Databricks-DE-Pro Data Security and Compliance Practice Question
A data engineer needs to grant a service principal permission to read data from a Unity Catalog table named sales.orders. The service principal is used by an automated job and should have only the minimum necessary privileges. Which Unity Catalog privilege should be granted on the table to allow the service principal to read data?
⚠ Common exam trap
Many exam-takers confuse USAGE with read access; USAGE on a table does not allow reading data, and MODIFY is for writes, not reads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SELECT
In Unity Catalog, SELECT is the privilege that grants read access to a table. For a service principal that only needs to read data, granting SELECT on the specific table is the least-privilege approach. Other privileges like MODIFY or ALL PRIVILEGES would provide additional capabilities that are not required and could increase risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ALL PRIVILEGES
Why it's wrong here
ALL PRIVILEGES grants every available privilege on the table, including the ability to modify data and change ownership or permissions. This far exceeds the read-only requirement and violates the principle of least privilege. It could also allow the service principal to grant access to others, which is a security risk.
- ✓
SELECT
Why this is correct
SELECT is the privilege that allows reading data from a table in Unity Catalog. Granting SELECT on sales.orders to the service principal gives it the ability to query the table, which is the minimum required for read access. This follows the principle of least privilege and does not grant unnecessary capabilities such as modifying data or changing metadata.
- ✗
USAGE
Why it's wrong here
USAGE is a privilege that applies to securable objects like catalogs and schemas, not to tables. It allows a user to see and use the object in a hierarchy but does not grant the ability to read data from a table. Granting USAGE on a table is not the correct way to provide read access to its data.
- ✗
MODIFY
Why it's wrong here
MODIFY allows inserting, updating, and deleting data in a table. It does not grant the ability to read data, and it exceeds the minimum necessary privileges for a job that only needs to read. Granting MODIFY would violate the principle of least privilege and could allow unintended data changes.
About these practice questions
Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.