views, not through GRANT on individual columns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Row filter using a SQL UDF that checks the user's allowed regions against the `region` column.

Unity Catalog provides native row filters and column masks for fine-grained access control. A column mask with a SQL UDF can conditionally reveal or obscure the credit card column based on group membership, while a row filter with a SQL UDF can restrict rows by region. Together they implement the required masking and filtering directly on the table without requiring a separate view.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Table ACLs that grant SELECT only on specific columns.

    Why it's wrong here

    Unity Catalog does not support column-level grants in the GRANT statement. While you can grant SELECT on a table, you cannot restrict which columns a user sees via table ACLs. Column-level security is achieved through column masks or by exposing a view with a subset of columns, so this option does not meet the masking requirement.

  • ✗

    Workspace-level IP access list to restrict access to the table.

    Why it's wrong here

    IP access lists control network origins for workspace access, not row or column visibility within a table. They cannot mask a column or filter rows based on a user's region. This feature addresses a different security concern and does not satisfy the fine-grained data access requirements described.

  • ✓

    Row filter using a SQL UDF that checks the user's allowed regions against the `region` column.

    Why this is correct

    Row filters in Unity Catalog apply a SQL UDF that evaluates per row and returns a boolean, allowing you to restrict which rows are visible. This is the correct feature to filter out rows where the `region` is not in the user's allowed regions, based on the invoking user's identity or group membership.

  • ✗

    Dynamic view that joins the table with a mapping table of user regions.

    Why it's wrong here

    A dynamic view can implement row-level filtering and column masking, but it is a separate object that users query instead of the base table. The scenario asks for fine-grained access control on the Delta table itself, and using a view would not apply the policies directly to the table. Unity Catalog's native row filters and column masks are the intended features here.

  • ✓

    Column mask using a SQL UDF that returns the masked value unless the user is in the `finance` group.

    Why this is correct

    Column masks in Unity Catalog allow you to apply a SQL user-defined function to a column so that the returned value depends on the invoking user or group. This is the correct mechanism to conditionally mask the `credit_card` column for everyone except members of the `finance` group, while still allowing finance users to see the real values.

About these practice questions

One of 267 original Databricks-DE-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.