Databricks-DE-Pro Data Governance Practice Question
A data engineer wants to ensure that all data in a specific catalog is encrypted at rest. Which feature should they verify is enabled within the Unity Catalog metastore configuration?
⚠ Common exam trap
Candidates often confuse 'encryption at rest' with 'access control' or 'data masking.' They may select options like Unity Catalog permissions, which govern access but not storage-level encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer-managed keys (CMK) for managed storage.
Customer-managed keys (CMK) for managed storage are the standard governance tool for ensuring that data at rest is encrypted according to organizational security policies. By configuring CMK, the organization maintains control over the encryption lifecycle, satisfying compliance requirements. This feature is critical for highly regulated industries where the entity, rather than the cloud provider, must maintain the ultimate authority over data access and encryption standards in the cloud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Workspace-level access control lists.
Why it's wrong here
Access control lists manage permissions on who can perform specific actions in a workspace, but they do not relate to the physical encryption of data at rest. While important for governance, they are a separate concern from data-at-rest encryption provided by cloud-native storage security features and CMK configurations.
- ✓
Customer-managed keys (CMK) for managed storage.
Why this is correct
Customer-managed keys provide a mechanism to encrypt data at rest using keys managed by the customer. This is the industry-standard approach for ensuring data confidentiality in a multi-tenant cloud environment, providing an additional layer of security and auditability that is essential for enterprise compliance and robust data governance.
- ✗
Unity Catalog lineage tracking.
Why it's wrong here
Lineage tracking monitors the flow of data but has no impact on the encryption status of the storage layer. It is a metadata management feature that helps with auditing and transparency, rather than a security mechanism for data protection at rest, which is handled at the infrastructure and storage level.
- ✗
Table access control (TAC).
Why it's wrong here
Table access control regulates who can read or write to a table, but it does not influence how the data is encrypted on the disk. Encryption at rest is an infrastructure-level concern, whereas TAC is an application-level governance policy that operates once the data is already accessible to the engine.
About these practice questions
Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.