Databricks-DE-Pro Data Security and Compliance Practice Question
A data engineer needs to ensure that PII data in a Delta table is accessible only to users in the 'HR_Manager' group. Which approach provides the most granular and scalable security implementation?
⚠ Common exam trap
Candidates often pick view-based security or access control lists (ACLs) on storage paths, missing that Unity Catalog row filters offer granular, scalable security enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a row filter function to the table using Unity Catalog.
Using Unity Catalog's Row-Level Security (RLS) via SQL functions is the standard best practice. It dynamically filters rows at query time based on the execution context, such as the current user's group membership. This approach avoids duplicating data into siloed tables, minimizes maintenance overhead, and ensures consistent enforcement across different BI tools and compute resources connecting to the same catalog.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create separate views for each group and grant access to those views.
Why it's wrong here
Creating individual views for every group leads to view sprawl and significant administrative overhead. As the organization scales, maintaining these views becomes error-prone and difficult to audit. RLS in Unity Catalog offers a centralized, scalable mechanism that eliminates the need for managing redundant, fragmented database objects.
- ✗
Implement column-level masking on the PII column.
Why it's wrong here
Masking obscures sensitive data but does not restrict access to the underlying rows. Even with masking, users might still see the existence of sensitive records. RLS is specifically designed to control row visibility, ensuring that unauthorized users cannot retrieve the rows at all, providing stronger security for sensitive PII.
- ✓
Apply a row filter function to the table using Unity Catalog.
Why this is correct
Row filters in Unity Catalog allow for defining an expression that acts as a WHERE clause. By using the 'is_account_group_member' function, you can ensure that only members of the specified HR group see rows containing PII. This is the most efficient and manageable way to enforce granular row-level data access.
- ✗
Use data partitioning to store HR data in separate folders.
Why it's wrong here
Partitioning is a performance optimization technique, not a security feature. Data stored in separate folders is still accessible to anyone with read permissions on the underlying storage location or table. Relying on physical storage layout for security is inherently insecure and violates the principle of least privilege.
About these practice questions
Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.