Courseiva
Data Governance →mediumMultiple Choice

Databricks-DE-Pro Data Governance Practice Question

A data engineer needs to grant a new data analyst the ability to query tables in the `sales` catalog, which is in Unity Catalog. The analyst should only be able to read data and not modify any tables or metadata. Which sequence of privileges should the engineer grant to the analyst?

⚠ Common exam trap

The trap here is forgetting that `USE SCHEMA` is required in addition to `USE CATALOG` and `SELECT`, or assuming that `BROWSE` or `ALL PRIVILEGES` can substitute for the necessary read-only privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant `USE CATALOG` on `sales`, `USE SCHEMA` on all schemas, and `SELECT` on all tables.

In Unity Catalog, querying a table requires a chain of privileges: `USE CATALOG` on the catalog, `USE SCHEMA` on the schema, and `SELECT` on the table. Granting these three privileges provides read-only access without allowing any modifications. This follows the principle of least privilege and ensures the analyst can only read data as required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant `ALL PRIVILEGES` on the catalog and rely on table-level `SELECT` to restrict modifications.

    Why it's wrong here

    Granting `ALL PRIVILEGES` on the catalog would give the analyst the ability to create, modify, and drop objects, which violates the requirement of read-only access. Table-level `SELECT` does not override catalog-level privileges. This approach over-privileges the analyst and poses a security risk.

  • ✗

    Grant `USE CATALOG` on `sales` and `SELECT` on all tables, without schema-level privileges.

    Why it's wrong here

    Without `USE SCHEMA` on the schemas, the analyst cannot access the schemas or the tables within them. `USE CATALOG` alone is insufficient; the user must also have `USE SCHEMA` on each schema containing the tables. `SELECT` on tables is necessary but not sufficient without the schema-level privilege.

  • ✓

    Grant `USE CATALOG` on `sales`, `USE SCHEMA` on all schemas, and `SELECT` on all tables.

    Why this is correct

    To query tables in Unity Catalog, a user needs `USE CATALOG` on the catalog, `USE SCHEMA` on the schema, and `SELECT` on the tables. This sequence grants the minimum privileges required for read-only access. It does not include any write or modify privileges, ensuring the analyst cannot alter data or metadata.

  • ✗

    Grant `BROWSE` on the catalog, `READ VOLUME` on all volumes, and `SELECT` on all tables.

    Why it's wrong here

    `BROWSE` allows viewing metadata but does not grant the ability to query data. `READ VOLUME` is for volumes, not tables. While `SELECT` on tables is necessary, the lack of `USE CATALOG` and `USE SCHEMA` would prevent the analyst from accessing the tables. This combination does not provide the required query access.

About these practice questions

This Databricks-DE-Pro question is part of Courseiva's 267-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.