Courseiva

Databricks-DE-Pro Data Security and Compliance Practice Question

A data engineer needs to grant a service principal permission to read data from a Unity Catalog table named sales.orders. The service principal is used by an automated job and should have only the minimum necessary privileges. Which Unity Catalog privilege should be granted on the table to allow the service principal to read data?

⚠ Common exam trap

Many exam-takers confuse USAGE with read access; USAGE on a table does not allow reading data, and MODIFY is for writes, not reads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SELECT

In Unity Catalog, SELECT is the privilege that grants read access to a table. For a service principal that only needs to read data, granting SELECT on the specific table is the least-privilege approach. Other privileges like MODIFY or ALL PRIVILEGES would provide additional capabilities that are not required and could increase risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ALL PRIVILEGES

    Why it's wrong here

    ALL PRIVILEGES grants every available privilege on the table, including the ability to modify data and change ownership or permissions. This far exceeds the read-only requirement and violates the principle of least privilege. It could also allow the service principal to grant access to others, which is a security risk.

  • ✓

    SELECT

    Why this is correct

    SELECT is the privilege that allows reading data from a table in Unity Catalog. Granting SELECT on sales.orders to the service principal gives it the ability to query the table, which is the minimum required for read access. This follows the principle of least privilege and does not grant unnecessary capabilities such as modifying data or changing metadata.

  • ✗

    USAGE

    Why it's wrong here

    USAGE is a privilege that applies to securable objects like catalogs and schemas, not to tables. It allows a user to see and use the object in a hierarchy but does not grant the ability to read data from a table. Granting USAGE on a table is not the correct way to provide read access to its data.

  • ✗

    MODIFY

    Why it's wrong here

    MODIFY allows inserting, updating, and deleting data in a table. It does not grant the ability to read data, and it exceeds the minimum necessary privileges for a job that only needs to read. Granting MODIFY would violate the principle of least privilege and could allow unintended data changes.

About these practice questions

Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.