Databricks-DE-Pro Data Security and Compliance Practice Question
A data engineer is tasked with ensuring that sensitive information in a 'customer' table is masked for all users except the 'Data_Science' group. What is the correct Unity Catalog feature to implement?
⚠ Common exam trap
Candidates mistakenly choose physical data duplication or static table views with restricted access rather than dynamic column masking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a masking policy using a SQL function to the table column.
Dynamic data masking in Unity Catalog allows for the creation of masking functions that return obfuscated values based on the current user's role. By assigning these functions to columns, administrators ensure that sensitive data is protected while remaining available for authorized users. This approach is highly effective for maintaining data usability without compromising the security of PII.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a view that performs a CASE statement to mask the column.
Why it's wrong here
While views can mask data, they are not the recommended approach in Unity Catalog. Managing separate views for different groups leads to object proliferation and maintenance difficulties. Dynamic masking is a native feature that allows the same table to be queried by different groups with different visibility levels.
- ✓
Apply a masking policy using a SQL function to the table column.
Why this is correct
Unity Catalog supports masking policies using SQL functions. By defining a function that checks for group membership and returns either the original or masked value, you apply a central policy. This is the official and most efficient method to handle dynamic masking requirements across the entire organization.
- ✗
Use the 'DROP COLUMN' command to remove sensitive columns.
Why it's wrong here
Dropping a column removes the data permanently for all users, which makes the data useless for the Data Science team. The requirement is to mask the data for most users, not to delete it. Masking provides the necessary balance between data protection and analytic utility for authorized users.
- ✗
Encrypt the column using an external library before writing to Delta.
Why it's wrong here
Encrypting data before storage makes it difficult to use for analytics or machine learning, as the data must be decrypted before processing. This creates performance bottlenecks and requires managing decryption keys throughout the compute pipeline. Dynamic masking is designed to handle this within the platform natively.
About these practice questions
One of 267 original Databricks-DE-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.